Simplify project permissions with IAM role inheritance
As the number of projects in an organization grows, teams often need to assign the same roles across multiple projects. Whenever users or groups responsible for shared work join a new project, administrators have to add their permissions again and check that no project was missed.
To reduce this repetitive work, KakaoCloud IAM now supports role inheritance. You can use it to assign common project roles to a user or group across every project in your organization at once. These roles are applied automatically to both existing projects and projects created later.
This post explains how to manage permissions consistently across projects with role inheritance, and how to check role assignment paths and change history.
Apply common roles across all projects
Role inheritance lets you manage common project roles at the organization level instead of assigning them separately in each project. Select a user or group and assign the required project roles from Management > IAM > Roles > Role inheritance to apply the same roles across all projects in the organization.
For example, an operations team may need to check resource status across several projects. Previously, you had to assign the required reader role to the team or its members in each project. Now, you can assign the role to the operations group through role inheritance, and the same permissions will apply across all projects. New members added to the group will also receive the group's roles, and you will not need to assign them again when a new project is created.
You can use role inheritance in two ways:
- By user: Assign common project roles across the organization directly to a specific user.
- By group: Assign common project roles across the organization to a group, applying them to all its users.
Groups are convenient when you need to manage the same permissions by team or job function. You can also assign roles to individual users when only they need them, choosing the approach that fits your organization.
Roles available for inheritance include Project Admin, Project Member, Project Leader, and project-level service roles. Organization roles are not included. You need the Organization Admin or IAM Organization Admin role to assign roles.
👉 Learn how to manage IAM role inheritance
Check where a role was assigned
A user can receive the same project role through multiple paths. A role may be assigned directly in a specific project, applied through a group assigned a project role, or applied through role inheritance.
The Assignment path column has been added to the project roles table to make it easier to tell how a role was applied.
User: Assigned directly to a user in a specific project.Group (group name): Applied through a group assigned a role in a specific project.Inherited · User: Assigned directly to a user through role inheritance.Inherited · Group (group name): Applied through a group assigned a role through role inheritance.
Checking the assignment path helps you quickly identify where a role is managed. Roles applied through role inheritance must be modified or removed from IAM > Roles > Role inheritance, not from an individual project. Removing a role through one path does not affect roles the user receives through other paths.
Review change history in Cloud Trail
Because roles applied across multiple projects have a broad impact, it is important to know who assigned or removed them. Role inheritance assignments and removals are recorded as Cloud Trail organization events.
You can review role assignment and removal history for users and groups through these events:
Domain Inherited Role AssignDomain Inherited Role UnassignDomain Inherited Group AssignDomain Inherited Group Unassign
Together with Cloud Trail, these events help you track when role inheritance settings changed and who made the change, supporting organization-wide permission management and audits.
👉 Review IAM events in Cloud Trail
Operate safely with the principle of least privilege
Role inheritance reduces repetitive permission management, but remember that assigned roles apply to every project in the organization. You cannot exclude individual projects, so avoid granting broader permissions than the work requires.
Before using role inheritance, check the following:
✔️ Confirm that the role is needed across all projects.
✔️ Assign roles with broad permissions, such as Project Admin, with care.
✔️ If you assign a role to a group through inheritance, review the scope whenever the group membership changes.
✔️ Review assignment paths and Cloud Trail events regularly.
✔️ IAM access keys retain the roles that were in effect when the key was created. If you need to use newly inherited permissions through the API, create a new IAM access key.
With IAM role inheritance, you can manage permissions consistently for users and groups without repeatedly assigning common roles as your projects grow. Use assignment paths and Cloud Trail together to maintain an effective role policy for your organization.
👉 Learn about IAM roles and permissions
👉 Get started with KakaoCloud
