Help Center/ Optimization Advisor/ User Guide/ Permissions/ Creating a User and Granting OA Permissions
Updated on 2025-08-28 GMT+08:00

Creating a User and Granting OA Permissions

You can use Identity and Access Management (IAM) for fine-grained permissions management of your OA. With IAM, you can:

  • Create IAM users for personnel based on your enterprise's organizational structure. Each IAM user has their own identity credentials for accessing OA resources.
  • Grant only the permissions required for users to perform a specific task.

If your Huawei Cloud account does not require individual IAM users, you can skip this section.

This section describes the procedure for granting permissions. Figure 1 shows the process flow.

Prerequisites

Before granting permissions to user groups, learn about system-defined permissions for OA and choose policies based on your needs.

For details about supported system-defined policies and their differences, see Permissions Management. To grant permissions for other services, learn about all system-defined permissions supported by IAM.

Process Flow

Figure 1 Process for granting OA permissions
  1. Create a user group on the IAM console, and assign the OA FullAccessPolicy, OA AdvancedOperationsPolicy, OA CommonOperationsPolicy, and OA ReadOnlyAccessPolicy permissions to the group. You are advised to assign the OA FullAccessPolicy permission to the group.
  2. Create a user.

    Create a user on the IAM console and add the user to the group created in 1.

  3. Log in as the IAM user and verify permissions.

    Log in to OA as the created user, and verify that it has the OA FullAccessPolicy permission.