A policy is a document of statements that allow or deny actions on resources. You attach policies to users, bots and groups. There are two kinds:
- Managed policies are built in and the same in every organization. You can’t change or delete them. Their ID is their name, like
ReadOnlyAccess. - Custom policies are ones you write. Their ID is a UUID, and they also have a policy ID like
pol_a1b2c3d4e5f6and a resource name.
For how policies combine into a decision, see How access is decided.
Policy documents
{
"statements": [
{
"sid": "ReadProjects",
"effect": "allow",
"actions": ["projects.list", "projects.get"],
"resources": ["*"]
},
{
"effect": "deny",
"actions": ["projects.delete"],
"resources": ["ezgh:*:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2"]
}
]
}| Field | Required | Value |
|---|---|---|
statements |
Yes | 1 to 20 statements |
sid |
No | A label for the statement, up to 64 characters |
effect |
Yes | allow or deny |
actions |
Yes | 1 to 100 actions or action patterns |
resources |
Yes | 1 to 100 resource names or patterns, each up to 1,024 characters |
Field names and effect values are lowercase. Policies have no conditions.
Actions
Actions are named <service>.<verb> or <service>.<resource>.<verb>, like projects.delete or ocr.processors.create. In an action pattern, * matches any run of characters: * is every action, projects.* every projects action, and *.list every list action. Each action or pattern must match at least one existing action; otherwise saving the policy returns 400 with invalid_request. The action reference lists every action.
Resources
A resource name identifies something a policy can target:
| Resource | Resource name |
|---|---|
| Organization | ezgh::org_k3f9a0x2m7qp |
| Project | ezgh::org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2 |
| Group | ezgh::org_k3f9a0x2m7qp:grp_… |
| Bot | ezgh::org_k3f9a0x2m7qp:bot_… |
| Custom policy | ezgh::org_k3f9a0x2m7qp:pol_… |
| SSO provider | ezgh::org_k3f9a0x2m7qp:sso_… |
| OCR processor | ezgh:us-west-1:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2:prc_… |
The part after ezgh: is the region, empty for resources that aren’t regional. The console shows each group’s, bot’s and custom policy’s Resource name on its page.
In resources:
*alone is everything in the organization.- Any other value starts with
ezgh:, a region, and your organization’s ID (org_…), written out. A policy can only name resources in its own organization. *matches any run of characters.ezgh:*:org_…:prj_…matches the project, andezgh:*:org_…:prj_…:*matches everything in it, in any region.- A pattern with an empty region can’t end in
:*, because it would miss regional resources. Use*as the region instead.
Each action is checked against one resource, shown as Checked against in the action reference. Actions that create things in the organization or act on the whole organization, such as projects.create, organizations.get or users.delete, are checked against the organization. A statement scoped to a project doesn’t allow them. This policy lets its holder see the organization and OCR models, and use OCR processors in one project only:
{
"statements": [
{
"effect": "allow",
"actions": ["organizations.get", "ocr.models.list", "ocr.models.get"],
"resources": ["*"]
},
{
"effect": "allow",
"actions": ["projects.list", "projects.get", "ocr.processors.*", "ocr.documents.process"],
"resources": [
"ezgh:*:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2",
"ezgh:*:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2:*"
]
}
]
}Listing projects with this policy returns only that project.
Managed policies
| Policy | What it allows |
|---|---|
AdministratorAccess |
Every action. The root user always has it. |
BasicAccess |
See the organization, its projects, users and bots, and create your own API keys: organizations.get, projects.list, projects.get, users.list, users.get, bots.list, bots.get, apiKeys.create. |
ReadOnlyAccess |
View everything, change nothing: *.get, *.list and audit.queries.run, plus every product’s list and read actions. |
ProjectsFullAccess |
Create, change and delete projects: organizations.get, projects.*. |
BillingFullAccess |
Manage billing details and payment methods: organizations.get, billing.*. |
IAMFullAccess |
Manage users, invitations, groups, bots, API keys, policies, SSO and SCIM: organizations.get, users.*, invitations.*, groups.*, bots.*, apiKeys.*, policies.*, ssoProviders.*, scim.*. |
OcrFullAccess |
Manage OCR processors, read models and process documents: every ocr.* action, plus organizations.get, projects.list, projects.get. |
OcrReadOnlyAccess |
Read OCR processors and models: ocr.models.list, ocr.models.get, ocr.processors.list, ocr.processors.get, plus organizations.get, projects.list, projects.get. |
Managed policies apply to everything in the organization. IAMFullAccess includes policies.attach, which lets its holder attach any policy to themselves, so treat it as administrator access.
To see a policy’s full document, open IAM > Policies and select it, or run ezgh iam policies get <policy>.
Create a custom policy
Creating a policy needs policies.create. A policy’s name is 1 to 100 characters and its description up to 1,000.
- Open IAM > Policies and select Create policy.
- Enter a Name and, optionally, a Description.
- Under Applies to, choose Everything in the organization or Only some projects. Select the actions to Allow, and optionally Add denied actions. To write the document yourself, select Edit as JSON.
- Review, then select Create policy.
ezgh iam policies create deployers --document @policy.json --description "Deploy to production"curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/policies \
-H "Authorization: Bearer $EZGH_API_KEY" \
-H "Content-Type: application/json" \
-d '{"name": "deployers", "document": {"statements": [{"effect": "allow", "actions": ["projects.*"], "resources": ["*"]}]}}'See CreatePolicy.
To change a custom policy, select Edit on its page (policies.update), run ezgh iam policies update, or call UpdatePolicy. Changes apply to everyone it’s attached to on their next request. Deleting a custom policy (policies.delete) detaches it from every user, bot and group.
Attach a policy
Attach policies to users, bots and groups. Attaching and detaching needs policies.attach. You can’t change the root user’s policies: the root user always has AdministratorAccess.
- Open the user’s, bot’s or group’s page under IAM.
- On the Permissions tab, select Edit policies.
- Select the policies, then Save.
The Permissions tab lists every policy that applies, and whether it’s attached Directly or Via group.
ezgh iam policies attach ReadOnlyAccess --user ada@example.com
ezgh iam policies attach deployers --bot deployer
ezgh iam policies detach ReadOnlyAccess --group developerscurl -X POST https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/users/$USER_ID/policies/ReadOnlyAccess \
-H "Authorization: Bearer $EZGH_API_KEY"Use the policy’s ID: a managed policy’s name, or a custom policy’s UUID. See AttachUserPolicy, AttachBotPolicy, AttachGroupPolicy, and SetUserPolicies to replace all of a user’s policies.
Check permissions
Ask which actions you’re allowed, on the organization or on one resource. The answer is for whoever makes the request: your session, or the API key’s owner.
ezgh iam permissions check
ezgh iam permissions check projects.delete --resource ezgh::org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2Without actions, it lists every action you’re allowed. With actions, it exits with status 4 if any is denied.
curl "https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/permissions?actions=projects.delete&resource=ezgh::org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2" \
-H "Authorization: Bearer $EZGH_API_KEY"allowed lists the allowed actions on the resource. allowedSomewhere lists the actions allowed on at least one resource. See GetPermissions.
Action reference
Every action a policy can name. Products add their own actions; ezgh iam actions list and ListActions return the current list. AdministratorAccess allows every action; Managed policies lists the other managed policies that allow each one.
Access level is how ReadOnlyAccess treats the action: it allows list and read actions, never write actions.
Organizations
| Action | Description | Access level | Checked against | Managed policies |
|---|---|---|---|---|
organizations.get |
View the organization | Read | Organization | BasicAccess, ReadOnlyAccess, ProjectsFullAccess, BillingFullAccess, IAMFullAccess, OcrFullAccess, OcrReadOnlyAccess |
organizations.update |
Rename the organization | Write | Organization | None |
projects.list |
List projects | List | Project | BasicAccess, ReadOnlyAccess, ProjectsFullAccess, OcrFullAccess, OcrReadOnlyAccess |
projects.get |
View a project | Read | Project | BasicAccess, ReadOnlyAccess, ProjectsFullAccess, OcrFullAccess, OcrReadOnlyAccess |
projects.create |
Create projects | Write | Organization | ProjectsFullAccess |
projects.update |
Rename projects | Write | Project | ProjectsFullAccess |
projects.delete |
Delete projects | Write | Project | ProjectsFullAccess |
IAM
| Action | Description | Access level | Checked against | Managed policies |
|---|---|---|---|---|
users.list |
List the organization’s users | List | Organization | BasicAccess, ReadOnlyAccess, IAMFullAccess |
users.get |
View a user, with their groups and policies | Read | Organization | BasicAccess, ReadOnlyAccess, IAMFullAccess |
users.delete |
Remove users from the organization, revoking their API keys | Write | Organization | IAMFullAccess |
users.reactivate |
Reactivate users your identity provider suspended, after SCIM provisioning is turned off | Write | Organization | IAMFullAccess |
invitations.list |
List invitations to the organization | List | Organization | ReadOnlyAccess, IAMFullAccess |
invitations.get |
View an invitation | Read | Organization | ReadOnlyAccess, IAMFullAccess |
invitations.create |
Invite people to the organization | Write | Organization | IAMFullAccess |
invitations.delete |
Revoke invitations | Write | Organization | IAMFullAccess |
groups.list |
List groups and their members | List | Group | ReadOnlyAccess, IAMFullAccess |
groups.create |
Create groups | Write | Organization | IAMFullAccess |
groups.update |
Rename groups | Write | Group | IAMFullAccess |
groups.delete |
Delete groups | Write | Group | IAMFullAccess |
groups.updateMembers |
Add and remove users and bots in groups | Write | Group | IAMFullAccess |
bots.list |
List bots | List | Bot | BasicAccess, ReadOnlyAccess, IAMFullAccess |
bots.get |
View a bot, with its groups and policies | Read | Bot | BasicAccess, ReadOnlyAccess, IAMFullAccess |
bots.create |
Create bots | Write | Organization | IAMFullAccess |
bots.update |
Rename bots | Write | Bot | IAMFullAccess |
bots.delete |
Delete bots and their API keys | Write | Bot | IAMFullAccess |
bots.createApiKey |
Create API keys that act as a bot | Write | Bot | IAMFullAccess |
apiKeys.list |
List every API key in the organization (everyone sees their own) | List | Organization | ReadOnlyAccess, IAMFullAccess |
apiKeys.create |
Create API keys for yourself | Write | Organization | BasicAccess, IAMFullAccess |
apiKeys.delete |
Revoke any API key (everyone can revoke their own) | Write | Organization | IAMFullAccess |
policies.list |
List and read policies | List | Policy | ReadOnlyAccess, IAMFullAccess |
policies.create |
Create custom policies | Write | Organization | IAMFullAccess |
policies.update |
Edit custom policies | Write | Policy | IAMFullAccess |
policies.delete |
Delete custom policies | Write | Policy | IAMFullAccess |
policies.attach |
Attach and detach policies on users, bots and groups | Write | Organization | IAMFullAccess |
scim.get |
View SCIM provisioning’s settings and status | Read | Organization | ReadOnlyAccess, IAMFullAccess |
scim.tokens.list |
List SCIM tokens | List | Organization | ReadOnlyAccess, IAMFullAccess |
scim.tokens.create |
Create SCIM tokens for an identity provider (turns SCIM provisioning on) | Write | Organization | IAMFullAccess |
scim.tokens.delete |
Delete SCIM tokens (the last one turns SCIM provisioning off) | Write | Organization | IAMFullAccess |
ssoProviders.list |
List SSO identity providers | List | Organization | ReadOnlyAccess, IAMFullAccess |
ssoProviders.create |
Add SSO identity providers | Write | Organization | IAMFullAccess |
ssoProviders.update |
Change how SSO providers’ groups map to EZGH groups | Write | SSO provider | IAMFullAccess |
ssoProviders.delete |
Remove SSO identity providers | Write | SSO provider | IAMFullAccess |
ssoProviders.verifyDomain |
Verify SSO providers’ email domains | Write | SSO provider | IAMFullAccess |
Billing
| Action | Description | Access level | Checked against | Managed policies |
|---|---|---|---|---|
billing.preferences.get |
View billing contact and address | Read | Organization | ReadOnlyAccess, BillingFullAccess |
billing.preferences.update |
Change billing contact and address | Write | Organization | BillingFullAccess |
billing.paymentMethods.list |
List payment methods | List | Organization | ReadOnlyAccess, BillingFullAccess |
billing.paymentMethods.create |
Add payment methods | Write | Organization | BillingFullAccess |
billing.paymentMethods.update |
Change the default payment method | Write | Organization | BillingFullAccess |
billing.paymentMethods.delete |
Remove payment methods | Write | Organization | BillingFullAccess |
billing.balance.get |
View the amount due, credit remaining and estimated bill | Read | Organization | ReadOnlyAccess, BillingFullAccess |
billing.invoices.list |
List invoices | List | Organization | ReadOnlyAccess, BillingFullAccess |
billing.invoices.get |
View invoices and download their PDFs | Read | Organization | ReadOnlyAccess, BillingFullAccess |
billing.ledger.list |
View the billing statement (ledger activity) | List | Organization | ReadOnlyAccess, BillingFullAccess |
billing.costs.get |
View costs and usage | Read | Organization | ReadOnlyAccess, BillingFullAccess |
billing.pricing.get |
View prices | Read | Organization | ReadOnlyAccess, BillingFullAccess |
Trails
| Action | Description | Access level | Checked against | Managed policies |
|---|---|---|---|---|
audit.events.list |
View the organization’s audit log | List | Organization | ReadOnlyAccess |
audit.queries.run |
Run SQL queries on the organization’s audit log | Read | Organization | ReadOnlyAccess |
audit.queries.get |
See an audit log query’s status and results | Read | Organization | ReadOnlyAccess |
audit.queries.list |
See everyone’s audit log query history | List | Organization | ReadOnlyAccess |
audit.queries.cancel |
Cancel running audit log queries | Write | Organization | None |
Service Quotas
| Action | Description | Access level | Checked against | Managed policies |
|---|---|---|---|---|
quotas.quotas.list |
List service quotas, their values and usage | List | Organization | ReadOnlyAccess |
quotas.quotas.get |
View a service quota, its values and usage | Read | Organization | ReadOnlyAccess |
OCR
| Action | Description | Access level | Checked against | Managed policies |
|---|---|---|---|---|
ocr.models.list |
List OCR models | List | Organization | ReadOnlyAccess, OcrFullAccess, OcrReadOnlyAccess |
ocr.models.get |
View an OCR model | Read | Organization | ReadOnlyAccess, OcrFullAccess, OcrReadOnlyAccess |
ocr.processors.list |
List a project’s processors | List | Project | ReadOnlyAccess, OcrFullAccess, OcrReadOnlyAccess |
ocr.processors.create |
Create processors in a project | Write | Project | OcrFullAccess |
ocr.processors.get |
View a processor | Read | Processor | ReadOnlyAccess, OcrFullAccess, OcrReadOnlyAccess |
ocr.processors.update |
Update a processor | Write | Processor | OcrFullAccess |
ocr.processors.delete |
Delete a processor | Write | Processor | OcrFullAccess |
ocr.processors.disable |
Disable a processor | Write | Processor | OcrFullAccess |
ocr.processors.enable |
Enable a processor | Write | Processor | OcrFullAccess |
ocr.documents.process |
Process documents with a processor | Write | Processor | OcrFullAccess |