Help Center> Cloud Trace Service> User Guide> Permissions Management
Updated on 2023-11-10 GMT+08:00

Permissions Management

This chapter describes how to use IAM for fine-grained permissions control for your CTS resources. With IAM, you can:

  • Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing CTS resources.
  • Manage permissions on a principle of least permissions (PoLP) basis.
  • Entrust an account or cloud service to perform efficient O&M on your CTS resources.

If your account does not require individual IAM users, skip this chapter.

Prerequisites

Learn about the permissions (see section "Permissions Management" in the Service Overview) supported by CTS and choose policies or roles according to your requirements.

Process Flow

Figure 1 Process of granting CTS permissions
  1. Create a user group and assign permissions.

    Create a user group on the IAM console, and attach the CTS Administrator policy to the group.

  2. Assign permissions to an IAM user.

    Create a user on the IAM console and add the user to the user group created in 1.

  3. Log in and verify permissions.

    Log in to the CTS console using the user created in 2, and verify that the user has the administrator permissions for CTS.