About access tags
tag based access control using conditions and a set of tag variables, you can add a policy to scope access based on the tags that have been applied to a resource access can be controlled based on a tag that exists on the resource tag based access control provides additional flexibility to your policies by allowing you to define access policies with tags access tags are visible account wide in all services; avoid using personal information access tags must always be in the key\ value format think of it as a string to isolate two logical parts for example, project\ projectname the kyndryl user interface (ui) makes this distinction very clear access tags, both key and value, are case sensitive what is a resource? a resource is any item that is created or owned by an application, such as virtual machines (vm), orders, and provider connections what is a resource group? a resource group helps you organize your resources in a way that best fits within your business with resource groups, you can quickly grant users access to one or more resources at the same time so, a resource group is a group that contains one or more resource attributes that maps to a collection of similar resources what is an attribute? an attribute is an element or metadata of the resource that helps identifying the resources, such as assetid, orderid, virtual machine in a specific region or virtual machine of a given provider use case assigning access tags in policy authoring access tags are designed for integration with abac when authoring an access policy you can define policies like allow access to resources where project=finance deny access if environment=prod tags can be used across users, access groups, and service identities for granular access control