Authorization
You can define what privileges you need in policies and associate them with principals. OCI authorization works on the least privilege-first approach, so you are not allowed to perform any actions.
You can specify one or more policy statements in a human-readable format. These policy statements allow you to gain access to OCI resources and outline what you can do with them.
Let's take a look at a few human-readable policy statements:
Allow group <group_name> to <verb> <resource-type> in tenancy Allow group <group_name> to <verb> <resource-type> in compartment <compartment_name> [where <conditions>]
You can either attach these policies to a compartment or at the tenancy level.