Vault uses the AWS Key Policy to control IAM users' access to BYOK keys. The default key policy template used by the CSP Vault for Cloud Keys defines the following roles:
An administrator with full administrative rights to the key
A user that can use the key for encryption or decryption.
CSP Vault for Cloud Keys admins can assign IAM users as administrator and/or user to a specific CloudKey. The default key policy template Vault uses matches the default policy template used by the AWS KMS console.
If you change a CloudKey's key policy in KMS, you will not be able to update or view its access information in CSP Vault for Cloud Keys.