Updated on 2026-09-23 GMT+08:00

Managing Agency Authorization

As an administrator, you can view and delete permissions assigned to an agency in the Permissions tab of the agency details page.

Agencies automatically created by IAM Identity Center (whose names start with SysReservedV3) can only be modified on the IAM Identity Center console, not on the IAM console.

Procedure

  • Managing Role/Policy-based Authorization
    1. Log in to the IAM console as the administrator.
    2. In the agency list, click an agency name to go to the details page.
    3. Click the Permissions tab to view the role/policy-based authorization of the agency. You can assign, delete, and export permissions for the agency on this page.
      Figure 1 Viewing role/policy-based authorization
  • Managing Identity Policy-based Authorization
    1. Log in to the IAM console as the administrator.
    2. In the agency list, click an agency name to go to the details page.
    3. In the Permissions tab, click Check identity policy-based authorization records. You can assign, delete, and export permissions for the agency on this page.

      After you click Authorize in the displayed pane on the left, you will go to the new console. You can assign permissions to the agency using identity policies.

      Figure 2 Checking identity policy-based authorization records