Scenario

Company A is an enterprise user and has multiple project teams that require different resources and personnel. This topic presents the best practice for multi-project management to address company A's requirements.

Requirements

Solution

In conclusion, Enterprise Management provides more flexible cross-region resource isolation between projects than IAM. Therefore, it is recommended that company A use Enterprise Management to manage project resources. The solutions to the following requirements are proposed using the Enterprise Management service. For details about the two services, see What Are the Differences Between IAM and Enterprise Management.
  • Solution to requirement 2: In IAM, company A creates IAM users for employees and adds the IAM users to different groups. In Enterprise Management, company A adds the user groups to the enterprise projects created to address Requirement 1 and assigns required resource access permissions (see Table 1) to each user group.
    Figure 1 Personnel management model of company A
    Table 1 User group permissions in company A

    User Group

    Responsibility

    Permissions

    Description

    Development team

    Project development

    ELB FullAccess

    Full permissions for Elastic Load Balance (ELB)

    OBS Administrator

    Full permissions for Object Storage Service (OBS)

    EPS Admin

    Full permissions for Enterprise Management

    Security maintenance team

    Security O&M of the project

    ECS CommonOperations

    Permissions for basic ECS operations

    Operations team

    Overall operations of the project

    EPS Admin

    Full permissions for Enterprise Management, including modifying, enabling, disabling, and viewing enterprise projects

    For details about system permissions of all cloud services, see Permission Description.