Use Cases

<p class="shortdesc"></p> <section class="section" id="applicationtest123__section_sfl_shd_flb"><h2 class="doc-tairway">Use Case I: Enterprise Sub-account Permission Management</h2> <p class="p">Enterprise F who has a cloud project signs up a master account on Ping AnCloud and purchases multiple cloud services. In the project, several employees need to operate cloud resource in different ways such as procurement and maintenance etc.. They have different responsibility and require various permission. For the sake of enterprise cloud business security, F would not like to directly provide password of the master account to employees. It can open sub-accounts for employees via RAM and authorize different permission based on the work duty of its employees; or it can create user groups, bind them with relevant access policy and add sub-accounts to the user groups for centralized management. For example, User A does not have the access permission of cloud hosts including ECS1, ECS2 and ECS3. Group A has the access permission of cloud host ECS1. Group B has the access permission of cloud host ECS2. If User A is added into Group A and Group B, it will have the access permission of cloud host ECS1 and ECS2. A master account bears the cost for purchasing by a sub-account and is able to modify permission of the sub-account or delete the sub account at any time.</p> <ul class="ul" id="applicationtest123__ul_zjy_thd_flb"> <li class="li">Prevent from sharing the master account among multiple employees to avoid uncontrollable risks due to disclosure of the master account password or Access Key. </li> <li class="li">Assign independent account and authorization to different employees to ensure consistent authority and responsibility. </li> <li class="li">There is no need to calculate the cost of each operator since all charges will be billed on the master account. </li> </ul> <img class="image" id="applicationtest123__image_p31_c3d_flb" src="https://obs-cn-shanghai.yun.pingan.com/pcp-portal/20201604174729-1c78b4cf9107.png" width="800"> </section> <section class="section" id="applicationtest123__section_ogp_shd_flb"><h2 class="doc-tairway">Use Case II: Authorization and Resource Management between Enterprises </h2> <p class="p">Financial enterprise F signs up a master account on Ping AnCloud and purchases cloud service to deploy business applications, but F focuses on business expansion and then entrusts the system operation and maintenance to Enterprise I. Out of data and account security, F does not need to provide the access key of the master account to I and can open up a sub-account for Enterprise I and authorize adequate permission to it via RAM. Enterprise I can further delegate permission to its employees. When the cooperation between F and I ends, F can terminate or delete I’s permission at any time. For instance, it can authorize Group A with two kinds of permissions to operate ECS1, Group B with two kinds of permissions to operate ECS2 and User C with three kinds of permissions to operate ECS3 etc.. </p> <img class="image" id="applicationtest123__image_utn_23d_flb" src="https://obs-cn-shanghai.yun.pingan.com/pcp-portal/20201604174729-110389c598d7.png" width="800"> </section>
Did the above content solve your problem? Yes No
Please complete information!

Call us

400-151-8800

Email us

cloud@pingan.com

Online customer service

Instant reply

Technical Support

cloud products