How to Assign a Policy to a User
Applies to CoCoCo platform v1.0.0-rc.31. Every step below was run on that version.
A policy takes effect when it is assigned to a user. Policies are assigned to people and service accounts one by one — teams do not carry policies.
Before you start: you need the permission to see users (user:list, user:read) and policies (iam:listPolicies, iam:listUserPolicies), and to assign and remove them (iam:attachPolicy, iam:detachPolicy). The policy must already exist — see How to Create an IAM Policy.
People are not created here. A person appears in Users the first time they sign in to this instance.
Assign a policy
Section titled “Assign a policy”- In the sidebar, under Identity & Access, click Users.
- Click the person. The page Edit user opens.
- Under Policies, tick the policy. The card is marked Assigned and the counter shows (unsaved).
- Click Save in the top right corner. The message Policies updated appears.
Nothing changes until you click Save. You can tick and untick several policies and save them together.
Remove a policy
Section titled “Remove a policy”- Open the person as above.
- Under Policies, untick the policy.
- Click Save. The message Policies updated appears.
Service accounts
Section titled “Service accounts”A service account gets its policies the same way, on its own page under Service accounts — see Service Accounts.
If a user has several policies
Section titled “If a user has several policies”All of a user’s policies count together. An action is allowed if one policy allows it and no policy denies it; a DENY always wins.