Overview
If you have used multiple Tencent Cloud services, which are managed by different users who share your root account key with the highest privilege, the following problems may exist:
Your key is shared by multiple users, so there are huge risks of data breaches.
Your users might introduce security risks from misoperations due to the lack of user access control.
In this case, you can create multiple users in CAM overview to take charge of different services, and give them viewing and operating privileges on different consoles by associating policies. This document provides examples of viewing and operating privileges for CWPP, guiding users on how to use access policies for CWPP. Examples
Full Access Policy
To grant users full access to all CWPP APIs, you need to associate the policy QcloudCWPPFullAccess with them.
See license management to grant users full access with the preset policy QcloudCWPPFullAccess. Read-only Policy
To grant users query access to CWPP, without other privileges to add, delete, or modify, you need to associate the policy QcloudCWPPReadOnlyAccess with them. The policy is implemented by granting users access privileges to APIs prefixed with Describe, Get, Check, and Export.
See license management to grant users read-only access with the preset policy QcloudCWPPReadOnlyAccess. Custom Policies
Note:
New users will not be associated with any CWPP policies by default, indicating they do not have any privileges. For more information, see user guide for CAM.
Was this page helpful?