Product |
Abbreviation in CAM |
Console |
Authorization by Tag |
Authorization Granularity |
IP Restriction |
Channel Business Management |
cbm |
Supported |
not supported |
Operation level |
not supported |
Note:
The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.
- Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
- Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
- Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.
API authorization granularity
Two authorization granularity levels of API are supported: resource level, and operation level.
- Resource level: It supports the authorization of a specific resource.
- Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.
Read operations
API |
API Description |
Authorization Granularity |
Six-segment Resource Description |
IP Restriction |
AchievementPreview |
AchievementPreview |
Operation level |
* |
not supported |
CooperationPartnershipUniversity |
|
Operation level |
* |
not supported |
DescribeBusinessStrategy |
describe business strategy |
Operation level |
* |
not supported |
DescribeSchedule |
DescribeSchedule |
Operation level |
* |
not supported |
DescribeTask |
task-list page view auth |
Operation level |
* |
not supported |
QueryCustomerType |
QueryCustomerType |
Operation level |
* |
not supported |
ReadClientSpecialRebatePolicy |
agent\'s client special rebate policy |
Operation level |
* |
not supported |
ReadClientVoucher |
agent\\\\\\\'s client voucher |
Operation level |
* |
not supported |
ServicesOutsourcingConsoleStaffVersion |
|
Operation level |
* |
not supported |
ViewConsumptionStatistics |
ViewConsumptionStatistics |
Operation level |
* |
not supported |
ViewCustomerStatistics |
ViewCustomerStatistics |
Operation level |
* |
not supported |
ViewPerformanceStatistics |
ViewPerformanceStatistics |
Operation level |
* |
not supported |
ViewPlans |
ViewPlans |
Operation level |
* |
not supported |
agentInfo |
|
Operation level |
* |
not supported |
authorize |
|
Operation level |
* |
not supported |
businessDetail |
|
Operation level |
* |
not supported |
exportClients |
|
Operation level |
* |
not supported |
inviteClient |
|
Operation level |
* |
not supported |
previewProductDetail |
preview for rebate |
Operation level |
* |
not supported |
rebateInfo |
|
Operation level |
* |
not supported |
reportCustomer |
|
Operation level |
* |
not supported |
transfer |
|
Operation level |
* |
not supported |
viewClients |
|
Operation level |
* |
not supported |
viewDeals |
|
Operation level |
* |
not supported |
viewMenu |
|
Operation level |
* |
not supported |
viewMessage |
|
Operation level |
* |
not supported |
Write operations
API |
API Description |
Authorization Granularity |
Six-segment Resource Description |
IP Restriction |
ApplyClientBind |
applyClientBind |
Operation level |
* |
not supported |
ApplyClientUnbind |
ApplyClientUnbind |
Operation level |
* |
not supported |
AssignBusiness |
AssignBusiness |
Operation level |
* |
not supported |
AssignDeclare |
assign declare to salesman |
Operation level |
* |
not supported |
AssignTask |
task-list page assign task auth |
Operation level |
* |
not supported |
CreatePlan |
CreatePlan |
Operation level |
* |
not supported |
CreateStaff |
CreateStaff |
Operation level |
* |
not supported |
EditBusinessStrategy |
edit business strategy |
Operation level |
* |
not supported |
ExecuteTask |
task-list page execute auth |
Operation level |
* |
not supported |
ManageAgentGroup |
ManageAgentGroup |
Operation level |
* |
not supported |
ManageGroups |
ManageGroups |
Operation level |
* |
not supported |
ManageStaff |
ManageStaff |
Operation level |
* |
not supported |
ModifyPassword |
ModifyPassword |
Operation level |
* |
not supported |
ModifyProject |
ModifyProject |
Operation level |
* |
not supported |
TradeClientDeal |
TradeClientDeal |
Operation level |
* |
not supported |
applyClient |
|
Operation level |
* |
not supported |
modifyAgen |
|
Operation level |
* |
not supported |
pay |
pay |
Operation level |
* |
not supported |
List Operations
API |
API Description |
Authorization Granularity |
Six-segment Resource Description |
IP Restriction |
DescribeDeals |
DescribeDeals |
Operation level |
* |
not supported |
DescribeProjects |
DescribeProjects |
Operation level |
* |
not supported |
ExportDeals |
ExportDeals |
Operation level |
* |
not supported |
Was this page helpful?