Project authorization supports additional project scope selection based on the original Add Policy authorization to limit permissions to the specified project.
For example, when a user is granted ECSFullAccess (full administrative rights for Cloud as a Service), if the project is not restricted, the user will have administrative rights to all instances of Cloud as a Service; if the policy is restricted to the specified project, the user only has the authority to manage Cloud as a Service instances in the project, and cannot manage other Cloud as a Service instances in the unspecified project.
tip
Projects are a type of grouping of cloud resources that you can divide into different projects to authorize or view bills based on the project. For more information, please refer to the project management help documentation .
For scenarios where project authorization cannot be used, please add permission policies directly at the time of authorization without limiting the scope of the project.