All Products
Search
Document Center

Platform For AI:Permission management

Last Updated:Jul 13, 2026

Using PAI involves two types of authorization: RAM user authorization for activating and accessing cloud services, and service authorization for PAI to access other Alibaba Cloud services.

image

Authorize RAM users

An Alibaba Cloud account doesn't require additional authorization. A RAM user must be authorized before they can log on to the console or use APIs to access resources under the account. This section describes the following authorization methods for RAM users in PAI:

Authorize a RAM user to activate PAI and purchase PAI resources

Attach the AliyunPAIFullAccess policy to a RAM user to allow them to activate PAI and purchase PAI resources. For more information, see Manage RAM user permissions.

Important

AliyunPAIFullAccess includes administrator permissions for purchasing, creating, and deleting resources, as well as full workspace management. Use this policy with caution.

We recommend that you use the Alibaba Cloud account or configure a minimum required policy for the RAM user. For more information, see Create a custom policy.

Authorize a RAM user to use PAI sub-products

PAI provides Use workspaces to manage permissions for managing permissions. Add a RAM user as a workspace member and assign one of the following roles: Owner, Administrator, Algorithm Developer, Algorithm O&M, Labeling Administrator, or Visitor. For the permissions of each role, see Appendix: Roles and permissions.

  • For iTAG, also configure additional permissions. For more information, see Assign user roles.

  • EAS provides system policies for RAM user authorization:

    • Full EAS permissions: AliyunPAIEASFullAccess.

    • Read-only EAS permissions: AliyunPAIEASReadOnlyAccess.

  • For most AI Acceleration features, only sub-product permissions for model development, training, and inference are required. No additional authorization is needed. However, the dataset acceleration feature requires the RAM user to have both AliyunPAIFullAccess and AliyunDatasetAccFullAccess permissions.

Authorize a RAM user to activate or use other cloud services

PAI depends on the following cloud services:

Click to view cloud services that PAI depends on

PAI sub-product

Dependent cloud service

iTAG

OSS

Designer

OSS, MaxCompute, Flink

DSW

OSS, NAS, VPC

DLC

OSS, NAS, VPC

AutoML

OSS, MaxCompute

EAS

OSS, API Gateway, SLS, VPC, CloudMonitor

LangStudio

OSS, SLS, VPC, Tracing Analysis

AI Assets

ACR

Note

Use the Alibaba Cloud account to activate cloud services. Then, use RAM policies to control access for RAM users. See the RAM user authorization column in the following table.

If a RAM user is added as a workspace member, they inherit partial permissions for the dependent cloud services based on their assigned role. If you encounter permission issues when activating or using a cloud service, refer to the following table.

For example, to activate OSS with a RAM user, attach the AliyunOSSFullAccess system policy to the RAM user. For more information about OSS permissions, see OSS RAM Policy.

Cloud service

Policy for activation

RAM user authorization

Documentation

OSS

AliyunOSSFullAccess

OSS RAM Policy

MaxCompute

AliyunBSSOrderAccess, AliyunDataWorksFullAccess

Add the RAM user with the MaxCompute Developer role in the workspace. For more information, see Create and manage a workspace.

Flink

AliyunStreamFullAccess

Management portal permissions

Activation: Activate Realtime Compute for Apache Flink

NAS

AliyunNASFullAccess

Control NAS access with RAM policies

API Gateway

AliyunApiGatewayFullAccess

Use RAM to manage API permissions

SLS

AliyunLogFullAccess

SLS authentication rules

VPC

AliyunVPCFullAccess

VPC authorization

CloudMonitor

AliyunCloudMonitorFullAccess

CloudMonitor authorization

Common operations: Step 1: Configure alert contacts, Step 2: Configure alert rules

Tracing Analysis

AliyunARMSFullAccess

Manage permissions with RAM users

Activation: Quick start

ACR

AliyunContainerRegistryFullAccess

ACR RAM authorization

Common operations: Build images on an Enterprise Edition instance

Authorize PAI to access other cloud services

Authorization for PAI to access other services is typically completed when you activate PAI. If any authorization steps were missed during activation, the console prompts you to complete them. You can also check the authorization status by following these steps. The following example uses Designer and OSS:

  1. Log on to the PAI console.

  2. In the left-side navigation pane, choose Activation & Authorization > Dependent Services. Find OSS in the Designer section.

  3. Check the authorization status of OSS in the Actions column.

    • If OSS is not authorized, click Actions > Authorize Now and follow the prompts to complete the authorization.

    • If OSS is already authorized, click Actions > View Authorization to view the authorization details.

PAI sub-products access other cloud services through service roles and service-linked roles. The preceding list doesn't cover all scenarios. For more information about specific sub-products, see: