Skip to content
Back to Knowledge Base

Understanding IAM: Policies, Permissions and Roles

Applies to CoCoCo platform v1.0.0-rc.31. Every rule below was checked on that version with a test account.

In CoCoCo, what someone may do is decided by policies. This page explains how they work and where you manage them.

  • A permission is one action on one kind of object, written resource:verb — for example network:list, job:write or device:delete. Most kinds of object have the verbs read, list, write and delete; a few have more, such as task:claim or iam:attachPolicy. The policy editor lists all of them, grouped by object.
  • A statement says ALLOW or DENY for a set of actions.
  • A policy is a named list of statements.
  • A user — a person or a service account — gets permissions only through the policies assigned to them.
  1. Nothing is allowed by default. A user without a policy can do nothing, and an action that no statement mentions is not allowed.
  2. ALLOW grants exactly the actions it names. Allowing network:list does not allow job:list.
  3. DENY always wins. If one policy allows an action and another denies it, the action is denied.
  4. One star means every action. The action * allows everything; All Actions in the editor writes it.
  5. Changes take effect at once — assigning a policy, removing it, and deleting a policy.
  6. Policies belong to users, not to teams. A team is for handing out tasks and custom apps; it grants no permission.

There are no built-in roles to pick from. A role is a policy you create — for example a Production manager policy with the job and operation actions that role needs — and assign to each person in that role.

Every instance comes with one policy, Full Access, which allows *. Give it only to administrators.

In the sidebar under Identity & Access:

  • Identity & Access — an overview with counts and the most recent users and policies
  • Users — the people who have signed in to this instance, and their policies
  • Service accounts — identities for integrations and scripts, with their own policies and tokens
  • Policies — create, change and delete policies
  • Teams — groups of people
  • How to Create an IAM Policy
  • How to Assign a Policy to a User
  • Service Accounts
  • How to Create a Team