All Products
Search
Document Center

MaxCompute:System policies for MaxCompute

Last Updated:Aug 19, 2025

What is a system policy?

A policy defines a set of permissions that are described based on the policy structure and syntax. You can use policies to describe the authorized resource sets, authorized operation sets, and authorization conditions. Alibaba Cloud Resource Access Management (RAM) provides system policies and custom policies. All system policies are created and updated by Alibaba Cloud. You can use system policies, but you cannot modify them. You can manage and update custom policies based on your business requirements. You can create, update, and delete custom policies. During service iteration, MaxCompute adds new permissions to system policies to support new features and capabilities. The update of a system policy affects all RAM identities to which the policy is attached, including RAM users, RAM user groups, and RAM roles. For more information about RAM policies, see Policy overview.

Note

System policies are designed for new users to quickly get started with Alibaba Cloud products on the management console, though they also enable the use of more advanced methods like API operations or CLI commands. If you are familiar with the advanced methods, we recommend that you use custom policies to implement finer-grained control on who is permitted to call what API operations, thereby improving security.

System policies can be classified into service system policies, service role policies, and service-linked role policies. Some cloud services provide only one or two of the three types of policies. For more information, see the policy types that are described in the following section.

Service system policies

AliyunMaxComputeFullAccess

The AliyunMaxComputeFullAccess policy: Provides full access to MaxCompute via Management Console. It can be attached to RAM identities.

AliyunMaxComputeFullAccess

AliyunMaxComputeReadOnlyAccess

The AliyunMaxComputeReadOnlyAccess policy: Provides read-only access to MaxCompute via Management Console. It can be attached to RAM identities.

AliyunMaxComputeReadOnlyAccess

Service role policies

AliyunODPSPAIRolePolicy

The AliyunODPSPAIRolePolicy policy is the dedicated authorization policy of the AliyunODPSPAIDefaultRole service role. By default, The policy for AliyunODPSPAIDefaultRole. Do not attach this policy to a RAM identity other than the service role. If a service provides precise authorization capabilities, refer to the documentation provided by the service.

AliyunODPSPAIRolePolicy

Service-linked role policies

AliyunServiceRolePolicyForMaxComputeIdentityMgmt

MaxCompute assumes the AliyunServiceRolePolicyForMaxComputeIdentityMgmt service-linked role to access the resources in other cloud services. The AliyunServiceRolePolicyForMaxComputeIdentityMgmt policy is the dedicated authorization policy of the AliyunServiceRoleForMaxComputeIdentityMgmt service-linked role. This policy is defined and used by MaxCompute. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the service-linked role.

AliyunServiceRolePolicyForMaxComputeIdentityMgmt

AliyunServiceRolePolicyForMaxComputeImageMgmt

MaxCompute assumes the AliyunServiceRolePolicyForMaxComputeImageMgmt service-linked role to access the resources in other cloud services. The AliyunServiceRolePolicyForMaxComputeImageMgmt policy is the dedicated authorization policy of the AliyunServiceRoleForMaxComputeImageMgmt service-linked role. This policy is defined and used by MaxCompute. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the service-linked role.

AliyunServiceRolePolicyForMaxComputeImageMgmt

AliyunServiceRolePolicyForMaxComputeLakehouse

MaxCompute assumes the AliyunServiceRolePolicyForMaxComputeLakehouse service-linked role to access the resources in other cloud services. The AliyunServiceRolePolicyForMaxComputeLakehouse policy is the dedicated authorization policy of the AliyunServiceRoleForMaxComputeLakehouse service-linked role. This policy is defined and used by MaxCompute. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the service-linked role.

AliyunServiceRolePolicyForMaxComputeLakehouse

AliyunServiceRolePolicyForMaxComputeMMS

MaxCompute assumes the AliyunServiceRolePolicyForMaxComputeMMS service-linked role to access the resources in other cloud services. The AliyunServiceRolePolicyForMaxComputeMMS policy is the dedicated authorization policy of the AliyunServiceRoleForMaxComputeMMS service-linked role. This policy is defined and used by MaxCompute. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the service-linked role.

AliyunServiceRolePolicyForMaxComputeMMS

AliyunServiceRolePolicyForMaxComputeNetwork

MaxCompute assumes the AliyunServiceRolePolicyForMaxComputeNetwork service-linked role to access the resources in other cloud services. The AliyunServiceRolePolicyForMaxComputeNetwork policy is the dedicated authorization policy of the AliyunServiceRoleForMaxComputeNetwork service-linked role. This policy is defined and used by MaxCompute. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the service-linked role.

AliyunServiceRolePolicyForMaxComputeNetwork

AliyunServiceRolePolicyForMaxComputeNotebook

MaxCompute assumes the AliyunServiceRolePolicyForMaxComputeNotebook service-linked role to access the resources in other cloud services. The AliyunServiceRolePolicyForMaxComputeNotebook policy is the dedicated authorization policy of the AliyunServiceRoleForMaxComputeNotebook service-linked role. This policy is defined and used by MaxCompute. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the service-linked role.

AliyunServiceRolePolicyForMaxComputeNotebook

AliyunServiceRolePolicyForMaxComputeOpenLake

MaxCompute assumes the AliyunServiceRolePolicyForMaxComputeOpenLake service-linked role to access the resources in other cloud services. The AliyunServiceRolePolicyForMaxComputeOpenLake policy is the dedicated authorization policy of the AliyunServiceRoleForMaxComputeOpenLake service-linked role. This policy is defined and used by MaxCompute. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the service-linked role.

AliyunServiceRolePolicyForMaxComputeOpenLake

AliyunServiceRolePolicyForOdpsMMS

MaxCompute assumes the AliyunServiceRolePolicyForOdpsMMS service-linked role to access the resources in other cloud services. The AliyunServiceRolePolicyForOdpsMMS policy is the dedicated authorization policy of the AliyunServiceRoleForOdpsMMS service-linked role. This policy is defined and used by MaxCompute. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the service-linked role.

AliyunServiceRolePolicyForOdpsMMS

AliyunServiceRolePolicyForOdpsUserMgmt

MaxCompute assumes the AliyunServiceRolePolicyForOdpsUserMgmt service-linked role to access the resources in other cloud services. The AliyunServiceRolePolicyForOdpsUserMgmt policy is the dedicated authorization policy of the AliyunServiceRoleForOdpsUserMgmt service-linked role. This policy is defined and used by MaxCompute. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the service-linked role.

AliyunServiceRolePolicyForOdpsUserMgmt

References

By default, RAM identities do not have any permissions. RAM identities can access cloud resources within an Alibaba Cloud account only after an account administrator grants the required permissions to the RAM identities. To ensure resource security, we recommend that you grant only the required permissions to the RAM identities based on the principle of least privilege. For more information, see the following topics: