If system policies do not meet your requirements, you can create custom policies to achieve least privilege. Custom policies provide fine-grained permission control to enhance resource access security. This topic describes scenarios and provides policy examples for using custom policies with Scalable Open Financial Architecture.
What are custom policies
Custom policies are user-defined policies that you can create, update, and delete in Resource Access Management (RAM). They are separate from system policies. You are responsible for maintaining the versions of your custom policies.
After you create a custom policy, you can attach it to a RAM user, user group, or RAM role. The RAM identity then has the access permissions specified in the policy.
Before you delete a policy, make sure that it is not attached to any RAM identity. If the policy is attached, you must first detach it.
Custom policies support versioning. You can manage the versions of your custom policies using the version control feature in RAM.