Help Center/ Optimization Advisor/ User Guide/ Permissions Management/ Using IAM to Grant Access to Optimization Advisor/ Using IAM Roles or Policies to Grant Access to Optimization Advisor
Updated on 2025-11-13 GMT+08:00

Using IAM Roles or Policies to Grant Access to Optimization Advisor

You can use Identity and Access Management (IAM) to implement fine-grained permissions control for your Optimization Advisor (OA) resources. With IAM, you can:

  • Create IAM users or user groups for personnel based on your enterprise's organizational structure. Each IAM user has their own identity credentials for accessing OA.
  • Grant users only the permissions required to perform a given task based on their job responsibilities.
  • Entrust a Huawei Cloud account to perform efficient O&M on OA.

If your Huawei Cloud account meets your permissions requirements, you can skip this section.

Figure 1 shows the process flow of role/policy-based authorization.

Prerequisites

Before granting permissions to user groups, learn about permissions supported by OA and select appropriate ones as needed. To grant permissions for other services, learn about all system-defined permissions supported by IAM.

Process Flow

Figure 1 Process of granting OA permissions to a user
  1. On the IAM console, create a user group and grant it permissions (BSS Administrator as an example).

    Create a user group on the IAM console, and assign the OA FullAccessPolicy (recommended), OA AdvancedOperationsPolicy, OA CommonOperationsPolicy, or OA ReadOnlyAccessPolicy permission to the group.

  2. Create an IAM user and add it to the created user group.

    On the IAM console, create a user and add it to the user group created in 1.

  3. Log in as the IAM user and verify permissions.

    Log in to the OA console as the created user, and verify that it only has the OA FullAccessPolicy permission.