Creating Policies for Users and Groups
Policies can be assigned to groups to enable granular control over the actions each group of users can perform. By default, access to Oracle Cloud Console is restricted to Cloud Account Administrators and Identity Domain Administrators. Service Administrators of individual environments must be assigned the appropriate policies to be able to view those environments in the Oracle Cloud Console. Similarly, users must be assigned to specific policies to view notifications.
You have the flexibility to create multiple groups, each with its own policy, and assign users accordingly. This enables granular control over the actions that each group of users can perform.
To create a policy:
-
(Optional) If needed, create the users and groups to whom you want to assign policies. See:
- Go to the Navigation menu, search for Identity, and select Policies.
- Select the Compartment for which you are defining the
policy.

- Click Create Policy to create the necessary read and manage
policies.
- In Create Policy, enter a Name and a Description for the policy.
- Select the Compartment.
- In Policy Builder, enter policy statements.
Be sure to replace
GROUP_NAMEwith the name of the group to which you want to apply the policy. For example:Allow group <identity-domain-name>/GROUP_NAME to manage epm-planning-environment-family in tenancy Allow group <identity-domain-name>/GROUP_NAME to read epm-planning-environment-family in tenancy Allow group <identity-domain-name>/GROUP_NAME to read organizations-subscriptions in tenancy Allow group <identity-domain-name>/GROUP_NAME to read organizations-assigned-subscriptions in tenancy Allow group <identity-domain-name>/GROUP_NAME to read organizations-subscription-regions in tenancy Allow group <identity-domain-name>/GROUP_NAME to read app-listing-environments in tenancy Allow group <identity-domain-name>/GROUP_NAME to read metrics in tenancy Allow group <identity-domain-name>/GROUP_NAME to inspect domains in tenancy Allow group <identity-domain-name>/GROUP_NAME to read announcements in tenancy
- Click Create.