Skip to content
Back to Knowledge Base

How to Assign a Policy to a User

Applies to CoCoCo platform v1.0.0-rc.31. Every step below was run on that version.

A policy takes effect when it is assigned to a user. Policies are assigned to people and service accounts one by one — teams do not carry policies.

Before you start: you need the permission to see users (user:list, user:read) and policies (iam:listPolicies, iam:listUserPolicies), and to assign and remove them (iam:attachPolicy, iam:detachPolicy). The policy must already exist — see How to Create an IAM Policy.

People are not created here. A person appears in Users the first time they sign in to this instance.

  1. In the sidebar, under Identity & Access, click Users.
  2. Click the person. The page Edit user opens.
  3. Under Policies, tick the policy. The card is marked Assigned and the counter shows (unsaved).
  4. Click Save in the top right corner. The message Policies updated appears.

Nothing changes until you click Save. You can tick and untick several policies and save them together.

  1. Open the person as above.
  2. Under Policies, untick the policy.
  3. Click Save. The message Policies updated appears.

A service account gets its policies the same way, on its own page under Service accounts — see Service Accounts.

All of a user’s policies count together. An action is allowed if one policy allows it and no policy denies it; a DENY always wins.