Updated on 2025-03-28 GMT+08:00

Enterprise Project Permissions

Administrator: The administrator can perform any operations on the Enterprise Project Management Service page.

IAM user: An IAM user's permissions are granted by the administrator. The enterprise project information displayed on the Enterprise Project Management Service page varies for each IAM user based on the permissions assigned. Each IAM user can only access resources that they are allowed to If the administrator can use default and custom policies to assign permissions.

The administrator can grant permissions specified in the default policies or custom policies to users. Policies related to enterprise projects include EPS FullAccess and EPS ReadOnlyAccess. You can configure enterprise project permissions for users in IAM. For details, see the Identity and Access Management User Guide.

The permissions set in IAM are different from those set in Enterprise Management. Administrator is advised to select either IAM or Enterprise Management to manage permissions based on enterprise requirements.

Table 1 Enterprise Management permissions

Service Name

Permission Name

Permission Description

Typically Associated Personnel

Enterprise Management

EPS FullAccess

  • Administrator permissions for Enterprise Management, including enterprise project and personnel management. For example, creating organizations, migrating resources, adding/removing user groups, and attaching policies to user groups. These permissions can be assigned by the administrator in the Global region on the IAM console.
  • Administrator permissions for a specific enterprise project, including modifying, enabling, disabling, and viewing the enterprise project. The administrator and users granted the EPS FullAccess policy in IAM can set the EPS FullAccess policy in Enterprise Management.

Enterprise asset administrators

EPS ReadOnlyAccess

Read-only permissions for a specific or all enterprise projects

  • Read-only permissions for viewing all enterprise projects and user information. These permissions can be assigned by the administrator in the Global region on the IAM console.
  • Read-only permissions of a single enterprise project, which can be set in Enterprise Management by the administrator and users granted the EPS FullAccess policy set in IAM.

Enterprise asset query personnel

Table 2 Common operations and required permissions

Operation

EPS FullAccess

EPS ReadOnlyAccess

Viewing resources in an enterprise project

Creating an enterprise project

×

Modifying an enterprise project

×

Enabling an enterprise project

×

Disabling an enterprise project

×

Adding resources to an enterprise project

×

Removing a resource from an enterprise project

×