All Products
Search
Document Center

E-MapReduce:Grant permissions to a RAM user

Last Updated:Mar 26, 2026

A Resource Access Management (RAM) user needs explicit permissions to perform EMR Serverless Spark operations, such as creating, viewing, or deleting workspaces. This topic explains how to grant those permissions using the RAM console.

Prerequisites

Before you begin, ensure that you have:

Choose a policy

Select the system policy that matches the RAM user's role:

  • AliyunEMRServerlessSparkFullAccess: Grants administrator permissions for EMR Serverless Spark, including permissions to create and delete workspaces. For more information, see AliyunEMRServerlessSparkFullAccess.

  • AliyunEMRServerlessSparkDeveloperAccess: Grants developer permissions for EMR Serverless Spark. Does not include permissions to create or delete workspaces. For more information, see AliyunEMRServerlessSparkDeveloperAccess.

  • AliyunEmrServerlessSparkReadOnlyAccess: Grants read-only permissions for EMR Serverless Spark, including access to the Spark service in read-only mode. For more information, see AliyunEmrServerlessSparkReadOnlyAccess.

Add permissions in the RAM console

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Identities > Users.

  3. On the Users page, find the target RAM user and click Add Permissions in the Actions column.

    To grant permissions to multiple RAM users at once, select them and click Add Permissions at the bottom of the page.

    image

  4. In the Grant Permission panel, configure the following parameters.

  5. Click Grant permissions.

  6. Click Close.