Strategy type
Updated at:2025-10-27
IAM identity and access management, in combination with enterprise organization, categorizes policy types into two groups.
Identity-based policy
Attaching policies with permission descriptions to IAM identities (e.g., policies granted to IAM users, groups, or roles) can be further divided into 2 types:
- System policy
System policy refers to preset policies in Baidu AI Cloud, serving as common permission sets for users, such as functional permissions like system administrator and financial personnel, or resource-based product-level read-only and operational permissions. Typically, system policies have coarser permission granularity and cannot be edited or deleted by any user. - Custom policy
Policies created by administrator users are collectively termed custom policies. Users can configure operation permissions for specific product services and resources based on service demands. For example, create a policy for a Baidu Cloud Compute (BCC) instance and associate it with an IAM user to grant operational permissions for that BCC instance. Compared with system policies, custom policies enable finer-grained permission control with greater flexibility.
Custom policies now support configuring multiple service permissions, cross-region resource instances within a single policy, and operation permissions without resource instances, such as create/add, page/button functions.
Service control policy
Service Control Policy (SCP) belongs to extended product enterprise organization of IAM. It does not directly control user permissions, but defines the maximum permission boundary for attached organizational units or sub-accounts. For detailed information about enterprise organizations and SCP, please refer to Enterprise Organization.
