All Products
Search
Document Center

Alibaba Cloud Model Studio:Grant management layer permissions to a RAM user

Last Updated:Feb 17, 2025

Grant management layer permissions to your RAM user so that the user can manage workspaces, accounts, and all API keys. This topic describes how to grant management layer permissions.

If you are not familiar with concepts such as RAM user, management layer permission, or workspace, read Permissions first.
Use your Alibaba Cloud account to perform the following operations. If you need to use a RAM user, you must first grant it the AliyunRAMFullAccess system policy. For more information, see Grant permissions to a RAM user.

Procedure

Step 1: Create a RAM user

Skip this step if you already have one.

For more information, see Create a RAM user.

Step 2: Grant a management layer permission

Grant your RAM user the permission to manage workspaces, accounts, and all API keys in Model Studio.

  1. In the RAM Console, choose Identities > Users from the left-side navigation pane.

  2. Click Add Permissions in the Actions column of the created RAM user.

    image

  3. On the Grant Permission panel, set Resource Scope to Account.

  4. In the Policy section, select AliyunBailianControlFullAccess or one of the policies in the following list. Click Grant permissions.

    We recommend that you assign only the minimum permissions required to avoid security risks.
    Only AliyunBailianFullAccess allows the user to activate new features and pay subscription bills, see More permissions required.

    image

    • AliyunBailianFullAccess: Grants full Management layer and data permissions.

      Note: Data permissions are different from data layer permissions. This policy does not grant workspace permissions.
      • Management layer: All permissions, including:

        • Manage workspaces, accounts, and all API keys.

        • Activate new features in Model Studio.

        • The essential permissions for paying subscription bills, see FAQ.

      • Data: Manage permissions, including:

    • AliyunBailianReadOnlyAccess: Grants limited management layer permissions (read-only) and limited data permissions (read-only).

      Note: Data permissions are different from data layer permissions. This policy does not grant workspace permissions.
      • Management layer: Limited permissions (read-only), including:

        • Read-only access to workspaces, accounts, and all API keys.

        • Cannot activate new features.

        • The essential permissions for paying subscription bills, see FAQ.

      • Data: Read-only access to OpenAPI.

    • AliyunBailianControlFullAccess: Grants limited management layer permissions (control).

      • Management layer: Limited permissions (control), including:

        • Manage workspaces, accounts, and all API keys.

        • Cannot activate new features.

        • The essential permissions for paying subscription bills, see FAQ.

    • AliyunBailianControlReadOnlyAccess: Grants limited management layer permissions (read-only).

      • Management layer: Limited permissions (read-only), including:

        • Read-only access to workspaces, accounts, and all API keys.

        • Cannot activate new features.

        • The essential permissions for paying subscription bills, see FAQ.

  5. (Optional) To revoke a permission, see Revoke permissions from a RAM user.

Next step

Use the RAM user to log on to the Model Studio console. If you are not able to access the workspace, the RAM user still lacks data layer permissions.

Important

Management layer permission alone does not give your RAM user access to a workspace. You must also grant data layer permission. For more information, see Grant workspace access to a RAM user.

FAQ

What RAM permissions are required when activating new features like model calling using a RAM user (or RAM role)?

Feature

RAM permissions required

Model calling

Use the Alibaba Cloud account to grant the AliyunBailianFullAccess system policy for your RAM user (or RAM role) in the RAM console. Other management layer permissions are not applicable.

Paying subscription bills

Use the Alibaba Cloud account to grant the AliyunBSSOrderAccess system policy and one of the management layer permissions (AliyunBailianFullAccess, AliyunBailianReadOnlyAccess, AliyunBailianControlFullAccess, or AliyunBailianControlReadOnlyAccess) in the RAM console.

OSZAR »