Skip to content

Policies

Write policy documents, use managed policies, attach policies, and check permissions.

Updated View as Markdown

A policy is a document of statements that allow or deny actions on resources. You attach policies to users, bots and groups. There are two kinds:

  • Managed policies are built in and the same in every organization. You can’t change or delete them. Their ID is their name, like ReadOnlyAccess.
  • Custom policies are ones you write. Their ID is a UUID, and they also have a policy ID like pol_a1b2c3d4e5f6 and a resource name.

For how policies combine into a decision, see How access is decided.

Policy documents

{
  "statements": [
    {
      "sid": "ReadProjects",
      "effect": "allow",
      "actions": ["projects.list", "projects.get"],
      "resources": ["*"]
    },
    {
      "effect": "deny",
      "actions": ["projects.delete"],
      "resources": ["ezgh:*:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2"]
    }
  ]
}
Field Required Value
statements Yes 1 to 20 statements
sid No A label for the statement, up to 64 characters
effect Yes allow or deny
actions Yes 1 to 100 actions or action patterns
resources Yes 1 to 100 resource names or patterns, each up to 1,024 characters

Field names and effect values are lowercase. Policies have no conditions.

Actions

Actions are named <service>.<verb> or <service>.<resource>.<verb>, like projects.delete or ocr.processors.create. In an action pattern, * matches any run of characters: * is every action, projects.* every projects action, and *.list every list action. Each action or pattern must match at least one existing action; otherwise saving the policy returns 400 with invalid_request. The action reference lists every action.

Resources

A resource name identifies something a policy can target:

Resource Resource name
Organization ezgh::org_k3f9a0x2m7qp
Project ezgh::org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2
Group ezgh::org_k3f9a0x2m7qp:grp_…
Bot ezgh::org_k3f9a0x2m7qp:bot_…
Custom policy ezgh::org_k3f9a0x2m7qp:pol_…
SSO provider ezgh::org_k3f9a0x2m7qp:sso_…
OCR processor ezgh:us-west-1:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2:prc_…

The part after ezgh: is the region, empty for resources that aren’t regional. The console shows each group’s, bot’s and custom policy’s Resource name on its page.

In resources:

  • * alone is everything in the organization.
  • Any other value starts with ezgh:, a region, and your organization’s ID (org_…), written out. A policy can only name resources in its own organization.
  • * matches any run of characters. ezgh:*:org_…:prj_… matches the project, and ezgh:*:org_…:prj_…:* matches everything in it, in any region.
  • A pattern with an empty region can’t end in :*, because it would miss regional resources. Use * as the region instead.

Each action is checked against one resource, shown as Checked against in the action reference. Actions that create things in the organization or act on the whole organization, such as projects.create, organizations.get or users.delete, are checked against the organization. A statement scoped to a project doesn’t allow them. This policy lets its holder see the organization and OCR models, and use OCR processors in one project only:

{
  "statements": [
    {
      "effect": "allow",
      "actions": ["organizations.get", "ocr.models.list", "ocr.models.get"],
      "resources": ["*"]
    },
    {
      "effect": "allow",
      "actions": ["projects.list", "projects.get", "ocr.processors.*", "ocr.documents.process"],
      "resources": [
        "ezgh:*:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2",
        "ezgh:*:org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2:*"
      ]
    }
  ]
}

Listing projects with this policy returns only that project.

Managed policies

Policy What it allows
AdministratorAccess Every action. The root user always has it.
BasicAccess See the organization, its projects, users and bots, and create your own API keys: organizations.get, projects.list, projects.get, users.list, users.get, bots.list, bots.get, apiKeys.create.
ReadOnlyAccess View everything, change nothing: *.get, *.list and audit.queries.run, plus every product’s list and read actions.
ProjectsFullAccess Create, change and delete projects: organizations.get, projects.*.
BillingFullAccess Manage billing details and payment methods: organizations.get, billing.*.
IAMFullAccess Manage users, invitations, groups, bots, API keys, policies, SSO and SCIM: organizations.get, users.*, invitations.*, groups.*, bots.*, apiKeys.*, policies.*, ssoProviders.*, scim.*.
OcrFullAccess Manage OCR processors, read models and process documents: every ocr.* action, plus organizations.get, projects.list, projects.get.
OcrReadOnlyAccess Read OCR processors and models: ocr.models.list, ocr.models.get, ocr.processors.list, ocr.processors.get, plus organizations.get, projects.list, projects.get.

Managed policies apply to everything in the organization. IAMFullAccess includes policies.attach, which lets its holder attach any policy to themselves, so treat it as administrator access.

To see a policy’s full document, open IAM > Policies and select it, or run ezgh iam policies get <policy>.

Create a custom policy

Creating a policy needs policies.create. A policy’s name is 1 to 100 characters and its description up to 1,000.

  1. Open IAM > Policies and select Create policy.
  2. Enter a Name and, optionally, a Description.
  3. Under Applies to, choose Everything in the organization or Only some projects. Select the actions to Allow, and optionally Add denied actions. To write the document yourself, select Edit as JSON.
  4. Review, then select Create policy.
ezgh iam policies create deployers --document @policy.json --description "Deploy to production"
curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/policies \
  -H "Authorization: Bearer $EZGH_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "deployers", "document": {"statements": [{"effect": "allow", "actions": ["projects.*"], "resources": ["*"]}]}}'

See CreatePolicy.

To change a custom policy, select Edit on its page (policies.update), run ezgh iam policies update, or call UpdatePolicy. Changes apply to everyone it’s attached to on their next request. Deleting a custom policy (policies.delete) detaches it from every user, bot and group.

Attach a policy

Attach policies to users, bots and groups. Attaching and detaching needs policies.attach. You can’t change the root user’s policies: the root user always has AdministratorAccess.

  1. Open the user’s, bot’s or group’s page under IAM.
  2. On the Permissions tab, select Edit policies.
  3. Select the policies, then Save.

The Permissions tab lists every policy that applies, and whether it’s attached Directly or Via group.

ezgh iam policies attach ReadOnlyAccess --user ada@example.com
ezgh iam policies attach deployers --bot deployer
ezgh iam policies detach ReadOnlyAccess --group developers
curl -X POST https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/users/$USER_ID/policies/ReadOnlyAccess \
  -H "Authorization: Bearer $EZGH_API_KEY"

Use the policy’s ID: a managed policy’s name, or a custom policy’s UUID. See AttachUserPolicy, AttachBotPolicy, AttachGroupPolicy, and SetUserPolicies to replace all of a user’s policies.

Check permissions

Ask which actions you’re allowed, on the organization or on one resource. The answer is for whoever makes the request: your session, or the API key’s owner.

ezgh iam permissions check
ezgh iam permissions check projects.delete --resource ezgh::org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2

Without actions, it lists every action you’re allowed. With actions, it exits with status 4 if any is denied.

curl "https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/permissions?actions=projects.delete&resource=ezgh::org_k3f9a0x2m7qp:prj_g7h8i9j0k1l2" \
  -H "Authorization: Bearer $EZGH_API_KEY"

allowed lists the allowed actions on the resource. allowedSomewhere lists the actions allowed on at least one resource. See GetPermissions.

Action reference

Every action a policy can name. Products add their own actions; ezgh iam actions list and ListActions return the current list. AdministratorAccess allows every action; Managed policies lists the other managed policies that allow each one.

Access level is how ReadOnlyAccess treats the action: it allows list and read actions, never write actions.

Organizations

Action Description Access level Checked against Managed policies
organizations.get View the organization Read Organization BasicAccess, ReadOnlyAccess, ProjectsFullAccess, BillingFullAccess, IAMFullAccess, OcrFullAccess, OcrReadOnlyAccess
organizations.update Rename the organization Write Organization None
projects.list List projects List Project BasicAccess, ReadOnlyAccess, ProjectsFullAccess, OcrFullAccess, OcrReadOnlyAccess
projects.get View a project Read Project BasicAccess, ReadOnlyAccess, ProjectsFullAccess, OcrFullAccess, OcrReadOnlyAccess
projects.create Create projects Write Organization ProjectsFullAccess
projects.update Rename projects Write Project ProjectsFullAccess
projects.delete Delete projects Write Project ProjectsFullAccess

IAM

Action Description Access level Checked against Managed policies
users.list List the organization’s users List Organization BasicAccess, ReadOnlyAccess, IAMFullAccess
users.get View a user, with their groups and policies Read Organization BasicAccess, ReadOnlyAccess, IAMFullAccess
users.delete Remove users from the organization, revoking their API keys Write Organization IAMFullAccess
users.reactivate Reactivate users your identity provider suspended, after SCIM provisioning is turned off Write Organization IAMFullAccess
invitations.list List invitations to the organization List Organization ReadOnlyAccess, IAMFullAccess
invitations.get View an invitation Read Organization ReadOnlyAccess, IAMFullAccess
invitations.create Invite people to the organization Write Organization IAMFullAccess
invitations.delete Revoke invitations Write Organization IAMFullAccess
groups.list List groups and their members List Group ReadOnlyAccess, IAMFullAccess
groups.create Create groups Write Organization IAMFullAccess
groups.update Rename groups Write Group IAMFullAccess
groups.delete Delete groups Write Group IAMFullAccess
groups.updateMembers Add and remove users and bots in groups Write Group IAMFullAccess
bots.list List bots List Bot BasicAccess, ReadOnlyAccess, IAMFullAccess
bots.get View a bot, with its groups and policies Read Bot BasicAccess, ReadOnlyAccess, IAMFullAccess
bots.create Create bots Write Organization IAMFullAccess
bots.update Rename bots Write Bot IAMFullAccess
bots.delete Delete bots and their API keys Write Bot IAMFullAccess
bots.createApiKey Create API keys that act as a bot Write Bot IAMFullAccess
apiKeys.list List every API key in the organization (everyone sees their own) List Organization ReadOnlyAccess, IAMFullAccess
apiKeys.create Create API keys for yourself Write Organization BasicAccess, IAMFullAccess
apiKeys.delete Revoke any API key (everyone can revoke their own) Write Organization IAMFullAccess
policies.list List and read policies List Policy ReadOnlyAccess, IAMFullAccess
policies.create Create custom policies Write Organization IAMFullAccess
policies.update Edit custom policies Write Policy IAMFullAccess
policies.delete Delete custom policies Write Policy IAMFullAccess
policies.attach Attach and detach policies on users, bots and groups Write Organization IAMFullAccess
scim.get View SCIM provisioning’s settings and status Read Organization ReadOnlyAccess, IAMFullAccess
scim.tokens.list List SCIM tokens List Organization ReadOnlyAccess, IAMFullAccess
scim.tokens.create Create SCIM tokens for an identity provider (turns SCIM provisioning on) Write Organization IAMFullAccess
scim.tokens.delete Delete SCIM tokens (the last one turns SCIM provisioning off) Write Organization IAMFullAccess
ssoProviders.list List SSO identity providers List Organization ReadOnlyAccess, IAMFullAccess
ssoProviders.create Add SSO identity providers Write Organization IAMFullAccess
ssoProviders.update Change how SSO providers’ groups map to EZGH groups Write SSO provider IAMFullAccess
ssoProviders.delete Remove SSO identity providers Write SSO provider IAMFullAccess
ssoProviders.verifyDomain Verify SSO providers’ email domains Write SSO provider IAMFullAccess

Billing

Action Description Access level Checked against Managed policies
billing.preferences.get View billing contact and address Read Organization ReadOnlyAccess, BillingFullAccess
billing.preferences.update Change billing contact and address Write Organization BillingFullAccess
billing.paymentMethods.list List payment methods List Organization ReadOnlyAccess, BillingFullAccess
billing.paymentMethods.create Add payment methods Write Organization BillingFullAccess
billing.paymentMethods.update Change the default payment method Write Organization BillingFullAccess
billing.paymentMethods.delete Remove payment methods Write Organization BillingFullAccess
billing.balance.get View the amount due, credit remaining and estimated bill Read Organization ReadOnlyAccess, BillingFullAccess
billing.invoices.list List invoices List Organization ReadOnlyAccess, BillingFullAccess
billing.invoices.get View invoices and download their PDFs Read Organization ReadOnlyAccess, BillingFullAccess
billing.ledger.list View the billing statement (ledger activity) List Organization ReadOnlyAccess, BillingFullAccess
billing.costs.get View costs and usage Read Organization ReadOnlyAccess, BillingFullAccess
billing.pricing.get View prices Read Organization ReadOnlyAccess, BillingFullAccess

Trails

Action Description Access level Checked against Managed policies
audit.events.list View the organization’s audit log List Organization ReadOnlyAccess
audit.queries.run Run SQL queries on the organization’s audit log Read Organization ReadOnlyAccess
audit.queries.get See an audit log query’s status and results Read Organization ReadOnlyAccess
audit.queries.list See everyone’s audit log query history List Organization ReadOnlyAccess
audit.queries.cancel Cancel running audit log queries Write Organization None

Service Quotas

Action Description Access level Checked against Managed policies
quotas.quotas.list List service quotas, their values and usage List Organization ReadOnlyAccess
quotas.quotas.get View a service quota, its values and usage Read Organization ReadOnlyAccess

OCR

Action Description Access level Checked against Managed policies
ocr.models.list List OCR models List Organization ReadOnlyAccess, OcrFullAccess, OcrReadOnlyAccess
ocr.models.get View an OCR model Read Organization ReadOnlyAccess, OcrFullAccess, OcrReadOnlyAccess
ocr.processors.list List a project’s processors List Project ReadOnlyAccess, OcrFullAccess, OcrReadOnlyAccess
ocr.processors.create Create processors in a project Write Project OcrFullAccess
ocr.processors.get View a processor Read Processor ReadOnlyAccess, OcrFullAccess, OcrReadOnlyAccess
ocr.processors.update Update a processor Write Processor OcrFullAccess
ocr.processors.delete Delete a processor Write Processor OcrFullAccess
ocr.processors.disable Disable a processor Write Processor OcrFullAccess
ocr.processors.enable Enable a processor Write Processor OcrFullAccess
ocr.documents.process Process documents with a processor Write Processor OcrFullAccess
Navigation

Type to search…

↑↓ navigate↵ selectEsc close