1. Introduction to OCI Resource Target Scoping
In Oracle Cloud Infrastructure (OCI) policy statements, the target of an action is defined by a Resource Type or a Resource Family.
Rather than requiring administrators to reference individual API permission strings for every cloud service, OCI groups related resources into logical hierarchies. This design allows you to grant broad administrative rights across an entire infrastructure component using a single Resource Family, or enforce strict least-privilege security using Individual Resource Types.
Understanding how resource families expand into individual resource types is essential for constructing clean, auditable IAM policies.
2. Resource Families vs. Individual Resource Types
What is a Resource Family?
A Resource Family is a top-level abstraction that encompasses multiple related individual resource types. When you specify a resource family in a policy statement, OCI automatically applies the specified verb to all individual resources contained within that family.
For example, referencing instance-family covers compute instances, console connections, volume attachments, instance images, and custom boot volumes under a single policy statement.
What is an Individual Resource Type?
An Individual Resource Type targets a specific, singular OCI resource component. Use individual resource types when enforcing least-privilege access rules where users need access to one specific component without gaining access to surrounding service features.
For example, specifying instances targets compute VMs, but excludes management of custom machine images or console connections.
3. Core OCI Resource Families Breakdown
Below is the mapping of major OCI Resource Families and their constituent Individual Resource Types:
| Resource Family | Included Individual Resource Types | Primary Target Components Covered |
|---|---|---|
all-resources | Every existing and future resource type across all OCI services | Complete tenancy or compartment administration |
instance-family | instances, instance-images, console-histories, volume-attachments | Compute VMs, custom images, serial consoles, and disk attachments |
virtual-network-family | vcns, subnets, route-tables, security-lists, dhcp-options, drgs, internet-gateways, nat-gateways, service-gateways, vnics | Complete core networking, subnets, routing, and gateway infrastructure |
volume-family | volumes, volume-backups, boot-volumes, volume-groups | Elastic Block Storage volumes, boot disks, and backup snapshots |
object-family | buckets, objects | OCI Object Storage containers and stored files |
database-family | autonomous-databases, db-systems, db-nodes, db-homes, backups | Oracle Autonomous Databases, Bare Metal/VM DB Systems, and Exadata |
[!IMPORTANT]
Theall-resourcesUniversal Family
Grantingmanage all-resources in compartment Productionprovides full administrative control over every OCI service operating in that compartment—including services deployed by Oracle in the future. This family should be reserved strictly for top-level Security Administrators and Tenant Root Admins.
4. Resource Family Expansion Example
To understand how policy statements evaluate under the hood, compare these two policy formulations:
Option A: Using a Resource Family (Broad Scoping)
Allow group Dev-Network-Admins to manage virtual-network-family in compartment Dev-Compartment
- Effect: Grants permission to create, modify, and delete VCNs, Subnets, Route Tables, Security Lists, DRGs, Internet Gateways, and NAT Gateways inside
Dev-Compartment.
Option B: Using Individual Resource Types (Least-Privilege Scoping)
Allow group Dev-Operators to use subnets in compartment Dev-Compartment
Allow group Dev-Operators to use vnics in compartment Dev-Compartment
- Effect: Grants developers permission to attach compute VMs to existing subnets and VNICs, but prevents them from deleting VCNs, modifying route tables, or altering security list rules.
5. OCI Web Console (GUI) Step-by-Step Walkthrough
Selecting and configuring resource types in policy statements is managed directly in the OCI Web Console GUI.
Step 1: Navigating to Policies
- Log in to the Oracle Cloud Console (
https://cloud.oracle.com). - Open the Navigation Menu (
≡) ➔ Identity & Security ➔ Policies. - Select the target compartment (e.g.,
Engineering-Compartment).
Step 2: Selecting Resource Scopes in the Policy Builder
- Click Create Policy.
- Name the policy:
StorageAdminPolicy. - Under Policy Builder:
- Switch off the manual editor to use the GUI Builder Dropdowns.
- Verb: Select
manage. - Target Resource: Choose Resource Family or Individual Resource:
- Selecting
volume-familygrants access to all block volumes, boot disks, and backups. - Selecting individual
bucketsrestricts access specifically to Object Storage containers.
- Selecting
- Complete the statement and click Create.
6. Common Architectural Misconceptions & Pitfalls
Misconception 1: “Specifying instance-family Automatically Grants Permission to Create Subnets”
- Reality: Provisioning a compute VM requires attaching it to a Virtual Network Interface Card (VNIC) on a subnet. If a user has
manage instance-familybut lacksuse subnetsoruse vnicsinvirtual-network-family, VM creation will fail during network attachment.
Misconception 2: “Individual Resource Types Can Be Combined in a Single Statement Array”
- Reality: An OCI policy statement accepts either one specific resource family, one individual resource type, or a comma-separated list of individual types belonging to the same service. Mixing incompatible resource families in a single statement syntax is invalid.
7. OCI Resource Types vs. Google Cloud (GCP) Resource Scoping
For cloud architects familiar with Google Cloud, the following table compares resource targeting models:
| Scoping Metric | Google Cloud (GCP) | Oracle Cloud Infrastructure (OCI) | Key Technical Difference |
|---|---|---|---|
| Permission Granularity | Individual API permission strings (e.g., compute.instances.create) | Resource Families or Individual Resource Types combined with progressive verbs | OCI groups related API methods under unified resource abstractions (instance-family) rather than managing granular string arrays. |
| Broad Scoping | Primitive Roles (Owner, Editor, Viewer) | Universal Family all-resources combined with verbs (inspect, read, use, manage) | OCI allows broad administrative control without granting destructive ownership permissions tenancy-wide. |
| Service Coverage | Managed via individual GCP service API enablement | Automatically covers current and future OCI services inside the targeted resource family | OCI policy resource families expand automatically when new features are added to a service family. |

