Updated on 2024-05-16 GMT+08:00

Querying an Organization Rule

Scenario

You can view organization rules and their details.

This section consists of Viewing an Organization Rule and Viewing Organization Rules Deployed to Member Accounts.

Viewing an Organization Rule

You can view details about a created organization rule.

  1. Sign in to the Config console using the account with which the organization rules are created.
  2. Click in the upper left corner. Under Management & Governance, click Config.
  3. In the navigation pane on the left, choose Resource Compliance.
  4. Click the Organization Rules tab and then click the name of the rule you want to view.

    Figure 1 Viewing organization rules

  5. On the left of the Rule Details page, view member accounts to which the rule deploys, the deployment status, and excluded accounts. On the right of the page, view rule details.

    Members in an organization can only view organization rules created by themselves.

Viewing Organization Rules Deployed to Member Accounts

A deployed organization rule will be displayed in the rule list of each member account in the organization. If you create an organization rule using an account, you can only use the same account to delete or modify the organization rule. Members can only trigger an organization rule and view evaluation results.

  1. Sign in to the management console as an organization member.
  2. Click in the upper left corner. Under Management & Governance, click Config.
  3. In the navigation pane on the left, choose Resource Compliance.
  4. On the Rules tab, click an organization rule name in the rule list to view details.

    The evaluation results are displayed on the left of the page, and the rule details on the right of the page.

    Figure 2 Viewing organization rules deployed to member accounts

    A deployed organization rule will be displayed in the rule list of every member account in the organization. The system automatically adds the Org field before the rule name.

    Members in an organization can only trigger evaluations against the organization rules and view evaluation results and details. They cannot modify, disable, or delete an organization rule.