System-defined permissions in identity policy-based authorization provided by Identity and Access Management (IAM) let you control access to Billing Center. With IAM, you can:
- Create IAM users or user groups for personnel based on your enterprise's organizational structure. Each IAM user has their own security credentials for accessing Billing Center.
- Grant users only the permissions required to perform a given task based on their job responsibilities.
- Entrust a HUAWEI ID to perform efficient O&M on your Billing Center.
If your HUAWEI ID meets your permissions requirements, you can skip this section.
Figure 1 shows the process flow of identity policy-based authorization.
Process Flow
Figure 1 Process of using identity policy-based authorization to grant permissions to use Billing Center
- On the IAM console, create an IAM user or create a user group.
- Attach a system-defined identity policy (BILLINGOperatorPolicy) to the user or user group.
- Log in as the IAM user and verify the permissions.
On the Huawei Cloud official website:
- Select Billing & Costs and check whether the IAM user can query data in the Billing Center. If yes, the BILLINGOperatorPolicy has already taken effect.
- If "insufficient permissions" is displayed when the IAM user attempts to perform financial operations in the Billing Center, the BILLINGOperatorPolicy has already taken effect.
Example Custom Identity Policies for Billing Center
You can create custom identity policies to supplement the system-defined policies of Billing Center. For details about the actions supported by system-defined identity policies, see Actions Supported by Identity Policy-based Authorization.
You can create custom identity policies in either of the following ways:
- Visual editor: Select cloud services, actions, resources, and conditions. This does not require knowledge of policy syntax.
- JSON: Create a JSON policy or edit an existing one.
For details, see Creating a Custom Identity Policy and Attaching It to a Principal. The following provides examples of custom identity policies in Billing Center.