Creating a User and Granting Permissions

This section describes how to use a group to grant permissions to a user. Figure 1 shows the process for granting permissions.

CSS has two types of user permissions: CSS administrator permission and read-only permission.

Prerequisites

Before assigning permissions to user groups, you have learned about the system policies listed in Permissions Management.

Process Flow

**Figure 1** Process of granting CSS permissions

Figure 1 Process of granting CSS permissions

  1. Create a user group and assign permissions.

    Create a user group on the IAM console, and assign the CSS permission to the group.

  2. Create an IAM user and add it to a user group.

    Create a user on the IAM console and add the user to the group created in 1. Create a user group and assign permissions.

  3. Log in and verify permissions.

    In the authorized region, perform the following operations:

    • Choose Service List > Cloud Search Service. Then click Create Cluster on the CSS console. If the cluster cannot be bought (assuming that the current permissions include only CSS ReadOnlyAccess), the CSS ReadOnlyAccess policy has already taken effect.

    • Choose another service from Service List. If a message appears indicating that you have insufficient permissions to access the service (assuming that the current policy contains only CSS ReadOnlyAccess), the ECS ReadOnlyAccess policy is in effect.