Help Center/ Cloud Operations Center/ FAQs/ Product Consultation/ How Do I Control Permissions Using Enterprise Projects?
Updated on 2026-03-11 GMT+08:00

How Do I Control Permissions Using Enterprise Projects?

Issue Description

Using enterprise projects to control permissions on COC is required.

Solution

  1. Log in to IAM as an administrator.
  2. In the navigation pane, choose Permissions > Policies/Roles. On the displayed page, click Create Custom Policy.
    Figure 1 Creating a custom policy
  3. Set the policy content, select CloudOpsCenter, and select the operations you want to authorize by enterprise project. Click OK.
    Figure 2 Setting the policy content (1)
    Figure 3 Setting the policy content (2)
    Figure 4 Setting the policy content (3)

    Currently, only some COC operations can be authorized by enterprise projects. For details about how to create custom policies, see Table 1.

    Table 1 Operations that can be authorized by enterprise projects

    Operation

    Description

    coc:instance:reinstallOS

    Grants permission to reinstall the ECS OS.

    coc:instance:changeOS

    Grants permission to change the ECS OS.

    coc:instance:start

    Grants permission to start an ECS.

    coc:instance:reboot

    Grants permission to restart an ECS.

    coc:instance:stop

    Grants permission to stop an ECS.

    coc:instance:startRDSInstance

    Grants permission to enable RDS DB instances.

    coc:instance:stopRDSInstance

    Grants permission to stop RDS DB instances.

    coc:instance:restartRDSInstance

    Grants permission to reboot RDS DB instances.

    coc:instance:scanOSCompliance

    Grants the permission to scan server OS patches.

    coc:instance:installPatches

    Grants permission to install patches for an ECS.

    coc:instance:executeDocument

    Grants permission to execute documents on an ECS.

    coc:schedule:create

    Grants permission to create a scheduled task list.

    coc:schedule:update

    Grants permission to update a scheduled task.

  4. Select a user or user group for authorization as the administrator.
    Figure 5 Selecting an object for authorization
  5. Select the custom policy created in step 3. When setting the minimum authorization scope, specify enterprise project resources.
    Figure 6 Granting permissions by enterprise project