Skip to content
Back to Knowledge Base

How to Create an IAM Policy

Applies to CoCoCo platform v1.0.0-rc.31. Every step below was run on that version, except changing an existing policy.

A policy is a named list of statements. Each statement allows or denies a set of actions. A policy does nothing on its own — it takes effect when you assign it to a user or a service account (see How to Assign a Policy to a User).

Before you start: you need the permission to create policies (iam:createPolicy) and to see the policy list (iam:listPolicies). Changing and deleting need iam:updatePolicy and iam:deletePolicy.

  1. In the sidebar, under Identity & Access, click Policies.
  2. Click Add Policy. The page New Policy opens.
  3. Enter a Name, for example Network viewer. Description is optional.
  4. Click Add Statement. The statement starts as ALLOW and applies to all resources.
  5. Under Actions, type into Search actions…, click the name of the group that appears (for example Network) and, in the list that opens, tick the action you want, for example network:list. Repeat for each action. Selected Actions shows what the statement contains.
  6. To deny actions, add another statement and click its ALLOW label once — it switches to DENY. Then pick the actions as in step 5.
  7. Click Save. The message Policy created appears and the policy opens for editing.

All Actions at the top of the action list grants every permission on the platform. Use it only for administrators.

  • A user can do an action if at least one of their policies allows it and none denies it. A DENY always wins — also when the ALLOW and the DENY sit in two different policies.
  • An action that no statement mentions is not allowed.
  • Start narrow. Adding an action later is easier than finding out which of too many rights someone relied on.
  • To change a policy, click Edit next to it in the list, change it and click Save.
  • To delete a policy, click Delete next to it in the list and confirm Delete Policy? with Delete. Everyone who had the policy loses its permissions at once.