A sub-account has no APM permissions by default and can access APM resources only after being granted relevant permissions by the root account.
Prerequisites
Log in to the Tencent Cloud console with the root account or a sub-account with the QcloudCamFullAccess
permission and create a sub-account as instructed in Creating Sub-User. Custom policy
1. Use the root account or a sub-account with the QcloudCamFullAccess
permission to log in to the CAM console and go to the Policies page. 2. click Create a custom policy. According to needs, select the corresponding create policy method. APM supports two custom policy methods: resource-level authorization and tag authorization.
Authorization at resource level
You can grant a sub-account management permissions for a single resource through policy syntax or default policies. For details, see Policy Syntax. Authorize by tag
You can grant sub-accounts management permissions for resources under corresponding tags by tagging the resources. For details, see Resource Tags. Policy Association
1. Use the root account or a sub-account with the QcloudCamFullAccess
permission to log in to the CAM console and go to the Policies page. 2. Go to the policy management page and enter a policy name in the policy search box.
3. Select QcloudAPMFullAccess
or QcloudAPMReadOnlyFullAccess
and click Associate User/Group/Role in the Operation column.
4. In the pop-up window, select the target user and click OK.