Access Policies
access policies grant one or more roles to a subject (user, service id or access group) over all resources or a set of resources based on attributes or tags policies extend permissions without changing a subject’s original role the following principles define how access policies work assign a platform and custom roles within a single policy choose all resources or resources based on attributes (attribute based access control using tags) attribute based scope takes effect only when the subject and target resources share the selected tags or attributes only administrators can view, assign or modify access policies other users cannot view or manage access policies assigning an access policy to a user from the main menu , go to administration → → users groups select the overflow menu next to the user that you want to modify select edit membership navigate to the access policies tab click + assign access policy select the services that you want to assign select the scope all resources or resources based on attributes select roles (platform roles, service roles, custom roles, or a combination of the three)) select assign assigning an access policy to an access group a similar flow applies when assigning policies to service ids or access groups from their detail pages learn more assigning access policies to an access group docid\ hzc4qy5gh7gwklhfysayc , and assigning an access policy to a service id docid\ i2wxfqp2tstqi7gfvof18