Scaleway Rules API
A rule (also known as an IAM rule) is the part of a [policy](https://www.scaleway.com/en/docs/iam/concepts/#policy) that defines the permissions of the policy's [principal](https://www.scaleway.com/en/docs/iam/concepts/#principal), and the scope of these permissions. A policy can have one or many rules. Each rule consists of: - A **scope**, which defines where the permission sets should apply. At Scaleway, a scope can be at [Project](https://www.scaleway.com/en/docs/iam/concepts/#project) or [Organization](https://www.scaleway.com/en/docs/iam/concepts/#organization) level. * **Projects** group your Scaleway resources (eg. Instances, Object Storage buckets, Managed Databases etc.) together. An Organization may have many Projects, or just one default Project. If you choose to define scope at Project level, you can select one, many, or all Projects. When you then define the [permission sets](https://www.scaleway.com/en/docs/iam/concepts/#permission-set) for this scope, you can give access to different resources within the Project(s). * An **Organization** is made of one or several Projects. Billing, IAM, Project management and support are all managed at Organization level, so choose the Organization scope to give access to these features. - One or more [**permission sets**](https://www.scaleway.com/en/docs/iam/reference-content/permission-sets/#permission-set) (eg. "list all Instances"). A permission set consists of one or multiple [permissions](https://www.scaleway.com/en/docs/iam/concepts/#permission) to perform actions on resources or features. Each permission set has a clear description, e.g. `InstancesFullAccess`, `InstancesReadOnly`, `RelationalDatabasesFullAccess`, `BillingReadOnly`.