Use resource groups for fine-grained access control

Updated at:

You can use Resource Group to manage Chat App Message Service resources as a collection and apply Resource Access Management (RAM) policies that authorize actions only on resources within a specific group. This lets you enforce the principle of least privilege (PoLP) in your Alibaba Cloud account.

Note

You can scope permissions to a resource group only for supported resource types and actions. For unsupported actions, any resource group scope in a policy is ignored, and permissions must be granted at the account level instead.

How it works

Resource groups organize your resources by project or environment. Once resources are grouped, you can attach a RAM policy to an identity (such as a RAM user, user group, or role) that scopes its permissions exclusively to that group. For more information, see Resource grouping and authorization.

This approach provides two key benefits:

  • Fine-grained access control: Instead of granting account-wide permissions, you can limit an identity's access to only the resources within a specific group. This helps isolate project-specific workloads and reduce the risk of unintended access.

  • Simplified management: When new resources are added to a resource group, RAM identities with permissions scoped to that group automatically gain access. You do not need to update RAM policies each time a new resource is created.

Grant resource group-level permissions to a RAM user

This section demonstrates how to grant a RAM user permission to access only the resources of Chat App Message Service within a specific resource group.

1. Prerequisites

2. Grant permissions

You can grant resource group-level permissions from either the Resource Management console or the RAM console.

Resource Management console

  • Log on to the Resource Management console.

  • On the Resource Group page, find the target resource group and click Permission Management in the Actions column.

  • On the Permissions tab, click Grant Permission.

  • In the Grant Permission panel, configure the principal and access policy.

  • Click OK.

For more information, see Grant permissions on resource groups to a RAM identity.

RAM console

  • Log on to the RAM console using an Alibaba Cloud account or a RAM administrator account.

  • In the navigation pane on the left, choose Identities > Users. On the Users page, find the target RAM user and click Attach Policy in the Actions column.

  • In the Attach Policy panel, add permissions for the RAM user.

    • Resource Scope: Select Resource Group.

    • Principal: Select an existing RAM user or the RAM user created in the previous step.

    • Policy: Select a System Policy or a Custom Policy. For more information, see Create a custom permission policy.

  • Click OK.

For more information, see Manage RAM user permissions.

Supported resources

The following resources from Chat App Message Service support resource group-level authorization:

Alibaba Cloud service

Service code

Resource type

Chat App Message Service

cams

instance : instance

Note

To request support for resource types not listed here, submit feedback via Resource Management console.

image

Unsupported actions

The following actions of Chat App Message Service do not support resource group-level authorization:

Action

Description

cams:AddAddressRecoverSuspend

-

cams:AddAuditViberOpen

-

cams:AddChatGroup

AddChatGroup

cams:AddChatGroupInviteLink

AddChatGroupInviteLink

cams:AddChatappPhoneNumber

Adds a phone number for a WhatsApp Business account (WABA).

cams:AddContacts

-

cams:AddCust

-

cams:AddCustomAudienceUser

-

cams:AddFacebookSource

-

cams:AddGroup

-

cams:AddHref

-

cams:AddInstagramContainer

-

cams:AddMarketingFLow

-

cams:AddMarketingFlow

-

cams:AddTelegram

-

cams:AddTemplate

-

cams:AssociateContact

-

cams:AssociateContactWithGroup

-

cams:BatchDeleteTemplate

-

cams:BindAgent

-

cams:BindDmAccount

-

cams:BindInstagramPage

-

cams:BindMessengerPage

-

cams:ChatAppWebPost

-

cams:ChatappBindWaba

Binds the WhatsApp Business account with ChatApp.

cams:ChatappEmbedSignUp

-

cams:ChatappMigrationRegister

Registers a phone number for migration.

cams:ChatappMigrationVerified

Verifies a specified phone number for migration.

cams:ChatappPhoneNumberDeregister

Deregisters a phone number from a WhatsApp Business account (WABA).

cams:ChatappPhoneNumberRegister

Registers a phone number.

cams:ChatappSyncPhoneNumber

Synchronizes phone numbers.

cams:ChatappVerifyAndRegister

Associates a phone number with a WhatsApp Business account (WABA).

cams:CheckCust

-

cams:CheckDirectSendMessageSample

-

cams:ConsoleQueryChatbotInfo

-

cams:CopyTemplate

-

cams:CpassGetInstagramPages

-

cams:CpassGetMessengerPages

-

cams:CpassInstagramBindPage

-

cams:CpassMessengerBindPage

-

cams:CpassModifyWebhook

-

cams:CreateChatFlow

Create Chatflow

cams:CreateChatFlowByImport

Import and create flow

cams:CreateChatFlowLogSetting

Create chatFlow log setting

cams:CreateChatappMigrationInitiate

The ID of the number.

cams:CreateChatappTemplate

The HTTP status code. \\\\* Example: OK. This parameter indicates that the request is successful. \\\\* Other values indicate that the request fails. For more information, see \\\\[Error codes]\\\(https://www.alibabacloud.com/help/zh/cams/latest/api-error-codes).

cams:CreateCustomAudience

-

cams:CreateFlow

Creates a Flow.

cams:CreateFlowVersion

CreateFlowVersion

cams:CreateMassPlanning

-

cams:CreateMessageCampaign

-

cams:CreateMessengerPage

-

cams:CreateMixTemplateAuditOrder

-

cams:CreatePhoneMessageQrdl

Creates a quick-response (QR) code that contains a message.

cams:CreateWhatsappConversionApi

-

cams:DeleteAgent

-

cams:DeleteChatFlow

Delete Process

cams:DeleteChatGroup

DeleteChatGroup

cams:DeleteChatGroupInviteLink

DeleteChatGroupInviteLink

cams:DeleteChatGroupParticipants

DeleteChatGroupParticipants

cams:DeleteChatParticipants

-

cams:DeleteChatappTemplate

Deletes a message template.

cams:DeleteContacts

-

cams:DeleteContactsByIds

-

cams:DeleteFlow

Deletes a Flow. Only Flows in the DRAFT state can be deleted.

cams:DeleteFlowVersion

Delete Flow Version

cams:DeleteGroupById

-

cams:DeleteInstagramPage

-

cams:DeleteMarketingFlow

-

cams:DeleteMessageCampaign

-

cams:DeleteMessengerPage

-

cams:DeleteMixMessage

-

cams:DeletePhoneMessageQrdl

Deletes a quick-response (QR) code that contains a message.

cams:DeprecateFlow

Deprecates a Flow.

cams:EnableScheduling

-

cams:EnableWhatsappROIMetric

Enables the statistics on the metrics that are related to WhatsApp.

cams:ExportBlockUsers

-

cams:FacebookDelete

-

cams:FacebookFeed

-

cams:FlowBindPhone

Bind phone numbers to flow

cams:FlowRebindPhone

Rebind phone number for flow

cams:FlowUnbindPhone

Unbind phone number from flow

cams:GenerateBillMonthDownloadTask

-

cams:GeneratePersonalizedBillMonthDownloadTask

-

cams:GeneratePresignedUrl

-

cams:GetAuditRequestByTypeUnAudit

-

cams:GetAutoGeneratedTemplate

-

cams:GetBillMonthDownloadTaskResult

-

cams:GetBillUpgradeLayerInfo

-

cams:GetBillViewDescription

-

cams:GetBillingDetailDownloadTaskResult

-

cams:GetBindAgentAttribute

-

cams:GetChatFlowMetric

Get ChatFlow Runtime Data

cams:GetChatFlowMetricAnalyze

-

cams:GetChatFlowTemplate

Query chatFlow template

cams:GetChatGroupInfo

-

cams:GetChatOptionInfo

-

cams:GetChatappConversationMetric

-

cams:GetChatappOpenStatus

-

cams:GetChatappPhoneNumberMetric

Queries the number of messages that are sent by using a phone number by a specific metric.

cams:GetChatappPhoneNumberSetting

-

cams:GetChatappTemplateDetail

Queries the information of a message template.

cams:GetChatappTemplateMetric

Queries the metrics about a marketing template.

cams:GetChatappUploadAuthorization

Obtains the authentication information that is used to upload a file.

cams:GetChatappVerifyCode

Obtains a verification code.

cams:GetCommerceSetting

Queries the business settings of a phone number.

cams:GetContactsByGroupId

-

cams:GetContactsExcelTemplate

-

cams:GetContactsList

-

cams:GetConversationalAutomation

Configures welcoming messages, opening remarks, and commands.

cams:GetCountByPartner

-

cams:GetCountryList

-

cams:GetCurrentRole

-

cams:GetCustAuditLog

-

cams:GetCustByCode

-

cams:GetCustomTask

-

cams:GetCustomerSite

-

cams:GetDefaultLanguage

-

cams:GetDownloadApplicationMaterials

-

cams:GetDownloadExcelList

-

cams:GetFbInstagramPages

-

cams:GetFbMessengerAdInfo

-

cams:GetFbMessengerPages

-

cams:GetFileStringByFileName

-

cams:GetFlow

Queries the information about a Flow.

cams:GetFlowJSONAssest

Queries the JSON content of a Flow.

cams:GetFlowPreviewUrl

Obtains the preview URL of a Flow.

cams:GetGroupExist

-

cams:GetHrefInfo

-

cams:GetMessageCampaignInsights

-

cams:GetMigrationVerifyCode

Obtain the verification code for the migration number.

cams:GetNLGenChatFlow

-

cams:GetNLGenChatFlowPromptExpansion

-

cams:GetNLGenChatFlowPromptOptimization

-

cams:GetNLTranslateTemplate

-

cams:GetOSSInfoForUploadFile

-

cams:GetOssConfig

-

cams:GetOssInfoForUploadFile

-

cams:GetPermissionByCode

Obtains permissions based on the authorization code obtained from embedded signup.

cams:GetPersonalizedBillConfig

-

cams:GetPersonalizedBillMonthDownloadTaskResult

-

cams:GetPhoneEncryptionPublicKey

Queries the encryption public key of a phone number.

cams:GetPhoneNumberVerificationStatus

Obtains the verification status of a phone number.

cams:GetPledgeTemplateAddress

-

cams:GetPreValidatePhoneId

Obtains the ID of a pre-registered phone number used for embedded signup without the need to re-obtain a verification code.

cams:GetSearchTreeData

-

cams:GetTelegramPage

-

cams:GetUserBill

-

cams:GetUserBillLadderSegmentDetail

-

cams:GetUserInstanceBillLadderSegmentDetail

-

cams:GetUserStatus

-

cams:GetViberByRequestNo

-

cams:GetViberPauseTimes

-

cams:GetWhatsappConnectionCatalog

Queries the product catalogs that are associated with a WhatsApp Business account (WABA).

cams:GetWhatsappConversionApi

-

cams:GetWhatsappHealthStatus

Queries the messaging health status of different types of nodes.

cams:GetWhatsappInsights

-

cams:GetWhiteList

-

cams:InstagramFeed

-

cams:IsPostPaidCustomer

-

cams:IsvGetAppId

Obtains the application ID under the ISV account.

cams:ListAdvert

-

cams:ListAllAudit

-

cams:ListAllGroups

-

cams:ListAuditAndFailByType

-

cams:ListBaseTemplate

-

cams:ListBindDmAccount

-

cams:ListBindingRelationsForFlowVersion

Query Bound List Based on flowCode

cams:ListBlockUsers

-

cams:ListChannelsForBinding

-

cams:ListChatFlow

List Flows

cams:ListChatFlowTemplate

ChatFlow Template List

cams:ListChatGroup

ListChatGroup

cams:ListChatGroupParticipants

ListChatGroupParticipants

cams:ListChatappMessage

-

cams:ListChatappTemplate

Queries message templates.

cams:ListCountByBar

-

cams:ListCountByLine

-

cams:ListCountry

-

cams:ListCust

-

cams:ListCustomAudience

-

cams:ListCustomBillTab

-

cams:ListCustomTask

-

cams:ListDayUseDetail

-

cams:ListDict

-

cams:ListDmAccount

-

cams:ListDmTag

-

cams:ListFacebookPosts

-

cams:ListFlow

Queries a list of Flows.

cams:ListFlowNodeGroup

-

cams:ListFlowNodePrototypeV2

ListFlowNodePrototypeV2

cams:ListFlowVersion

List Flow Versions

cams:ListHref

-

cams:ListInstagramPage

-

cams:ListInstagramPosts

-

cams:ListIntent

-

cams:ListLanguage

-

cams:ListMarketingFlow

-

cams:ListMessageCampaign

-

cams:ListMessageType

-

cams:ListMessengerPage

-

cams:ListMessengerSubscriptionToken

-

cams:ListMixMessage

-

cams:ListOwnViberAudit

-

cams:ListOwnViberChangeDest

-

cams:ListPageAdAccount

-

cams:ListPhoneMessageQrdl

Queries the information about a list of quick-response (QR) codes that contain messages.

cams:ListProduct

Queries products in a product catalog.

cams:ListProductCatalog

Queries the product catalogs on the Business Manager platform of Meta.

cams:ListReleaseRecords

-

cams:ListSenderIdReport

-

cams:ListSwitchVariable

-

cams:ListTemplateLanguage

-

cams:ListTemplateParam

-

cams:ListUserBillDetail

-

cams:ListUserBillingInstanceBillDetail

-

cams:ListVariableType

-

cams:ListViberServiceMessage

-

cams:ListWabaIdByInputToken

-

cams:ModifyBlockUsers

-

cams:ModifyChatappPhoneNumber

-

cams:ModifyChatappTemplate

The code of the message template.

cams:ModifyChatappTemplateProperties

-

cams:ModifyFlow

Modifies the basic information about a Flow.

cams:ModifyPhoneBusinessProfile

The ID of the request.

cams:ModifyWebhook

-

cams:MoveContactToGroup

-

cams:OfflineFlowVersion

Offline Flow Version

cams:OnlineFlowVersion

Online Flow Version

cams:OpenChatappService

-

cams:OpenProduct

-

cams:PagePersonalizedBill

-

cams:PauseMarketingFLow

-

cams:PublishFlow

Publishes a Flow.

cams:QueryChatappBindWaba

Query the WhatsApp Business account you associate with ChatApp.

cams:QueryChatappPhoneNumbers

Queries phone numbers that receive messages and statuses of these numbers under a specified user.

cams:QueryMMLActive

-

cams:QueryPackageDetail

-

cams:QueryPackageSummary

-

cams:QueryPackageType

-

cams:QueryPhoneBusinessProfile

Queries the business information of the account to which a specified phone number is bound.

cams:QueryProductOpenStatus

-

cams:QueryThreshold

-

cams:QueryTokenForMnsQueue

-

cams:QueryWabaBusinessInfo

Queries the business information about the WhatsApp Business account (WABA).

cams:QueryWabaByEmbedSignUp

-

cams:RamUserIsOpen

-

cams:RamUserOpen

-

cams:ReadChatFlow

Retrieve Flow

cams:ReadChatFlowLogSetting

View chatFlow log settings

cams:ReadFlowVersion

Get Flow Version

cams:RemoveContactById

-

cams:RemoveContacts

-

cams:RequestWhatsappConversionApi

-

cams:SendChatAppMessage

-

cams:SendChatappMassMessage

Sends a message to multiple phone numbers by using ChatAPP at a time.

cams:SendChatappMessage

Sends messages by using ChatAPP.

cams:SendSafetyControl

-

cams:SubmitIsvCustomerTerms

-

cams:SyncBusinessAppHistory

-

cams:SyncChatGroup

-

cams:SyncFlow

-

cams:SyncMessageCampaign

-

cams:SyncMessengerSubscriptionToken

-

cams:TranslateCustToIsv

-

cams:TriggerChatFlow

Trigger an Online ChatFlow

cams:UnbindDmAccount

-

cams:UpdateAccountWebhook

Modifies the callback URL of an account.

cams:UpdateAuditRequest

-

cams:UpdateChatFlow

Get Process

cams:UpdateChatFlowLogSetting

Modify chatFlow log settings

cams:UpdateChatGroup

UpdateChatGroup

cams:UpdateChatappPhoneNumberSetting

-

cams:UpdateCheckCode

-

cams:UpdateCommerceSetting

Modifies the business settings of a phone number.

cams:UpdateContactById

-

cams:UpdateConversationalAutomation

Modifies welcoming messages, opening remarks, and commands for a phone number.

cams:UpdateCust

-

cams:UpdateFlowJSONAsset

Updates a Flow by using JSON content.

cams:UpdateFlowVersion

Update flow version, used for updating the flow DSL on the canvas

cams:UpdateGroupName

-

cams:UpdateHref

-

cams:UpdateMarketingFLow

-

cams:UpdatePackageRemainAlarmThreshold

-

cams:UpdatePackgeRemainAlarmThreshold

-

cams:UpdatePersonalizedBillConfig

-

cams:UpdatePhoneEncryptionPublicKey

Updates the encryption public key of a phone number.

cams:UpdatePhoneMessageQrdl

Modifies a quick-response (QR) code that contains a message.

cams:UpdatePhoneWebhook

The HTTP status code returned. \* A value of OK indicates that the call is successful. \* Other values indicate that the call fails. For more information, see \[Error codes]\(~~196974~~).

cams:UpdateViberWebhook

-

cams:UpdateWabaMmlStatus

-

cams:WhatsappCall

-

cams:WorkbenchSendMessage

-

For these actions, you must create a custom policy with the scope set to Account.

image.pngCustomize the following policy examples to suit your needs:

  • Allow read-only access

    {
      "Version": "1",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "cams:GetAuditRequestByTypeUnAudit",
            "cams:GetAutoGeneratedTemplate",
            "cams:GetBillMonthDownloadTaskResult",
            "cams:GetBillUpgradeLayerInfo",
            "cams:GetBillViewDescription",
            "cams:GetBillingDetailDownloadTaskResult",
            "cams:GetBindAgentAttribute",
            "cams:GetChatFlowMetric",
            "cams:GetChatFlowMetricAnalyze",
            "cams:GetChatFlowTemplate",
            "cams:GetChatGroupInfo",
            "cams:GetChatOptionInfo",
            "cams:GetChatappConversationMetric",
            "cams:GetChatappOpenStatus",
            "cams:GetChatappPhoneNumberMetric",
            "cams:GetChatappPhoneNumberSetting",
            "cams:GetChatappTemplateDetail",
            "cams:GetChatappTemplateMetric",
            "cams:GetChatappUploadAuthorization",
            "cams:GetChatappVerifyCode",
            "cams:GetCommerceSetting",
            "cams:GetContactsByGroupId",
            "cams:GetContactsExcelTemplate",
            "cams:GetContactsList",
            "cams:GetConversationalAutomation",
            "cams:GetCountByPartner",
            "cams:GetCountryList",
            "cams:GetCurrentRole",
            "cams:GetCustAuditLog",
            "cams:GetCustByCode",
            "cams:GetCustomTask",
            "cams:GetCustomerSite",
            "cams:GetDefaultLanguage",
            "cams:GetDownloadApplicationMaterials",
            "cams:GetDownloadExcelList",
            "cams:GetFbInstagramPages",
            "cams:GetFbMessengerAdInfo",
            "cams:GetFbMessengerPages",
            "cams:GetFileStringByFileName",
            "cams:GetFlow",
            "cams:GetFlowJSONAssest",
            "cams:GetFlowPreviewUrl",
            "cams:GetGroupExist",
            "cams:GetHrefInfo",
            "cams:GetMessageCampaignInsights",
            "cams:GetMigrationVerifyCode",
            "cams:GetNLGenChatFlow",
            "cams:GetNLGenChatFlowPromptExpansion",
            "cams:GetNLGenChatFlowPromptOptimization",
            "cams:GetNLTranslateTemplate",
            "cams:GetOSSInfoForUploadFile",
            "cams:GetOssConfig",
            "cams:GetOssInfoForUploadFile",
            "cams:GetPermissionByCode",
            "cams:GetPersonalizedBillConfig",
            "cams:GetPersonalizedBillMonthDownloadTaskResult",
            "cams:GetPhoneEncryptionPublicKey",
            "cams:GetPhoneNumberVerificationStatus",
            "cams:GetPledgeTemplateAddress",
            "cams:GetPreValidatePhoneId",
            "cams:GetSearchTreeData",
            "cams:GetTelegramPage",
            "cams:GetUserBill",
            "cams:GetUserBillLadderSegmentDetail",
            "cams:GetUserInstanceBillLadderSegmentDetail",
            "cams:GetUserStatus",
            "cams:GetViberByRequestNo",
            "cams:GetViberPauseTimes",
            "cams:GetWhatsappConnectionCatalog",
            "cams:GetWhatsappConversionApi",
            "cams:GetWhatsappHealthStatus",
            "cams:GetWhatsappInsights",
            "cams:GetWhiteList",
            "cams:ListAdvert",
            "cams:ListAllAudit",
            "cams:ListAllGroups",
            "cams:ListAuditAndFailByType",
            "cams:ListBaseTemplate",
            "cams:ListBindDmAccount",
            "cams:ListBindingRelationsForFlowVersion",
            "cams:ListBlockUsers",
            "cams:ListChannelsForBinding",
            "cams:ListChatFlow",
            "cams:ListChatFlowTemplate",
            "cams:ListChatGroup",
            "cams:ListChatGroupParticipants",
            "cams:ListChatappMessage",
            "cams:ListChatappTemplate",
            "cams:ListCountByBar",
            "cams:ListCountByLine",
            "cams:ListCountry",
            "cams:ListCust",
            "cams:ListCustomAudience",
            "cams:ListCustomBillTab",
            "cams:ListCustomTask",
            "cams:ListDayUseDetail",
            "cams:ListDict",
            "cams:ListDmAccount",
            "cams:ListDmTag",
            "cams:ListFacebookPosts",
            "cams:ListFlow",
            "cams:ListFlowNodeGroup",
            "cams:ListFlowNodePrototypeV2",
            "cams:ListFlowVersion",
            "cams:ListHref",
            "cams:ListInstagramPage",
            "cams:ListInstagramPosts",
            "cams:ListIntent",
            "cams:ListLanguage",
            "cams:ListMarketingFlow",
            "cams:ListMessageCampaign",
            "cams:ListMessageType",
            "cams:ListMessengerPage",
            "cams:ListMessengerSubscriptionToken",
            "cams:ListMixMessage",
            "cams:ListOwnViberAudit",
            "cams:ListOwnViberChangeDest",
            "cams:ListPageAdAccount",
            "cams:ListPhoneMessageQrdl",
            "cams:ListProduct",
            "cams:ListProductCatalog",
            "cams:ListReleaseRecords",
            "cams:ListSenderIdReport",
            "cams:ListSwitchVariable",
            "cams:ListTemplateLanguage",
            "cams:ListTemplateParam",
            "cams:ListUserBillDetail",
            "cams:ListUserBillingInstanceBillDetail",
            "cams:ListVariableType",
            "cams:ListViberServiceMessage",
            "cams:ListWabaIdByInputToken"
          ],
          "Resource": "*"
        }
      ]
    }
    
  • Allow full access

    {
      "Version": "1",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "cams:AddAddressRecoverSuspend",
            "cams:AddAuditViberOpen",
            "cams:AddChatGroup",
            "cams:AddChatGroupInviteLink",
            "cams:AddChatappPhoneNumber",
            "cams:AddContacts",
            "cams:AddCust",
            "cams:AddCustomAudienceUser",
            "cams:AddFacebookSource",
            "cams:AddGroup",
            "cams:AddHref",
            "cams:AddInstagramContainer",
            "cams:AddMarketingFLow",
            "cams:AddMarketingFlow",
            "cams:AddTelegram",
            "cams:AddTemplate",
            "cams:AssociateContact",
            "cams:AssociateContactWithGroup",
            "cams:BatchDeleteTemplate",
            "cams:BindAgent",
            "cams:BindDmAccount",
            "cams:BindInstagramPage",
            "cams:BindMessengerPage",
            "cams:ChatAppWebPost",
            "cams:ChatappBindWaba",
            "cams:ChatappEmbedSignUp",
            "cams:ChatappMigrationRegister",
            "cams:ChatappMigrationVerified",
            "cams:ChatappPhoneNumberDeregister",
            "cams:ChatappPhoneNumberRegister",
            "cams:ChatappSyncPhoneNumber",
            "cams:ChatappVerifyAndRegister",
            "cams:CheckCust",
            "cams:CheckDirectSendMessageSample",
            "cams:ConsoleQueryChatbotInfo",
            "cams:CopyTemplate",
            "cams:CpassGetInstagramPages",
            "cams:CpassGetMessengerPages",
            "cams:CpassInstagramBindPage",
            "cams:CpassMessengerBindPage",
            "cams:CpassModifyWebhook",
            "cams:CreateChatFlow",
            "cams:CreateChatFlowByImport",
            "cams:CreateChatFlowLogSetting",
            "cams:CreateChatappMigrationInitiate",
            "cams:CreateChatappTemplate",
            "cams:CreateCustomAudience",
            "cams:CreateFlow",
            "cams:CreateFlowVersion",
            "cams:CreateMassPlanning",
            "cams:CreateMessageCampaign",
            "cams:CreateMessengerPage",
            "cams:CreateMixTemplateAuditOrder",
            "cams:CreatePhoneMessageQrdl",
            "cams:CreateWhatsappConversionApi",
            "cams:DeleteAgent",
            "cams:DeleteChatFlow",
            "cams:DeleteChatGroup",
            "cams:DeleteChatGroupInviteLink",
            "cams:DeleteChatGroupParticipants",
            "cams:DeleteChatParticipants",
            "cams:DeleteChatappTemplate",
            "cams:DeleteContacts",
            "cams:DeleteContactsByIds",
            "cams:DeleteFlow",
            "cams:DeleteFlowVersion",
            "cams:DeleteGroupById",
            "cams:DeleteInstagramPage",
            "cams:DeleteMarketingFlow",
            "cams:DeleteMessageCampaign",
            "cams:DeleteMessengerPage",
            "cams:DeleteMixMessage",
            "cams:DeletePhoneMessageQrdl",
            "cams:DeprecateFlow",
            "cams:EnableScheduling",
            "cams:EnableWhatsappROIMetric",
            "cams:ExportBlockUsers",
            "cams:FacebookDelete",
            "cams:FacebookFeed",
            "cams:FlowBindPhone",
            "cams:FlowRebindPhone",
            "cams:FlowUnbindPhone",
            "cams:GenerateBillMonthDownloadTask",
            "cams:GeneratePersonalizedBillMonthDownloadTask",
            "cams:GeneratePresignedUrl",
            "cams:GetAuditRequestByTypeUnAudit",
            "cams:GetAutoGeneratedTemplate",
            "cams:GetBillMonthDownloadTaskResult",
            "cams:GetBillUpgradeLayerInfo",
            "cams:GetBillViewDescription",
            "cams:GetBillingDetailDownloadTaskResult",
            "cams:GetBindAgentAttribute",
            "cams:GetChatFlowMetric",
            "cams:GetChatFlowMetricAnalyze",
            "cams:GetChatFlowTemplate",
            "cams:GetChatGroupInfo",
            "cams:GetChatOptionInfo",
            "cams:GetChatappConversationMetric",
            "cams:GetChatappOpenStatus",
            "cams:GetChatappPhoneNumberMetric",
            "cams:GetChatappPhoneNumberSetting",
            "cams:GetChatappTemplateDetail",
            "cams:GetChatappTemplateMetric",
            "cams:GetChatappUploadAuthorization",
            "cams:GetChatappVerifyCode",
            "cams:GetCommerceSetting",
            "cams:GetContactsByGroupId",
            "cams:GetContactsExcelTemplate",
            "cams:GetContactsList",
            "cams:GetConversationalAutomation",
            "cams:GetCountByPartner",
            "cams:GetCountryList",
            "cams:GetCurrentRole",
            "cams:GetCustAuditLog",
            "cams:GetCustByCode",
            "cams:GetCustomTask",
            "cams:GetCustomerSite",
            "cams:GetDefaultLanguage",
            "cams:GetDownloadApplicationMaterials",
            "cams:GetDownloadExcelList",
            "cams:GetFbInstagramPages",
            "cams:GetFbMessengerAdInfo",
            "cams:GetFbMessengerPages",
            "cams:GetFileStringByFileName",
            "cams:GetFlow",
            "cams:GetFlowJSONAssest",
            "cams:GetFlowPreviewUrl",
            "cams:GetGroupExist",
            "cams:GetHrefInfo",
            "cams:GetMessageCampaignInsights",
            "cams:GetMigrationVerifyCode",
            "cams:GetNLGenChatFlow",
            "cams:GetNLGenChatFlowPromptExpansion",
            "cams:GetNLGenChatFlowPromptOptimization",
            "cams:GetNLTranslateTemplate",
            "cams:GetOSSInfoForUploadFile",
            "cams:GetOssConfig",
            "cams:GetOssInfoForUploadFile",
            "cams:GetPermissionByCode",
            "cams:GetPersonalizedBillConfig",
            "cams:GetPersonalizedBillMonthDownloadTaskResult",
            "cams:GetPhoneEncryptionPublicKey",
            "cams:GetPhoneNumberVerificationStatus",
            "cams:GetPledgeTemplateAddress",
            "cams:GetPreValidatePhoneId",
            "cams:GetSearchTreeData",
            "cams:GetTelegramPage",
            "cams:GetUserBill",
            "cams:GetUserBillLadderSegmentDetail",
            "cams:GetUserInstanceBillLadderSegmentDetail",
            "cams:GetUserStatus",
            "cams:GetViberByRequestNo",
            "cams:GetViberPauseTimes",
            "cams:GetWhatsappConnectionCatalog",
            "cams:GetWhatsappConversionApi",
            "cams:GetWhatsappHealthStatus",
            "cams:GetWhatsappInsights",
            "cams:GetWhiteList",
            "cams:InstagramFeed",
            "cams:IsPostPaidCustomer",
            "cams:IsvGetAppId",
            "cams:ListAdvert",
            "cams:ListAllAudit",
            "cams:ListAllGroups",
            "cams:ListAuditAndFailByType",
            "cams:ListBaseTemplate",
            "cams:ListBindDmAccount",
            "cams:ListBindingRelationsForFlowVersion",
            "cams:ListBlockUsers",
            "cams:ListChannelsForBinding",
            "cams:ListChatFlow",
            "cams:ListChatFlowTemplate",
            "cams:ListChatGroup",
            "cams:ListChatGroupParticipants",
            "cams:ListChatappMessage",
            "cams:ListChatappTemplate",
            "cams:ListCountByBar",
            "cams:ListCountByLine",
            "cams:ListCountry",
            "cams:ListCust",
            "cams:ListCustomAudience",
            "cams:ListCustomBillTab",
            "cams:ListCustomTask",
            "cams:ListDayUseDetail",
            "cams:ListDict",
            "cams:ListDmAccount",
            "cams:ListDmTag",
            "cams:ListFacebookPosts",
            "cams:ListFlow",
            "cams:ListFlowNodeGroup",
            "cams:ListFlowNodePrototypeV2",
            "cams:ListFlowVersion",
            "cams:ListHref",
            "cams:ListInstagramPage",
            "cams:ListInstagramPosts",
            "cams:ListIntent",
            "cams:ListLanguage",
            "cams:ListMarketingFlow",
            "cams:ListMessageCampaign",
            "cams:ListMessageType",
            "cams:ListMessengerPage",
            "cams:ListMessengerSubscriptionToken",
            "cams:ListMixMessage",
            "cams:ListOwnViberAudit",
            "cams:ListOwnViberChangeDest",
            "cams:ListPageAdAccount",
            "cams:ListPhoneMessageQrdl",
            "cams:ListProduct",
            "cams:ListProductCatalog",
            "cams:ListReleaseRecords",
            "cams:ListSenderIdReport",
            "cams:ListSwitchVariable",
            "cams:ListTemplateLanguage",
            "cams:ListTemplateParam",
            "cams:ListUserBillDetail",
            "cams:ListUserBillingInstanceBillDetail",
            "cams:ListVariableType",
            "cams:ListViberServiceMessage",
            "cams:ListWabaIdByInputToken",
            "cams:ModifyBlockUsers",
            "cams:ModifyChatappPhoneNumber",
            "cams:ModifyChatappTemplate",
            "cams:ModifyChatappTemplateProperties",
            "cams:ModifyFlow",
            "cams:ModifyPhoneBusinessProfile",
            "cams:ModifyWebhook",
            "cams:MoveContactToGroup",
            "cams:OfflineFlowVersion",
            "cams:OnlineFlowVersion",
            "cams:OpenChatappService",
            "cams:OpenProduct",
            "cams:PagePersonalizedBill",
            "cams:PauseMarketingFLow",
            "cams:PublishFlow",
            "cams:QueryChatappBindWaba",
            "cams:QueryChatappPhoneNumbers",
            "cams:QueryMMLActive",
            "cams:QueryPackageDetail",
            "cams:QueryPackageSummary",
            "cams:QueryPackageType",
            "cams:QueryPhoneBusinessProfile",
            "cams:QueryProductOpenStatus",
            "cams:QueryThreshold",
            "cams:QueryTokenForMnsQueue",
            "cams:QueryWabaBusinessInfo",
            "cams:QueryWabaByEmbedSignUp",
            "cams:RamUserIsOpen",
            "cams:RamUserOpen",
            "cams:ReadChatFlow",
            "cams:ReadChatFlowLogSetting",
            "cams:ReadFlowVersion",
            "cams:RemoveContactById",
            "cams:RemoveContacts",
            "cams:RequestWhatsappConversionApi",
            "cams:SendChatAppMessage",
            "cams:SendChatappMassMessage",
            "cams:SendChatappMessage",
            "cams:SendSafetyControl",
            "cams:SubmitIsvCustomerTerms",
            "cams:SyncBusinessAppHistory",
            "cams:SyncChatGroup",
            "cams:SyncFlow",
            "cams:SyncMessageCampaign",
            "cams:SyncMessengerSubscriptionToken",
            "cams:TranslateCustToIsv",
            "cams:TriggerChatFlow",
            "cams:UnbindDmAccount",
            "cams:UpdateAccountWebhook",
            "cams:UpdateAuditRequest",
            "cams:UpdateChatFlow",
            "cams:UpdateChatFlowLogSetting",
            "cams:UpdateChatGroup",
            "cams:UpdateChatappPhoneNumberSetting",
            "cams:UpdateCheckCode",
            "cams:UpdateCommerceSetting",
            "cams:UpdateContactById",
            "cams:UpdateConversationalAutomation",
            "cams:UpdateCust",
            "cams:UpdateFlowJSONAsset",
            "cams:UpdateFlowVersion",
            "cams:UpdateGroupName",
            "cams:UpdateHref",
            "cams:UpdateMarketingFLow",
            "cams:UpdatePackageRemainAlarmThreshold",
            "cams:UpdatePackgeRemainAlarmThreshold",
            "cams:UpdatePersonalizedBillConfig",
            "cams:UpdatePhoneEncryptionPublicKey",
            "cams:UpdatePhoneMessageQrdl",
            "cams:UpdatePhoneWebhook",
            "cams:UpdateViberWebhook",
            "cams:UpdateWabaMmlStatus",
            "cams:WhatsappCall",
            "cams:WorkbenchSendMessage"
          ],
          "Resource": "*"
        }
      ]
    }
    
Important

Granting account-level permissions allows access to all relevant resources in the account. Always follow PoLP.

FAQ

How do I find which resource group a resource belongs to?

  • Method 1: From the service console

    • Navigate to the service console where the resource was created. On the resource's details page, you can typically find the resource group listed in the basic information section.

  • Method 2: From the Resource Management console

    • Log on to the Resource Management console.

    • Choose Resource Center > Resource Search.

    • In the left pane, select the account that owns the target resource (the default is Current Account).

    • Use filter conditions to find your resource.

    • The Resource Group Name column shows which group the resource belongs to.

How do I view all resources in a specific resource group?

  • Method 1:

    • Log on to the Resource Management console.

    • Choose Resource Center > Resource Search.

    • In the left pane, under the account that owns the resources (the default is Current Account), click the name of the desired resource group.

    • In the right pane, select the cloud service from the Select resource types drop-down list.

    • All resources in that group will be displayed.

  • Method 2:

    • Log on to the Resource Management console.

    • Choose Resource Group > Resource Group.

    • Find the desired resource group and click Resource Management in the Actions column.

    • On the resource management page, select the cloud service from the Service drop-down list.

    • All resources in that group will be displayed.

How do I move multiple resources to a different resource group in batch?

  1. Log on to the Resource Management console.

  2. Choose Resource Group > Resource Group.

  3. Find the desired resource group and click Resource Management in the Actions column.

  4. On the resource management page, use filter conditions to find the resources you want to move.

  5. Select the checkbox for each resource.

  6. At the bottom of the page, click Transfer.

  7. In the dialog box, select the destination resource group and click Confirm.