Access Tags
access tags in enable organizations to define and manage resource level access control through a simple and scalable key value tagging system this feature empowers administrators to organize, restrict and assign access policies based on defined access tags, ensuring secure and efficient resource management non administrative users can only view access tags created for the account they can neither create nor delete access tags this update introduces the ability to create and delete account wide access tags using a key value format these tags can then be used when authoring access policies for users or access groups, especially when choosing attribute based access control (abac) with access tags, you can manage resource segmentation, enforce fine grained access control and streamline policy definitions using standardized labels for instance, tags like environment\ dev or project\ finance can help enforce which users can access which environments or project resources prerequisites to create or delete access tags you must have the administrator role in the account accessing the access tags page from the main menu , go to administration → → access tags creating access tags to create an access tag, complete the following steps on the access tags page, click add access tags enter a tag key (e g , environment) enter a tag value (e g , dev) click add tag + to add multiple tag entries (up to 10 total) click add access tag to save validation and error each key\ value pair must be unique access tags, both key and value, are case sensitive if a tag already exists, an error will display "the newly added key\ value pairs must be unique " "key already in use please enter a unique value " "value already in use please enter a unique value " deleting access tags to delete access tags, locate the access tag and select the delete icon next to their name confirm the action when prompted access tags cannot be edited, they can only be created or deleted use case assigning access tags in policy authoring access tags are designed for integration with abac when authoring an access policy you can define policies like allow access to resources where project=finance deny access if environment=prod tags can be used across users, access groups, and service identities for granular access control