Skip to main content
Organization access policies authorize principals in your organization to take AI Object Storage actions. They aren’t a blanket control over every bucket. At least one organization access policy must be in place before you can create a bucket.

Example usage

Schema

Required

  • name (String) The name of the organization access policy, must be unique.
  • statements (Attributes Set) The list of access policy statements associated with this policy. At least one statement is required. (see below for nested schema)

Nested Schema for statements

Required:
  • actions (Set of String) Defines which operations the policy allows or denies. Organization access policies can include actions from two APIs - S3 (s3:) and AI Object Storage API (cwobject:). You can use wildcards (like s3:* or cwobject:*) to cover multiple actions at once.
  • effect (String) Must be either Allow or Deny (case-sensitive). Determines whether the statement grants or denies the specified actions on the listed resources for the designated principals. By default, all access is denied.
  • name (String) A short, human-readable identifier for this specific policy statement, similar to Sid in bucket access policies.
  • principals (Set of String) Defines which users, roles, or groups the policy applies to. Only short-form identifiers are supported. If you use a full ARN, the policy will fail with an error. See the AI Object Storage documentation for guidelines on defining principals.
  • resources (Set of String) Defines which resources the policy applies to. See the AI Object Storage documentation for guidelines on defining resources.

Import

Import is supported using the following syntax:
Last modified on October 8, 2026