Back to Knowledge Base
Understanding IAM: Policies, Permissions and Roles
Applies to CoCoCo platform v1.0.0-rc.31. Every rule below was checked on that version with a test account.
In CoCoCo, what someone may do is decided by policies. This page explains how they work and where you manage them.
The pieces
Section titled “The pieces”- A permission is one action on one kind of object, written
resource:verb— for examplenetwork:list,job:writeordevice:delete. Most kinds of object have the verbsread,list,writeanddelete; a few have more, such astask:claimoriam:attachPolicy. The policy editor lists all of them, grouped by object. - A statement says ALLOW or DENY for a set of actions.
- A policy is a named list of statements.
- A user — a person or a service account — gets permissions only through the policies assigned to them.
The rules
Section titled “The rules”- Nothing is allowed by default. A user without a policy can do nothing, and an action that no statement mentions is not allowed.
- ALLOW grants exactly the actions it names. Allowing
network:listdoes not allowjob:list. - DENY always wins. If one policy allows an action and another denies it, the action is denied.
- One star means every action. The action
*allows everything; All Actions in the editor writes it. - Changes take effect at once — assigning a policy, removing it, and deleting a policy.
- Policies belong to users, not to teams. A team is for handing out tasks and custom apps; it grants no permission.
There are no built-in roles to pick from. A role is a policy you create — for example a Production manager policy with the job and operation actions that role needs — and assign to each person in that role.
Every instance comes with one policy, Full Access, which allows *. Give it only to administrators.
Where you manage it
Section titled “Where you manage it”In the sidebar under Identity & Access:
- Identity & Access — an overview with counts and the most recent users and policies
- Users — the people who have signed in to this instance, and their policies
- Service accounts — identities for integrations and scripts, with their own policies and tokens
- Policies — create, change and delete policies
- Teams — groups of people
Where to go next
Section titled “Where to go next”- How to Create an IAM Policy
- How to Assign a Policy to a User
- Service Accounts
- How to Create a Team