Skip to main content

Service access permissions

To ensure security, compliance, and separation of duties in a cloud environment, FPT Cloud uses an Identity and Access Management (IAM) module to control who can do what, and on which resources. IAM enables centralized permission management across users, groups, and DBaaS components in the FPT Cloud Portal, enforcing the principle of least privilege by assigning roles to users through groups within a Tenant and VPC scope. **Least privilege principle**: assign only the minimum necessary rights to perform tasks. For instance, grant viewing access only if no configuration or delete actions are required. To perform database provisioning, operation, and management tasks, users must be granted the appropriate IAM permissions. Each action within the FPT Database Engine service is governed by specific permissions. If a user is not assigned a required permission, the corresponding operation will not be available to that user. Permissions are organized into functional domains: service management, database management, backup & restore, notification, monitoring, and reporting. To configure roles and define user groups, refer to the sub-sections below.