Help Center/ SecMaster/ User Guide (ME-Abu Dhabi Region)/ Permissions Management/ SecMaster Permissions and Supported Actions
Updated on 2023-10-31 GMT+08:00

SecMaster Permissions and Supported Actions

This topic describes fine-grained permissions management for your SecMaster. If your account does not need individual IAM users, then you may skip over this section.

By default, new IAM users do not have any permissions assigned. You need to add a user to one or more groups, and assign permissions policies to these groups. Users inherit permissions from the groups to which they are added and can perform specified operations on cloud services based on the permissions.

Permissions are classified into roles and policies based on the authorization granularity. A role is a coarse-grained authorization mechanism provided by IAM to define permissions based on users' job responsibilities. A policy defines permissions required to perform operations on specific cloud resources under certain conditions. IAM uses policies to perform fine-grained authorization.

Supported Actions

SecMaster provides system-defined policies that can be directly used in IAM. You can also create custom policies and use them to supplement system-defined policies, implementing more refined access control.

  • Permission: A statement in a policy that allows or denies certain operations.
  • Action: Specific operations that are allowed or denied.