Create Oracle Cloud Infrastructure Identity and Access Management (IAM) policies to control who has access to Oracle Managed Access resources, and the type of access for each
group of users.
By default, only users in the Administrators group have access to all Managed Access resources. If you're new to IAM policies, see Getting Started with Policies. The supported Oracle Managed Access policies use the term
lockbox to see an Oracle Managed Access
resource.
For a complete list of all policies in Oracle Cloud Infrastructure, see the Policy Reference.
This topic covers details for writing policies to control access to the Managed Access service.
Resource-Types 🔗
The following resource types are related to Oracle Managed Access.
This topic covers details for writing policies to control access to Managed Access resources.
Resource Type
Permissions
lockboxes
LOCKBOXES_INSPECT
LOCKBOXES_READ
LOCKBOXES_CREATE
LOCKBOXES_UPDATE
LOCKBOXES_DELETE
LOCKBOXES_MOVE
approval-templates
APPROVAL_TEMPLATES_INSPECT
APPROVAL_TEMPLATES_READ
APPROVAL_TEMPLATES_CREATE
APPROVAL_TEMPLATES_UPDATE
APPROVAL_TEMPLATES_DELETE
APPROVAL_TEMPLATES_MOVE
APPROVAL_TEMPLATES_ATTACH
access-requests
ACCESS_REQUESTS_INSPECT
ACCESS_REQUESTS_READ
ACCESS_REQUESTS_CREATE
ACCESS_REQUESTS_ACTION_HANDLE
access-approvals
ACCESS_APPROVALS_INSPECT
ACCESS_APPROVALS_READ
ACCESS_APPROVALS_CREATE
ACCESS_APPROVALS_ACTION_REVOKE
ACCESS_APPROVALS_RETRIEVE
A policy that uses <verb> lockbox-family is equal
to writing a policy with a separate <verb><resource-type> statement for each of the individual
resource types.
Individual Resource-Types
lockbox
lockboxes
approval-template
approval-templates
access-request
access-requests
access-approval
access-approvals
Aggregate Resource-Types
lockbox-family
Supported Variables 🔗
Managed Access
IAM policies support all the general policy
variables.