Available in Classic and VPC
You can set different access permissions for Sub Account using NAVER Cloud Platform's Sub Account service. Sub Account offers both system-managed (System Managed) and user-defined (User Created) policies to help you configure management and operation permissions.
Sub Account is a free service with no additional charges. For more information about Sub Account, see Services > Management & Governance > Sub Account on the NAVER Cloud Platform portal and the Sub Account user guide.
System-managed policies
System-managed policies are pre-built, role-based policies that NAVER Cloud Platform provides for your convenience. When you assign one of these policies to a sub account, that account gets access to Sub Account. Here are the available system-managed policies for Sub Account:
| Policy name | Policy description |
|---|---|
| NCP_ADMINISTRATOR | Full access to all services, same as the main account. |
| NCP_INFRA_MANAGER | Access to all services, except My Account > Manage billing information and expense > Manage billing and payment menu on the console. |
| NCP_FINANCE_MANAGER | Access to only Cost Explorer service and My Account > Manage billing information and expense > Manage billing and payment menu on the console. |
| NCP_SUB_ACCOUNT_MANAGER | Full access to all Sub Account features including External Access. |
| NCP_SUB_ACCOUNT_VIEWER | View-only access to all Sub Account features and lists. |
| NCP_EXTERNAL_ACCESS_MANAGER | Full access to all External Access features. |
| NCP_EXTERNAL_ACCESS_VIEWER | View-only access to all External Access features and lists. |
User-defined policies
User-defined policies let you create custom permissions. When you assign a user-defined policy to a sub account, that account can only perform the specific actions you've allowed. Here are the available user-defined policies for Sub Account:
Sub Account
| Type | Action | Related action | Resource type | Group by resource type | Action description | Applicable condition keys |
|---|---|---|---|---|---|---|
| View | View/getResourceCount | - | - | Dashboard | View Sub Account resource information. | - All principal properties condition keys - ncp:principalTag |
| View | View/getSubAccountList | - | - | SubAccount | View sub account list. | - All principal properties condition keys - ncp:principalTag |
| View | View/getSubAccountDetail | View/getSubAccountList | SubAccount | SubAccount | View sub account details. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| View | View/getSubAccountAccessKey | View/getSubAccountDetail View/getSubAccountList |
SubAccount | SubAccount | View sub account's Access Key. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| View | View/getGroupList | - | - | Group | View group list. | - All principal properties condition keys - ncp:principalTag |
| View | View/getGroupDetail | View/getGroupList | Group | Group | View group details. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| View | View/getPolicyList | - | - | Policy | View policy list created by user. | - All principal properties condition keys - ncp:principalTag |
| View | View/getPolicyDetail | View/getPolicyList | Policy | Policy | View details of policy created by user. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| View | View/validatePolicy | - | - | Policy | View policy validity. | - All principal properties condition keys - ncp:principalTag |
| View | View/getRoleList | - | - | Role | View role list. | - All principal properties condition keys - ncp:principalTag |
| View | View/getRoleDetail | View/getRoleList | Role | Role | View role details. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| View | View/getServerInstanceList | - | - | Role | View server resource list to assign roles. | - All principal properties condition keys - ncp:principalTag |
| View | View/getServerInstanceDetail | View/getServerInstanceList | VPCServer:Server | Role | View Server resource details to assign roles. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| View | View/getStsSessionToken | - | - | STS | Create STS token and view created STS token information. | - All principal properties condition keys - ncp:principalTag |
| Change | Change/manageLoginPageSetting | - | - | Dashboard | Manage access page settings. | - All principal properties condition keys - ncp:principalTag |
| Change | Change/managePasswordSetting | - | - | Dashboard | Manage password settings. | - All principal properties condition keys - ncp:principalTag |
| Change | Change/manageSessionSetting | - | - | Dashboard | Manage session expiration settings. | - All principal properties condition keys - ncp:principalTag |
| Change | Change/createSubAccount | View/getSubAccountList | - | SubAccount | Create sub account. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/updateSubAccount | View/getSubAccountDetail View/getSubAccountList |
SubAccount | SubAccount | Edit sub account. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/deleteSubAccount | View/getSubAccountDetail View/getSubAccountList |
SubAccount | SubAccount | Delete sub account. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/suspendSubAccount | View/getSubAccountDetail View/getSubAccountList |
SubAccount | SubAccount | Temporarily suspend and disconnect sub account. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/resetSubAccountPassword | View/getSubAccountDetail View/getSubAccountList |
SubAccount | SubAccount | Initialize sub account password. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/addPolicyToSubAccount | View/getSubAccountDetail View/getSubAccountList View/getPolicyList View/getPolicyDetail |
SubAccount | SubAccount | Assign policy to sub account. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/removePolicyFromSubAccount | View/getSubAccountDetail View/getSubAccountList |
SubAccount | SubAccount | Delete policy from sub account. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/createSubAccountAccessKey | View/getSubAccountDetail View/getSubAccountList View/getSubAccountAccessKey |
SubAccount | SubAccount | Create sub account's Access Key. | - All principal properties condition keys - ncp:principalTag |
| Change | Change/deleteSubAccountAccessKey | View/getSubAccountDetail View/getSubAccountList View/getSubAccountAccessKey |
SubAccount | SubAccount | Delete sub account's Access Key. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/manageSubAccountAccessKeyState | View/getSubAccountDetail View/getSubAccountList View/getSubAccountAccessKey |
SubAccount | SubAccount | Manage sub account access key status. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/manageSubAccountAllowSourceSetting | View/getSubAccountDetail View/getSubAccountList |
SubAccount | SubAccount | View and edit the source IP or VPC Server that can access the console or API. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/resetSubAccountMFA | getSubAccountList getSubAccountDetail |
SubAccount | SubAccount | Initialize sub account's two-factor authentication settings. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/addSubAccountToGroup | View/getGroupList View/getSubAccountDetail View/getSubAccountList View/getGroupDetail |
Group SubAccount |
Group SubAccount |
Add sub accounts to group. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/removeSubAccountFromGroup | View/getGroupList View/getSubAccountDetail View/getSubAccountList View/getGroupDetail |
Group SubAccount |
Group SubAccount |
Delete sub account from group. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/addPolicyToGroup | View/getGroupList View/getPolicyList View/getPolicyDetail View/getGroupDetail |
Group | Group | Assign policy to group. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/removePolicyFromGroup | View/getGroupList View/getGroupDetail |
Group | Group | Delete policy from group. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/createGroup | View/getGroupList | - | Group | Create groups. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/updateGroup | View/getGroupList View/getGroupDetail |
Group | Group | Edit group information. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/deleteGroup | View/getGroupList View/getGroupDetail |
Group | Group | Delete groups. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/createPolicy | View/getPolicyList | - | Policy | Create new policy. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/updatePolicy | View/getPolicyList View/getPolicyDetail |
Policy | Policy | Change policy created by user. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/deletePolicy | View/getPolicyList View/getPolicyDetail |
Policy | Policy | Delete policy created by user. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/createRole | View/getRoleList | - | Role | Create role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/updateRole | View/getRoleDetail View/getRoleList |
Role | Role | Edit role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/deleteRole | View/getRoleDetail View/getRoleList |
Role | Role | Delete role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/addPolicyToRole | View/getPolicyList View/getRoleDetail View/getRoleList View/getPolicyDetail |
Role | Role | Assign policy to role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/removePolicyFromRole | View/getRoleDetail View/getRoleList |
Role | Role | Delete policy from role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/attachRoleToServer | View/getRoleDetail View/getServerInstanceList View/getRoleList View/getServerInstanceDetail |
Role | Role | Assign role to server resource. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/detachRoleFromServer | View/getRoleDetail View/getRoleList |
Role | Role | Remove roles from server resource. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/suspendRole | View/getRoleDetail View/getRoleList |
Role | Role | Suspend and release roles. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/attachRoleToAccount | View/getRoleDetail View/getRoleList |
Role | Role | Set target accounts in account role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/detachRoleFromAccount | View/getRoleDetail View/getRoleList |
Role | Role | Delete target accounts in account role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/switchRole | - | Role | Role | Switch permissions to the assigned account role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag |
| Change | Change/tagSubAccount | View/getSubAccountList View/getSubAccountDetail |
SubAccount | SubAccount | Assign tag to sub account. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/untagSubAccount | View/getSubAccountList View/getSubAccountDetail |
SubAccount | SubAccount | Delete tag from sub account. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/tagGroup | View/getGroupList View/getGroupDetail |
Group | Group | Assign tag to group. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/untagGroup | View/getGroupList View/getGroupDetail |
Group | Group | Delete tag from group. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/tagPolicy | View/getPolicyList View/getPolicyDetail |
Policy | Policy | Assign tag to policy. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/untagPolicy | View/getPolicyList View/getPolicyDetail |
Policy | Policy | Delete tag from policy. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/tagRole | View/getRoleList View/getRoleDetail |
Role | Role | Assign tag to role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/untagRole | View/getRoleList getRoleDetail |
Role | Role | Delete tag from role. | - All principal properties condition keys - ncp:principalTag - ncp:resourceTag - ncp:requestTag |
| Change | Change/manageLongtermUnusedDeactiveSetting | - | - | Dashboard | Manage the feature to disable sub accounts that have been inactive for an extended period. | - All principal properties condition keys - ncp:principalTag |
External Access
| Type | Action | Related action | Resource type | Group by resource type | Action description | Available condition keys |
|---|---|---|---|---|---|---|
| Change | Change/createTrustAnchor | getCAList getCADetail |
\- | TrustAnchor | Create TrustAnchor. | - All Principal properties condition keys |
| Change | Change/createProfile | getRoleList getRoleDetail |
\- | Profile | Create Profile. | - All Principal properties condition keys |
| Change | Change/deleteTrustAnchor | getTrustAnchorList getTrustAnchorDetail |
TrustAnchor | TrustAnchor | Delete TrustAnchor. | - All Principal properties condition keys |
| Change | Change/disableTrustAnchor | getTrustAnchorList getTrustAnchorDetail |
TrustAnchor | TrustAnchor | Disable TrustAnchor. | - All Principal properties condition keys |
| Change | Change/enableTrustAnchor | getTrustAnchorList getTrustAnchorDetail |
TrustAnchor | TrustAnchor | Enable TrustAnchor. | - All Principal properties condition keys |
| View | View/getTrustAnchorList | \- | \- | TrustAnchor | View list of TrustAnchor. | - All Principal properties condition keys |
| View | View/getTrustAnchorDetail | getTrustAnchorList | TrustAnchor | TrustAnchor | View TrustAnchor details. | - All Principal properties condition keys |
| Change | Change/updateTrustAnchor | getTrustAnchorList getTrustAnchorDetail getCAList getCADetail |
TrustAnchor | TrustAnchor | Edit TrustAnchor. | - All Principal properties condition keys |
| Change | Change/deleteProfile | getProfileList getProfileDetail |
Profile | Profile | Delete Profile. | - All Principal properties condition keys |
| Change | Change/disableProfile | getProfileList getProfileDetail |
Profile | Profile | Disable Profile. | - All Principal properties condition keys |
| Change | Change/enableProfile | getProfileList getProfileDetail |
Profile | Profile | Enable Profile. | - All Principal properties condition keys |
| View | View/getProfileList | \- | \- | Profile | View list of Profile. | - All Principal properties condition keys |
| View | View/getProfileDetail | getProfileList | Profile | Profile | View Profile details. | - All Principal properties condition keys |
| Change | Change/updateProfile | getProfileList getProfileDetail getRoleList getRoleDetail |
Profile | Profile | Edit Profile. | - All Principal properties condition keys |
| View | View/getSubjectList | \- | \- | Subject | View SubjectActivity list. | - All Principal properties condition keys |
| View | View/getSubjectDetail | getSubjectList | Subject | Subject | View SubjectActivity details. | - All Principal properties condition keys |
| View | View/getCAList | \- | \- | TrustAnchor | View CA list. | - All Principal properties condition keys |
| View | View/getCADetail | getCAList | Private CA:CA | TrustAnchor | View CA details. | - All Principal properties condition keys |
| View | View/getRoleList | \- | \- | Profile | View role list. | - All Principal properties condition keys |
| View | View/getRoleDetail | getRoleList | Sub Account:Role | Profile | View role details. | - All Principal properties condition keys |
| Change | Change/importCrl | getTrustAnchorDetail | Crl | Crl | Import Crl. | - All Principal properties condition keys |
| Change | Change/deleteCrl | getTrustAnchorDetail getCrlDetail getCrlList |
Crl | Crl | Delete Crl. | - All Principal properties condition keys |
| Change | Change/disbleCrl | getTrustAnchorDetail getCrlDetail |
Crl | Crl | Disable Crl. | - All Principal properties condition keys |
| Change | Change/enableCrl | getTrustAnchorDetail getCrlDetail |
Crl | Crl | Enable Crl. | - All Principal properties condition keys |
| View | View/getCrlDetail | getTrustAnchorDetail getCrlList |
Crl | Crl | View Crl details. | - All Principal properties condition keys |
| View | View/getCrlList | getTrustAnchorDetail | Crl | Crl | View Crl list. | - All Principal properties condition keys |
If you grant someone access to a specific action but not to the required related actions, they won't be able to complete their tasks. Sub Account automatically includes these related permissions to prevent this issue. However, if you manually uncheck these auto-selected related actions, the system assumes this was intentional and won't override your selection.