Cryptographic Security Platform Vault uses the AWS Key Policy to control IAM users' access to BYOK keys. The default key policy template used by Cryptographic Security Platform Vault defines the following roles: 

  • An administrator with full administrative rights to the key

  • A user that can use the key for encryption or decryption.

Cryptographic Security Platform Vault admins can assign IAM users as administrator and/or user to a specific CloudKey. The default key policy template used by Cryptographic Security Platform Vault is the same as the default policy template that is used by the AWS KMS console.

If you change a CloudKey's key policy in KMS, you will not be able to update or view its access information in Vault.