You can add multiple members to a workspace and grant different permissions to the members by assigning different roles to the members. This topic describes how to add Resource Access Management (RAM) users to a workspace and assign different roles to the RAM users.

Background information

Multiple members may share the same workspace. If you grant excessive permissions to the members, data security may be compromised. If the members do not have sufficient permissions, the members may be unable to use specific features. To resolve this issue, Machine Learning Platform for AI allows you to assign different roles to RAM users that share the same workspace based on the requirements of the members. In the left-side navigation pane, click Roles and Permissions to view the mappings between roles and permissions.

This topic describes the following operations that you can perform on workspace members:

Limits

Only the administrator and owner of a workspace can manage the members in the workspace.

Go to the Members panel

  1. Go to the Workspace Details page.
    1. Log on to the PAI console.
    2. You can use one of the following methods to go to the Workspace Details page.
      • In the Recently Used Workspaces section of the Overview page, find the workspace that you want to manage and click the name of the workspace. Workspace Details method1
        1. In the left-side navigation pane, click Workspaces.
        2. On the Workspaces page, click the name of the workspace that you want to manage. Workspace Details method 2
  2. On the Workspace Details page, click Manage next to Members to go to the Members panel. Go to the Member management panel

Add a member

  1. Go to the Members panel.
  2. In the Members panel, click Add Member.
  3. In the Add Member dialog box, set the following parameters.
    Add a member
    Parameter Description
    Account In the Pending Adding section, all RAM users that can be added to the workspace are displayed. Select the check box on the left side of a RAM user and click the Rightwords arrow icon. Then, the RAM user is displayed in the Selected section on the right side.

    To remove a selected RAM user, select the check box of the RAM user that you want to remove in the Selected section and click the Leftwoards arrow icon. Then, the RAM user is removed from the Selected section and displayed in the Pending Adding section.

    Role The following roles are supported. You can select one or more roles based on your requirements:
    • Administrator: This role has the permissions to modify members, and manage resource groups and all assets in the workspace.
    • Algorithm Developer: This role has the permissions to develop and train models in the workspace.
    • Algorithm O&M Engineer: This role has the permissions to manage task priorities, publish models, and monitor online services.
    • Label Administrator: This role has the permissions to use intelligent labeling.
    • MaxCompute Developer: The developer role in DataWorks. This role has the permissions to develop MaxCompute data. You can assign this role to RAM users that you want to use to submit jobs from the Machine Learning Platform for AI console to MaxCompute.
    • Visitor: This role has the read-only permissions on all assets in the workspace.
    Note You can assign one or more roles to a RAM user based on your requirements.
    In the left-side navigation pane of the Machine Learning Platform for AI console, click Roles and Permissions to view the mappings between roles and permissions.
  4. Click OK.

Modify the role of a member

  1. Go to the Members panel.
  2. In the Members panel, find the member that you want to manage and click the drop-down list in the Role column.
  3. In the Role drop-down list, if you click a role that is assigned to the member, the role is deleted from the member. If you click a role that is not assigned to the member, the system assigns the role to the member. assign a role
    You can also click the Revoke a role icon next to the role name to revoke the role from a member.
    Note
    • Each member must be assigned at least one role. You cannot revoke all the roles from a member.
    • You cannot revoke the Owner role. The Alibaba Cloud account or RAM user that creates a workspace automatically becomes the owner of the workspace. The owner of a workspace has the permissions to modify workspace members, reference and manage resource groups, and manage all assets in the workspace.

Delete a member

You can use one of the following methods to delete one or more members:
Note You cannot delete the member whose role is Owner.
You can use the following method to delete a member.
  1. Go to the Members panel.
  2. In the Members panel, find the member that you want to delete and click Delete in the Actions column.
  3. In the Delete message, click OK.
You can use the following method to delete multiple members at a time.
  1. Go to the Members panel.
  2. In the Members panel, find the members that you want to delete and select the check boxes on the left side.
  3. Click Batch Delete.
  4. In the message that appears, click OK.