Creating an Agency
Scenario
SecMaster allows you to create agencies to authorize other users in the project to manage your workspaces. This way, other users can view asset risks, alerts, and incidents and perform security operations for you in a unified manner.
Limitations and Constraints
If you select Organization for Initiated By, there are some limitations you need to know:
- If you select all accounts under all organizations for the agency, the agency works for workspaces of new accounts of an organization.
- If you select all accounts of a specific organization for the agency, it takes a while for workspaces of new accounts of the organization to be synchronized in the agency.
Prerequisites
- An agency view has been created by the agency user. For details about how to create an agency view, see Creating an Agency View.
- You have authorized the workspaces to access the cloud service data.
Procedure
- Log in to the management console.
- Click in the upper left corner of the management console and select a region or project.
- Click in the upper left corner of the page and choose Security & Compliance > SecMaster.
- In the navigation pane on the left, choose
.Figure 1 Agencies
- Click Create Agency in the upper right corner of the page.
- On the Create Agency slide-out is displayed, configure agency parameters.
Table 1 Parameters for creating an agency Parameter
Description
Initiated By
Agency creator.
Agency Created By
Workspace
A workspace to be managed by this agency.
Agency Accepted By
Account
Account name of the user who delegate the management permission to this agency. Take the following steps to obtain the account name:
- Log in to the management console, hover the mouse over the username in the upper right corner, and select My Credentials from the drop-down list. The API Credentials page is displayed by default.
- On the API Credentials page, obtain the Account Name.
Figure 2 Account Name
Agency View
An existing agency view.
Agency Details
Agency Name
Name of the agency
Agency Duration
How long the agency works
Agency Status
Agency permission policy.
You can query the meaning of a policy in IAM. To view the meaning, perform the following steps:
- Log in to the management console, hover the mouse over the username in the upper right corner, and select Identity and Access Management from the drop-down list. The IAM users page is displayed.
- In the navigation pane on the left, choose
View the meaning and scope of the policy.
. On the Policies page, enter the policy name in the search box.
Description
Description of the agency
- Click Confirm.
Follow-up Operations
You need to wait for agency user's acceptance of your delegation. As an agency user, you need to accept the delegation from other users. For details, see Authorizing an Agency.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot