All Products
Search
Document Center

Platform For AI:Roles and permissions

Last Updated:May 27, 2026

PAI provides the following roles: Owner, Workspace Administrator, Algorithm Developer, Algorithm O&M Engineer, Labeling Administrator, Visitor, and MaxCompute Developer. The tabs below list default permissions for each role by module.

PAI general

Description

Actions

Checks purchase and activation status for PAI, MaxCompute, DataWorks, and OSS.

Pai:ListProducts (Allowed by default unless explicitly denied.)

Lists quotas (Will be deprecated).

Pai:ListQuotas (Will be deprecated. Allowed by default unless explicitly denied.)

Queries pay-as-you-go prices for PAI-DSW, PAI-DLC, and PAI-EAS.

Pai:GetPayAsYouGoPrice (Allowed by default unless explicitly denied.)

Queries pricing module information for PAI-DSW, PAI-DLC, and PAI-EAS.

Pai:DescribePricingModule (Allowed by default unless explicitly denied.)

Lists RAM users.

Pai:ListUsers (Allowed by default unless explicitly denied.)

Lists user configurations for the Alibaba Cloud account.

Pai:ListUserConfigs

Updates user configurations for the Alibaba Cloud account.

Pai:SetUserConfigs

Deletes a user configuration from the Alibaba Cloud account.

Pai:DeleteUserConfig

Creates PAI orders.

Pai:CreateOrder

Workspace management

Table 1. Managing off-workspace resources

Permission

Action (managed by RAM)

Workspace administrator/owner

Algorithm developer

Algorithm O&M engineer

Labeling administrator

Visitor

Private (created by me)

Private (created by others)

Public (created by me)

Public (created by others)

Private (created by me)

Private (created by others)

Public

Private (created by me)

Private (created by others)

Public

Private (created by me)

Private (created by others)

Public

Create workspaces

PaiWorkspace:CreateWorkspace

Delete workspaces

PaiWorkspace:DeleteWorkspace

List workspaces

PaiWorkspace:ListWorkspaces

Create the default workspace

PaiWorkspace:CreateDefaultWorkspace

Update resource quotas

PaiWorkspace:UpdateQuota

Update the default workspace

PaiWorkspace:UpdateDefaultWorkspace

Get the default workspace

PaiWorkspace:GetDefaultWorkspace

✅ Permission granted regardless of ownership or visibility

✅ Permission granted regardless of ownership or visibility

✅ Permission granted regardless of ownership or visibility

✅ Permission granted regardless of ownership or visibility

Table 2. Workspace management: Resource actions

Description

Action (managed in PAI workspace)

Action (managed via RAM)

Resource

Workspace owner / administrator

Algorithm developer

Algorithm O&M engineer

Labeling administrator

Visitor

Private (created by you)

Private (created by others)

Public (created by you)

Public (created by others)

Private (created by you)

Private (created by others)

Public

Private (created by you)

Private (created by others)

Public

Private (created by you)

Private (created by others)

Public

Get a custom role

PaiWorkspace:GetWorkspaceRole

PaiWorkspace:GetWorkspaceRole

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

Create a custom role

PaiWorkspace:AddWorkspaceRole

PaiWorkspace:AddWorkspaceRole

Delete a custom role

PaiWorkspace:RemoveWorkspaceRole

PaiWorkspace:RemoveWorkspaceRole

Update a custom role

PaiWorkspace:UpdateWorkspaceRole

PaiWorkspace:UpdateWorkspaceRole

List custom roles

PaiWorkspace:ListWorkspaceRoles

PaiWorkspace:ListWorkspaceRoles

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

View basic workspace information

PaiWorkspace:GetWorkspace

PaiWorkspace:GetWorkspace

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

Modify basic workspace information

PaiWorkspace:UpdateWorkspace

PaiWorkspace:UpdateWorkspace

Get workspace operation logs

PaiWorkspace:ListOperationLogs

PaiWorkspace:ListOperationLogs

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

List RAM users not in the workspace

PaiWorkspace:ListWorkspaceUsers

PaiWorkspace:ListWorkspaceUsers

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

List permissions in the workspace

PaiWorkspace:ListPermissions

PaiWorkspace:ListPermissions

Add a workspace resource quota

PaiWorkspace:AddWorkspaceQuota

PaiWorkspace:AddWorkspaceQuota

Remove a workspace resource quota

PaiWorkspace:RemoveWorkspaceQuota

PaiWorkspace:RemoveWorkspaceQuota

Add a member

PaiWorkspace:CreateMember

PaiWorkspace:CreateMember

Delete members

PaiWorkspace:DeleteMembers

PaiWorkspace:DeleteMembers

Add a role to a member

PaiWorkspace:AddMemberRole

PaiWorkspace:AddMemberRole

Remove a role from a member

PaiWorkspace:RemoveMemberRole

PaiWorkspace:RemoveMemberRole

View a workspace member

PaiWorkspace:GetMember

PaiWorkspace:GetMember

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

List workspace members

PaiWorkspace:ListMembers

PaiWorkspace:ListMembers

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

List resource instances

PaiWorkspace:ListResources

PaiWorkspace:ListResources

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

Create a resource instance

PaiWorkspace:CreateWorkspaceResource

PaiWorkspace:CreateWorkspaceResource

Delete a resource instance

PaiWorkspace:DeleteWorkspaceResource

PaiWorkspace:DeleteWorkspaceResource

Update a resource instance (for example, set a default resource group)

PaiWorkspace:UpdateWorkspaceResource

PaiWorkspace:UpdateWorkspaceResource

View a resource instance

PaiWorkspace:GetResource

PaiWorkspace:GetResource

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

View storage configurations

PaiWorkspace:ListConfigs

PaiWorkspace:ListConfigs

✅ Applies to all

✅ Applies to all

✅ Applies to all

✅ Applies to all

Create or update a storage configuration

PaiWorkspace:UpdateConfigs

PaiWorkspace:UpdateConfigs

Get an instance job

PaiWorkspace:GetInstanceJob

PaiWorkspace:GetInstanceJob

/instancejob/{instanceJobId}

✅ Applies to all

✅ Applies to all

Delete a storage configuration

PaiWorkspace:DeleteConfig

PaiWorkspace:DeleteConfig

Quick start

Table 1. QuickStart - TrainingService

Action

Permission

Owner/administrator

Algorithm developer

Algorithm O&M engineer

Private (created by you)

Private (created by others)

Public (created by you)

Public (created by others)

Private (created by you)

Private (created by others)

Public

Create job

PaiTraining:CreateTrainingJob

Update job

PaiTraining:UpdateTrainingJob

View job details

PaiTraining:GetTrainingJob

View job statistics

List jobs

PaiTraining:ListTrainingJobs

Clone job

PaiTraining:CloneTrainingJob

Stop job

PaiTraining:StopTrainingJob

Delete job

PaiTraining:DeleteTrainingJob

Share job

PaiTraining:ShareTrainingJob

View built-in algorithm definitions

Table 2. QuickStart - experiment management

Action

Permission

Owner/administrator

Algorithm developer

Algorithm O&M engineer

Visitor

Private (created by you)

Private (created by others)

Public (created by you)

Public (created by others)

Private (created by you)

Private (created by others)

Public

Private (created by you)

Private (created by others)

Public

Create experiment

PaiExperiment:CreateExperiment

Get experiment

PaiExperiment:GetExperiment

Update experiment

PaiExperiment:UpdateExperiment

Delete experiment

PaiExperiment:DeleteExperiment

List all experiments in the workspace

PaiExperiment:ListAllExperiments

List public and your experiments

PaiExperiment:ListExperiments

Set experiment tags

PaiExperiment:SetExperimentLabel

Delete experiment tags

PaiExperiment:DeleteExperimentLabel

Create trial

PaiExperiment:CreateTrial

Get trial

PaiExperiment:GetTrial

Set trial tags

PaiExperiment:SetTrialLabel

iTAG

Permission

Workspace owner and workspace administrator

Labeling administrator

Private (owned)

Private (shared)

Public

Create, manage, distribute, and execute labeling jobs.

✅ Applies to all

Visual modeling designer

Description

Action (managed via PAI workspace)

Action (managed via RAM)

Resource

Workspace owner/administrator

Algorithm developer

Algorithm O&M engineer

Visitor

MaxCompute developer

Private (yours)

Private (others')

Public (yours)

Public (others')

Private (yours)

Private (others')

Public

Private (yours)

Private (others')

Public

Private (yours)

Private (others')

Public

Get a pipeline draft

PaiDesigner:GetPipelineDraft

PaiDesigner:GetPipelineDraft

/pipelinedraft/{pipelineDraftId}

Get pipeline draft meta

PaiDesigner:GetPipelineDraftMeta

PaiDesigner:GetPipelineDraftMeta

/pipelinedraft/{pipelineDraftId}

List your and public pipeline drafts

PaiDesigner:ListPipelineDrafts

PaiDesigner:ListPipelineDrafts

/pipelinedraft/*

List all pipeline drafts in the workspace

PaiDesigner:ListAllPipelineDrafts

PaiDesigner:ListAllPipelineDrafts

/pipelinedraft/*

Create a pipeline draft

PaiDesigner:CreatePipelineDraft

PaiDesigner:CreatePipelineDraft

/pipelinedraft/{pipelineDraftId}

Delete a pipeline draft

PaiDesigner:DeletePipelineDraft

PaiDesigner:DeletePipelineDraft

/pipelinedraft/{pipelineDraftId}

Update pipeline draft meta

PaiDesigner:UpdatePipelineDraftMeta

PaiDesigner:UpdatePipelineDraftMeta

/pipelinedraft/{pipelineDraftId}

Update pipeline draft content

PaiDesigner:UpdatePipelineDraftContent

PaiDesigner:UpdatePipelineDraftContent

/pipelinedraft/{pipelineDraftId}

Copy a pipeline draft

PaiDesigner:CopyPipelineDraft

PaiDesigner:CopyPipelineDraft

/pipelinedraft/{pipelineDraftId}

Get statistics for your and public pipeline drafts

PaiDesigner:GetPipelineDraftsStatistics

PaiDesigner:GetPipelineDraftsStatistics

/pipelinedraft/*

Get statistics for all pipeline drafts in the workspace

PaiDesigner:GetAllPipelineDraftsStatistics

PaiDesigner:GetAllPipelineDraftsStatistics

/pipelinedraft/*

Get user statistics for your and public pipeline drafts

PaiDesigner:GetPipelineDraftsUsersStatistics

PaiDesigner:GetPipelineDraftsUsersStatistics

/pipelinedraft/*

Get user statistics for all pipeline drafts in the workspace

PaiDesigner:GetAllPipelineDraftsUsersStatistics

PaiDesigner:GetAllPipelineDraftsUsersStatistics

/pipelinedraft/*

Create a pipeline draft from a template

PaiDesigner:CreateTemplatePipelineDraft

PaiDesigner:CreateTemplatePipelineDraft

/pipelinedraft/*

Publish a pipeline draft to the workspace

PaiDesigner:PublishPipelineDraft

PaiDesigner:PublishPipelineDraft

/pipelinedraft/{pipelineDraftId}

List the current user's recent pipeline drafts

PaiDesigner:ListRecentPipelineDrafts

PaiDesigner:ListRecentPipelineDrafts

/pipelinedraft/*

Stop all jobs in a pipeline draft

PaiDesigner:StopPipelineDraft

PaiDesigner:StopPipelineDraft

/pipelinedraft/{pipelineDraftId}

Get the status of a pipeline draft and its child nodes

PaiDesigner:GetPipelineDraftStatus

PaiDesigner:GetPipelineDraftStatus

/pipelinedraft/{pipelineDraftId}

Get the visualization meta for a pipeline draft

PaiDesigner:GetPipelineDraftVisualizationMeta

PaiDesigner:GetPipelineDraftVisualizationMeta

/pipelinedraft/{pipelineDraftId}

Query visualization data for a pipeline draft

PaiDesigner:QueryPipelineDraftVisualizationData

PaiDesigner:QueryPipelineDraftVisualizationData

/pipelinedraft/{pipelineDraftId}

List a pipeline draft's node outputs

PaiDesigner:ListPipelineDraftNodeOutputs

PaiDesigner:ListPipelineDraftNodeOutputs

/pipelinedraft/{pipelineDraftId}

Get a pipeline draft node's output

PaiDesigner:GetPipelineDraftNodeOutput

PaiDesigner:GetPipelineDraftNodeOutput

/pipelinedraft/{pipelineDraftId}

Create a pipeline draft job

PaiDesigner:CreateJob

PaiDesigner:CreateJob

/pipelinedraft/{pipelineDraftId}/job/*

List pipeline draft jobs

PaiDesigner:ListJobs

PaiDesigner:ListJobs

/pipelinedraft/{pipelineDraftId}/job/*

Get a pipeline draft job

PaiDesigner:GetJob

PaiDesigner:GetJob

/pipelinedraft/{pipelineDraftId}/job/{jobId}

Stop a pipeline draft job

PaiDesigner:StopJob

PaiDesigner:StopJob

/pipelinedraft/{pipelineDraftId}/job/{jobId}

Create a template

PaiDesigner:CreateTemplate

PaiDesigner:CreateTemplate

/pipelinedrafttemplate/*

Get a template

PaiDesigner:GetTemplate

PaiDesigner:GetTemplate

/pipelinedrafttemplate/{templateId}

List your and public templates

PaiDesigner:ListTemplates

PaiDesigner:ListTemplates

/pipelinedrafttemplate/*

List all templates in the workspace

PaiDesigner:ListAllTemplates

PaiDesigner:ListAllTemplates

/pipelinedrafttemplate/*

Delete a template

PaiDesigner:DeleteTemplate

PaiDesigner:DeleteTemplate

/pipelinedrafttemplate/{templateId}

Update a template

PaiDesigner:UpdateTemplate

PaiDesigner:UpdateTemplate

/pipelinedrafttemplate/{templateId}

Add tags to a template

PaiDesigner:CreateTemplateLabels

PaiDesigner:CreateTemplateLabels

/pipelinedrafttemplate/{templateId}/label/*

Remove tags from a template

PaiDesigner:DeleteTemplateLabels

PaiDesigner:DeleteTemplateLabels

/pipelinedrafttemplate/{templateId}/label/*

List a template's tags

PaiDesigner:ListTemplateLabels

PaiDesigner:ListTemplateLabels

/pipelinedrafttemplate/{templateId}/label/*

Create a pipeline draft folder

PaiDesigner:CreatePipelineDraftFolder

PaiDesigner:CreatePipelineDraftFolder

/pipelinedraftfolder/*

List your and public subfolders and pipeline drafts in a pipeline draft folder

PaiDesigner:GetPipelineDraftFolderChildren

PaiDesigner:GetPipelineDraftFolderChildren

/pipelinedraftfolder/*

List all subfolders and pipeline drafts in a pipeline draft folder

PaiDesigner:GetAllPipelineDraftFolderChildren

PaiDesigner:GetAllPipelineDraftFolderChildren

/pipelinedraftfolder/*

Update a pipeline draft folder

PaiDesigner:UpdatePipelineDraftFolder

PaiDesigner:UpdatePipelineDraftFolder

/pipelinedraftfolder/{folderId}

Delete a pipeline draft folder

PaiDesigner:DeletePipelineDraftFolder

PaiDesigner:DeletePipelineDraftFolder

/pipelinedraftfolder/{folderId}

Transfer your pipeline drafts

PaiDesigner:TransferPipelineDrafts

PaiDesigner:TransferPipelineDrafts

/pipelinedraft/*

Transfer all pipeline drafts in the workspace

PaiDesigner:TransferAllPipelineDrafts

PaiDesigner:TransferAllPipelineDrafts

/pipelinedraft/*

Get an instance job

PaiDesigner:GetInstanceJob

PaiDesigner:GetInstanceJob

/instancejob/{instanceJobId}

PAIFlow

Description

Action (PAI workspace)

Action (RAM)

Resource

Workspace owner/administrator

Algorithm developer

Algorithm O&M engineer

Visitor

MaxCompute developer (with DataWorks and Designer permissions)

Private (Own)

Private (Others)

Public (Own)

Public (Others)

Private (Own)

Private (Others)

Public

Private (Own)

Private (Others)

Public

Private (Own)

Private (Others)

Public

Create pipeline

Paiflow:CreatePipeline

Paiflow:CreatePipeline

/pipeline/*

Update pipeline

Paiflow:UpdatePipeline

Paiflow:UpdatePipeline

/pipeline/{pipelineId}

Get pipeline schema

Paiflow:GetPipelineSchema

Paiflow:GetPipelineSchema

/pipeline/{pipelineId}

Get pipeline

Paiflow:GetPipeline

Paiflow:GetPipeline

/pipeline/{pipelineId}

Delete pipeline

Paiflow:DeletePipeline

Paiflow:DeletePipeline

/pipeline/{pipelineId}

List pipelines

Paiflow:ListPipelines

Paiflow:ListPipelines

/pipeline/*

Create pipeline run sharing token

Paiflow:CreatePipelineRunToken

Paiflow:CreatePipelineRunToken

/pipelinerun/{pipelineRunId}

List pipeline run node events

Paiflow:ListPipelineRunNodeEvents

Paiflow:ListPipelineRunNodeEvents

/pipelinerun/{pipelineRunId}

Rerun failed nodes in a pipeline run

Paiflow:RerunPipelineRun

Paiflow:RerunPipelineRun

/pipelinerun/{pipelineRunId}

List pipeline run node statuses

Paiflow:ListPipelineRunNodeStatus

Paiflow:ListPipelineRunNodeStatus

/pipelinerun/{pipelineRunId}

Create pipeline run

Paiflow:CreatePipelineRun

Paiflow:CreatePipelineRun

/pipelinerun/*

Get pipeline run

Paiflow:GetPipelineRun

Paiflow:GetPipelineRun

/pipelinerun/{pipelineRunId}

Update pipeline run

Paiflow:UpdatePipelineRun

Paiflow:UpdatePipelineRun

/pipelinerun/{pipelineRunId}

List logs for a pipeline run node

Paiflow:ListPipelineRunNodeLogs

Paiflow:ListPipelineRunNodeLogs

/pipelinerun/{pipelineRunId}

List outputs of a pipeline run node

Paiflow:ListPipelineRunNodeOutputs

Paiflow:ListPipelineRunNodeOutputs

/pipelinerun/{pipelineRunId}

Start pipeline run

Paiflow:StartPipelineRun

Paiflow:StartPipelineRun

/pipelinerun/{pipelineRunId}

Get pipeline run node

Paiflow:GetPipelineRunNode

Paiflow:GetPipelineRunNode

/pipelinerun/{pipelineRunId}

Terminate pipeline run

Paiflow:TerminatePipelineRun

Paiflow:TerminatePipelineRun

/pipelinerun/{pipelineRunId}

List statuses for your and public pipeline runs

Paiflow:ListPipelineRunsStatus

Paiflow:ListPipelineRunsStatus

/pipelinerun/*

List sources for your and public pipeline runs

Paiflow:ListPipelineRunSources

Paiflow:ListPipelineRunSources

/pipelinerun/*

Delete pipeline run

Paiflow:DeletePipelineRun

Paiflow:DeletePipelineRun

/pipelinerun/{pipelineRunId}

List your and public pipeline runs

Paiflow:ListPipelineRuns

Paiflow:ListPipelineRuns

/pipelinerun/*

List statuses of all pipeline runs

Paiflow:ListAllPipelineRunsStatus

Paiflow:ListAllPipelineRunsStatus

/pipelinerun/*

List sources of all pipeline runs

Paiflow:ListAllPipelineRunSources

Paiflow:ListAllPipelineRunSources

/pipelinerun/*

List all pipeline runs

Paiflow:ListAllPipelineRuns

Paiflow:ListAllPipelineRuns

/pipelinerun/*

Interactive modeling (DSW)

Description

Action (managed by PAI workspace)

Action (managed by RAM)

Resource

Workspace owner/administrator

Algorithm developer

Algorithm O&M engineer

Private (created by you)

Private (created by others)

Public (created by you)

Public (created by others)

Private (created by you)

Private (created by others)

Public

Create pay-as-you-go instance

PaiDSW:CreatePostPaidInstance

PaiDSW:CreatePostPaidInstance

dswinstance/*

Create instance from a resource group

PaiDSW:CreatePrePaidInstance

PaiDSW:CreatePrePaidInstance

dswinstance/*

Start instance

PaiDSW:StartInstance

PaiDSW:StartInstance

dswinstance/{instanceId}

Delete pay-as-you-go instance

PaiDSW:DeletePostPaidInstance

PaiDSW:DeletePostPaidInstance

dswinstance/{instanceId}

Delete instance from a resource group

PaiDSW:DeletePrePaidInstance

PaiDSW:DeletePrePaidInstance

dswinstance/{instanceId}

View instance details

PaiDSW:GetInstance

PaiDSW:GetInstance

dswinstance/{instanceId}

Update pay-as-you-go instance

PaiDSW:UpdatePostPaidInstance

PaiDSW:UpdatePostPaidInstance

dswinstance/{instanceId}

Update instance from a resource group

PaiDSW:UpdatePrePaidInstance

PaiDSW:UpdatePrePaidInstance

dswinstance/{instanceId}

Stop instance

PaiDSW:StopInstance

PaiDSW:StopInstance

dswinstance/{instanceId}

Access instance

PaiDSW:OpenInstance

PaiDSW:OpenInstance

dswinstance/{instanceId}

List your own and public instances

PaiDSW:ListInstances

PaiDSW:ListInstances

dswinstance/*

List all instances in the workspace

PaiDSW:ListAllInstances

PaiDSW:ListAllInstances

dswinstance/*

Check if instances exist in the workspace

PaiDSW:CheckInstanceExistence

PaiDSW:CheckInstanceExistence

dswinstance/*

Create idle-shutdown policy

PaiDSW:CreateIdleInstanceCuller

PaiDSW:CreateIdleInstanceCuller

dswinstance/{instanceId}

Get idle-shutdown policy

PaiDSW:GetIdleInstanceCuller

PaiDSW:GetIdleInstanceCuller

dswinstance/{instanceId}

Delete idle-shutdown policy

PaiDSW:DeleteIdleInstanceCuller

PaiDSW:DeleteIdleInstanceCuller

dswinstance/{instanceId}

Create scheduled shutdown timer

PaiDSW:CreateInstanceShutdownTimer

PaiDSW:CreateInstanceShutdownTimer

dswinstance/{instanceId}

Delete scheduled shutdown timer

PaiDSW:DeleteInstanceShutdownTimer

PaiDSW:DeleteInstanceShutdownTimer

dswinstance/{instanceId}

Get scheduled shutdown timer

PaiDSW:GetInstanceShutdownTimer

PaiDSW:GetInstanceShutdownTimer

dswinstance/{instanceId}

Create instance snapshot

PaiDSW:CreateInstanceSnapshot

PaiDSW:CreateInstanceSnapshot

dswinstance/{instanceId}/snapshot/*

Delete instance snapshot

PaiDSW:DeleteInstanceSnapshot

PaiDSW:DeleteInstanceSnapshot

dswinstance/{instanceId}/snapshot/{snapshotId}

Get an instance snapshot

PaiDSW:GetInstanceSnapshot

PaiDSW:GetInstanceSnapshot

dswinstance/{instanceId}/snapshot/{snapshotId}

List instance snapshots

PaiDSW:ListInstanceSnapshot

PaiDSW:ListInstanceSnapshot

dswinstance/{instanceId}/snapshot/*

Share a notebook

PaiDSW:CreateShare

PaiDSW:CreateShare

dswinstance/{instanceId}/share/*

List shared notebooks

PaiDSW:ListShares

PaiDSW:ListShares

dswinstance/{instanceId}/share/*

List instance events

PaiDSW:GetInstanceEvents

PaiDSW:GetInstanceEvents

dswinstance/{instanceId}

Get instance monitoring metrics

PaiDSW:GetInstanceMetrics

PaiDSW:GetInstanceMetrics

dswinstance/{instanceId}

Get instance lifecycle

PaiDSW:GetLifecycle

PaiDSW:GetLifecycle

dswinstance/{instanceId}

Get instance authentication token (SSH proxy)

PaiDSW:GetToken

PaiDSW:GetToken

dswinstance/{instanceId}

List statistics for your own and public instances

PaiDSW:ListInstanceStatistics

PaiDSW:ListInstanceStatistics

dswinstance/*

List all instance statistics in the workspace

PaiDSW:ListAllInstanceStatistics

PaiDSW:ListAllInstanceStatistics

dswinstance/*

Create temporary file

PaiDSW:CreateTempFile (Allowed by default unless explicitly denied)

tempfile/*

Delete temporary file

PaiDSW:DeleteTempFile (Allowed by default unless explicitly denied)

tempfile/{tempfileId}

Get temporary file

PaiDSW:GetTempFile (Allowed by default unless explicitly denied)

tempfile/{tempfileId}

Update temporary file

PaiDSW:UpdateTempFile (Allowed by default unless explicitly denied)

tempfile/{tempfileId}

List temporary files

PaiDSW:ListTempFiles (Allowed by default unless explicitly denied)

tempfile/*

Create temporary file task

PaiDSW:CreateTempFileTask (Allowed by default unless explicitly denied)

tempfiletask/*

Delete temporary file task

PaiDSW:DeleteTempFileTask (Allowed by default unless explicitly denied)

tempfiletask/{tempfileTaskId}

Update temporary file task

PaiDSW:UpdateTempFileTask (Allowed by default unless explicitly denied)

tempfiletask/{tempfileTaskId}

Get user configuration

PaiDSW:GetUserConfig (Allowed by default unless explicitly denied)

userconfig/*

List available ECS specifications

PaiDSW:ListEcsSpecs (Allowed by default unless explicitly denied)

ecsspec/*

List available ECS specifications by type

PaiDSW:ListEcsSpecsByInstanceTypes (Allowed by default unless explicitly denied)

ecsspec/*

Update instance labels

PaiDSW:UpdateInstanceLabels

PaiDSW:UpdateInstanceLabels

dswinstance/{instanceId}/labels

Delete instance labels

PaiDSW:DeleteInstanceLabels

PaiDSW:DeleteInstanceLabels

dswinstance/{instanceId}/labels

Distributed training DLC

Description

Action (managed in PAI workspace)

Action (managed in RAM)

Resource

Workspace owner/administrator

Algorithm developer

Algorithm O&M engineer

Private (created by you)

Private (created by others)

Public (created by you)

Public (created by others)

Private (created by you)

Private (created by others)

Public

Create job

PaiDLC:CreateJob

PaiDLC:CreateJob

dlcjob/*

View job details

PaiDLC:GetJob

PaiDLC:GetJob

dlcjob/jobid

View statistics for multiple jobs

PaiDLC:BatchGetJobsStatistics

PaiDLC:BatchGetJobsStatistics

dlcjob/*

View job statistics

PaiDLC:GetJobsStatistics

PaiDLC:GetJobsStatistics

dlcjob/*

List your jobs

PaiDLC:ListJobs

PaiDLC:ListJobs

dlcjob/*

Clone job

PaiDLC:CloneJob

PaiDLC:CloneJob

dlcjob/jobid

Stop job

PaiDLC:StopJob

PaiDLC:StopJob

dlcjob/jobid

Share job

PaiDLC:ShareJob

PaiDLC:ShareJob

dlcjob/jobid

Adjust job priority

PaiDLC:UpdateJob

PaiDLC:UpdateJob

dlcjob/jobid

Delete job

PaiDLC:DeleteJob

PaiDLC:DeleteJob

dlcjob/jobid

Generate a command-line script

PaiDLC:GenerateJobScript

PaiDLC:GenerateJobScript

dlcjob/jobid

Validate web terminal token

PaiDLC:CheckWebTerminalToken

PaiDLC:CheckWebTerminalToken

dlcjob/jobid

View job retries

PaiDLC:ListJobRetries

PaiDLC:ListJobRetries

dlcjob/jobid

View job sanity check result

PaiDLC:GetJobSanityCheckResult

PaiDLC:GetJobSanityCheckResult

dlcjob/jobid

List job sanity check results

PaiDLC:ListJobSanityCheckResults

PaiDLC:ListJobSanityCheckResults

dlcjob/jobid

View job metrics

PaiDLC:GetMetrics

PaiDLC:GetMetrics

dlcjob/jobid

Download large log files for a job

PaiDLC:DownloadLargeLogs

PaiDLC:DownloadLargeLogs

dlcjob/jobid

View latest aggregated job logs

PaiDLC:GetLatestJobLogs

PaiDLC:GetLatestJobLogs

dlcjob/jobid

View aggregated job logs

PaiDLC:GetJobPagedLogs

PaiDLC:GetJobPagedLogs

dlcjob/jobid

View job log count

PaiDLC:GetLogsCount

PaiDLC:GetLogsCount

dlcjob/jobid

View all aggregated job events

PaiDLC:GetJobEvents

PaiDLC:GetJobEvents

dlcjob/jobid

View latest aggregated job events

PaiDLC:GetLatestJobEvents

PaiDLC:GetLatestJobEvents

dlcjob/jobid

View paginated job events

PaiDLC:GetJobPagedEvents

PaiDLC:GetJobPagedEvents

dlcjob/jobid

Get a job token

PaiDLC:GetToken

PaiDLC:GetToken

dlcjob/jobid

List job pods

PaiDLC:ListJobPods

PaiDLC:ListJobPods

dlcjob/jobid/pod/*

Get a temporary access token for a pod

PaiDLC:GetWebTerminal

PaiDLC:GetWebTerminal

dlcjob/jobid/pod/podid

View pod logs

PaiDLC:GetPodLogs

PaiDLC:GetPodLogs

dlcjob/jobid/pod/podid

View latest pod logs

PaiDLC:GetLatestPodLogs

PaiDLC:GetLatestPodLogs

dlcjob/jobid/pod/podid

View paginated pod logs

PaiDLC:GetPodPagedLogs

PaiDLC:GetPodPagedLogs

dlcjob/jobid/pod/podid

View log context in a pod

PaiDLC:GetPodContextLogs

PaiDLC:GetPodContextLogs

dlcjob/jobid/pod/podid

View pod events

PaiDLC:GetPodEvents

PaiDLC:GetPodEvents

dlcjob/jobid/pod/podid

View latest aggregated pod events

PaiDLC:GetLatestPodEvents

PaiDLC:GetLatestPodEvents

dlcjob/jobid/pod/podid

View paginated pod events

PaiDLC:GetPodPagedEvents

PaiDLC:GetPodPagedEvents

dlcjob/jobid/pod/podid

View event context in a pod

PaiDLC:GetPodContextEvents

PaiDLC:GetPodContextEvents

dlcjob/jobid/pod/podid

Create a TensorBoard instance

PaiDLC:CreateTensorboard

PaiDLC:CreateTensorboard

tensorboard/*

View a TensorBoard instance

PaiDLC:GetTensorboard

PaiDLC:GetTensorboard

tensorboard/tbid

List your TensorBoard instances

PaiDLC:ListTensorboards

PaiDLC:ListTensorboards

tensorboard/*

Start a TensorBoard instance

PaiDLC:StartTensorboard

PaiDLC:StartTensorboard

tensorboard/tbid

Stop a TensorBoard instance

PaiDLC:StopTensorboard

PaiDLC:StopTensorboard

tensorboard/tbid

Update a TensorBoard instance

PaiDLC:UpdateTensorboard

PaiDLC:UpdateTensorboard

tensorboard/tbid

Delete a TensorBoard instance

PaiDLC:DeleteTensorboard

PaiDLC:DeleteTensorboard

tensorboard/tbid

Get the shared URL for a TensorBoard instance

PaiDLC:GetTensorboardSharedUrl

PaiDLC:GetTensorboardSharedUrl

tensorboard/tbid

Create job template

PaiDLC:CreateJobTemplate

PaiDLC:CreateJobTemplate

jobtemplate/*

View job template details

PaiDLC:GetJobTemplate

PaiDLC:GetJobTemplate

jobtemplate/{templateId}

View job template list

PaiDLC:ListJobTemplates

PaiDLC:ListJobTemplates

jobtemplate/*

Update job template

PaiDLC:UpdateJobTemplate

PaiDLC:UpdateJobTemplate

jobtemplate/{templateId}

Delete job template

PaiDLC:DeleteJobTemplate

PaiDLC:DeleteJobTemplate

jobtemplate/{templateId}

AutoML

Description

Action (PAI workspace)

Action (RAM)

Workspace owner/workspace administrator

Algorithm developer

Algorithm O&M engineer

Visitor

Private (yours)

Private (created by others)

Public (yours)

Public (created by others)

Private (yours)

Private (created by others)

Public

Private (yours)

Private (created by others)

Public

Create an HPO experiment

PAIAutoML:CreateHpoExperiment

PAIAutoML:CreateHpoExperiment

 

 

 

 

 

 

 

 

Restart failed HPO trials

PAIAutoML:RestartHpoTrials

PAIAutoML:RestartHpoTrials

 

 

 

 

 

 

 

 

Stop an HPO experiment

PAIAutoML:StopHpoExperiment

PAIAutoML:StopHpoExperiment

 

 

 

 

 

 

Stop HPO trials

PAIAutoML:StopHpoTrials

PAIAutoML:StopHpoTrials

 

 

 

 

Update an HPO experiment

PAIAutoML:UpdateHpoExperiment

PAIAutoML:UpdateHpoExperiment

 

 

 

 

 

 

 

 

 

Delete an HPO experiment

PAIAutoML:DeleteHpoExperiment

PAIAutoML:DeleteHpoExperiment

 

 

 

 

 

 

 

View an HPO experiment

PAIAutoML:GetHpoExperiment

PAIAutoML:GetHpoExperiment

 

 

View a trial

PAIAutoML:GetHpoTrial

PAIAutoML:GetHpoTrial

 

 

List logs for an HPO experiment

PAIAutoML:ListHpoExperimentLogs

PAIAutoML:ListHpoExperimentLogs

 

List HPO experiments

PAIAutoML:ListHpoExperiments

PAIAutoML:ListHpoExperiments

 

 

List logs for a trial

PAIAutoML:ListHpoTrialLogs

PAIAutoML:ListHpoTrialLogs

 

 

List trials for an HPO experiment

PAIAutoML:ListHpoTrials

PAIAutoML:ListHpoTrials

 

 

List log names for a trial

PAIAutoML:ListHpoTrialLogNames

PAIAutoML:ListHpoTrialLogNames

 

 

List commands for a trial

PAIAutoML:ListHpoTrialCommands

PAIAutoML:ListHpoTrialCommands

 

Large model application development with LangStudio

Action

API

Workspace owner/administrator

Algorithm developer

Algorithm O&M

Private (by me)

Private (by others)

Public (by me)

Public (by others)

Private (by me)

Private (by others)

Public

Create application flow template

PaiLangStudio:CreateFlowTemplate

Update application flow template

PaiLangStudio:UpdateFlowTemplate

Delete application flow template

PaiLangStudio:DeleteFlowTemplate

View application flow template

PaiLangStudio:GetFlowTemplate

List application flow templates

PaiLangStudio:ListFlowTemplates

Create application flow

PaiLangStudio:CreateFlow

View application flow

PaiLangStudio:GetFlow

Update application flow

PaiLangStudio:UpdateFlow

Delete application flow

PaiLangStudio:DeleteFlow

List application flows

PaiLangStudio:ListFlows

Deploy application flow

PaiLangStudio:DeployFlow

Create connection

PaiLangStudio:CreateConnection

View connection

PaiLangStudio:GetConnection

Update connection

PaiLangStudio:UpdateConnection

Delete connection

PaiLangStudio:DeleteConnection

List connections

PaiLangStudio:ListConnections

Create runtime environment

PaiLangStudio:CreateRuntime

View runtime environment details

PaiLangStudio:GetRuntime

List runtime environments

PaiLangStudio:ListRuntimes

Reinstall dependencies for runtime environment

PaiLangStudio:ReloadRuntime

Update runtime environment

PaiLangStudio:UpdateRuntime

Delete runtime environment

PaiLangStudio:DeleteRuntime

View tool metadata

PaiLangStudio:GetToolMeta

List tools supported by the runtime container

PaiLangStudio:GetPackageTools

Get default tool metadata

PaiLangStudio:GetBuiltinTools

Create application flow run

PaiLangStudio:CreateFlowRun

View application flow run details

PaiLangStudio:GetFlowRun

List application flow run records

PaiLangStudio:ListFlowRuns

Cancel application flow run

PaiLangStudio:CancelFlowRun

Delete application flow run

PaiLangStudio:DeleteFlowRun

Check VPC consistency between user and resource

PaiLangStudio:CheckVpcConsistency

Create knowledge base

PaiLangStudio:CreateKnowledgeBase

Update knowledge base

PaiLangStudio:UpdateKnowledgeBase

View knowledge base details

PaiLangStudio:GetKnowledgeBase

List knowledge bases

PaiLangStudio:ListKnowledgeBases

Delete knowledge base

PaiLangStudio:DeleteKnowledgeBase

Resume application flow run

PaiLangStudio:ResumeFlowRun

Create snapshot

PaiLangStudio:CreateSnapshot

View snapshot details

PaiLangStudio:GetSnapshot

List snapshots

PaiLangStudio:ListSnapshots

Update snapshot

PaiLangStudio:UpdateSnapshot

Delete snapshot

PaiLangStudio:DeleteSnapshot

Create deployment

PaiLangStudio:CreateDeployment

View deployment details

PaiLangStudio:GetDeployment

List deployments

PaiLangStudio:ListDeployments

Update deployment record

PaiLangStudio:UpdateDeployment

Delete deployment record

PaiLangStudio:DeleteDeployment

Create toolset

PaiLangStudio:CreateToolset

View toolset details

PaiLangStudio:GetToolset

List toolsets

PaiLangStudio:ListToolsets

Update toolset

PaiLangStudio:UpdateToolset

Delete toolset

PaiLangStudio:DeleteToolset

Validate tool

PaiLangStudio:ValidateTool

EAS

Description

Action (PAI workspace)

Action (RAM)

Workspace owner/administrator

Algorithm developer

Algorithm O&M

Private (created by me)

Private (created by others)

Public (created by me)

Public (created by others)

Private (created by me)

Private (created by others)

Public

Create service

eas:CreateService

eas:CreateService

✅ Not distinguished by scope

✅ Not distinguished by scope

Enable service auto scaling

eas:CreateServiceAutoScaler

eas:CreateServiceAutoScaler

✅ Not distinguished by scope

✅ Not distinguished by scope

Enable service scheduled scaling

eas:CreateServiceCronScaler

eas:CreateServiceCronScaler

✅ Not distinguished by scope

✅ Not distinguished by scope

Enable service traffic mirroring

eas:CreateServiceMirror

eas:CreateServiceMirror

✅ Not distinguished by scope

✅ Not distinguished by scope

Create application service

eas:CreateAppService

eas:CreateAppService

✅ Not distinguished by scope

✅ Not distinguished by scope

Clone service

eas:CloneService

eas:CloneService

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete service

eas:DeleteService

eas:DeleteService

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete service tag

eas:DeleteServiceLabel

eas:DeleteServiceLabel

✅ Not distinguished by scope

✅ Not distinguished by scope

Disable service auto scaling

eas:DeleteServiceAutoScaler

eas:DeleteServiceAutoScaler

✅ Not distinguished by scope

✅ Not distinguished by scope

Disable service scheduled scaling

eas:DeleteServiceCronScaler

eas:DeleteServiceCronScaler

✅ Not distinguished by scope

✅ Not distinguished by scope

Restart service instances

eas:DeleteServiceInstances

eas:DeleteServiceInstances

✅ Not distinguished by scope

✅ Not distinguished by scope

Disable service traffic mirroring

eas:DeleteServiceMirror

eas:DeleteServiceMirror

✅ Not distinguished by scope

✅ Not distinguished by scope

Update service

eas:UpdateService

eas:UpdateService

✅ Not distinguished by scope

✅ Not distinguished by scope

Update service tag

eas:UpdateServiceLabel

eas:UpdateServiceLabel

✅ Not distinguished by scope

✅ Not distinguished by scope

Start service

eas:StartService

eas:StartService

✅ Not distinguished by scope

✅ Not distinguished by scope

Stop service

eas:StopService

eas:StopService

✅ Not distinguished by scope

✅ Not distinguished by scope

Restart service

eas:RestartService

eas:RestartService

✅ Not distinguished by scope

✅ Not distinguished by scope

Update service auto scaling configuration

eas:UpdateServiceAutoScaler

eas:UpdateServiceAutoScaler

✅ Not distinguished by scope

✅ Not distinguished by scope

Update service scheduled scaling configuration

eas:UpdateServiceCronScaler

eas:UpdateServiceCronScaler

✅ Not distinguished by scope

✅ Not distinguished by scope

Develop service

eas:DevelopService

eas:DevelopService

✅ Not distinguished by scope

✅ Not distinguished by scope

Commit and publish container

eas:CommitService

eas:CommitService

✅ Not distinguished by scope

✅ Not distinguished by scope

Update service traffic mirroring configuration

eas:UpdateServiceMirror

eas:UpdateServiceMirror

✅ Not distinguished by scope

✅ Not distinguished by scope

Switch service version

eas:UpdateServiceVersion

eas:UpdateServiceVersion

✅ Not distinguished by scope

✅ Not distinguished by scope

Update service safety lock

eas:UpdateServiceSafetyLock

eas:UpdateServiceSafetyLock

✅ Not distinguished by scope

✅ Not distinguished by scope

Update service instance attributes

eas:UpdateServiceInstance

eas:UpdateServiceInstance

✅ Not distinguished by scope

✅ Not distinguished by scope

Update application service

eas:UpdateAppService

eas:UpdateAppService

✅ Not distinguished by scope

✅ Not distinguished by scope

Adjust traffic for blue-green deployment

eas:ReleaseService

eas:ReleaseService

✅ Not distinguished by scope

✅ Not distinguished by scope

View service details

eas:DescribeService

eas:DescribeService

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View service auto scaling information

eas:DescribeServiceAutoScaler

eas:DescribeServiceAutoScaler

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View service scheduled scaling information

eas:DescribeServiceCronScaler

eas:DescribeServiceCronScaler

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View service diagnosis details

eas:DescribeServiceDiagnosis

eas:DescribeServiceDiagnosis

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View service instance diagnosis details

eas:DescribeServiceInstanceDiagnosis

eas:DescribeServiceInstanceDiagnosis

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View service logs

eas:DescribeServiceLog

eas:DescribeServiceLog

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View service events

eas:DescribeServiceEvent

eas:DescribeServiceEvent

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View service traffic mirroring information

eas:DescribeServiceMirror

eas:DescribeServiceMirror

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View service group details

eas:DescribeGroup

eas:DescribeGroup

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View preemptible instance price history

eas:DescribeSpotDiscountHistory

eas:DescribeSpotDiscountHistory

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List service instances

eas:ListServiceInstances

eas:ListServiceInstances

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List service versions

eas:ListServiceVersions

eas:ListServiceVersions

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List service containers

eas:ListServiceContainers

eas:ListServiceContainers

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List services

eas:ListServices

eas:ListServices

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List service groups

eas:ListGroups

eas:ListGroups

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Create resource group

eas:CreateResource

eas:CreateResource

✅ Not distinguished by scope

✅ Not distinguished by scope

Create resource group instances

eas:CreateResourceInstances

eas:CreateResourceInstances

✅ Not distinguished by scope

✅ Not distinguished by scope

Enable resource group log delivery

eas:CreateResourceLog

eas:CreateResourceLog

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete resource group

eas:DeleteResource

eas:DeleteResource

✅ Not distinguished by scope

✅ Not distinguished by scope

Disable resource group VPC direct connection

eas:DeleteResourceDLink

eas:DeleteResourceDLink

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete resource group instances

eas:DeleteResourceInstances

eas:DeleteResourceInstances

✅ Not distinguished by scope

✅ Not distinguished by scope

Disable resource group log delivery

eas:DeleteResourceLog

eas:DeleteResourceLog

✅ Not distinguished by scope

✅ Not distinguished by scope

Update resource group information

eas:UpdateResource

eas:UpdateResource

✅ Not distinguished by scope

✅ Not distinguished by scope

Update resource group VPC direct connection

eas:UpdateResourceDLink

eas:UpdateResourceDLink

✅ Not distinguished by scope

✅ Not distinguished by scope

Update resource group instance

eas:UpdateResourceInstance

eas:UpdateResourceInstance

✅ Not distinguished by scope

✅ Not distinguished by scope

View resource group details

eas:DescribeResource

eas:DescribeResource

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View resource group VPC connection information

eas:DescribeResourceDLink

eas:DescribeResourceDLink

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View resource group log delivery information

eas:DescribeResourceLog

eas:DescribeResourceLog

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List resource group instances

eas:ListResourceInstances

eas:ListResourceInstances

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List resource group workers

eas:ListResourceInstanceWorker

eas:ListResourceInstanceWorker

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List resource groups

eas:ListResources

eas:ListResources

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List services in a resource group

eas:ListResourceServices

eas:ListResourceServices

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Create benchmark task

eas:CreateBenchmarkTask

eas:CreateBenchmarkTask

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete benchmark task

eas:DeleteBenchmarkTask

eas:DeleteBenchmarkTask

✅ Not distinguished by scope

✅ Not distinguished by scope

View benchmark task details

eas:DescribeBenchmarkTask

eas:DescribeBenchmarkTask

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View benchmark task report

eas:DescribeBenchmarkTaskReport

eas:DescribeBenchmarkTaskReport

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List benchmark tasks

eas:ListBenchmarkTask

eas:ListBenchmarkTask

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Start benchmark task

eas:StartBenchmarkTask

eas:StartBenchmarkTask

✅ Not distinguished by scope

✅ Not distinguished by scope

Stop benchmark task

eas:StopBenchmarkTask

eas:StopBenchmarkTask

✅ Not distinguished by scope

✅ Not distinguished by scope

Update benchmark task

eas:UpdateBenchmarkTask

eas:UpdateBenchmarkTask

✅ Not distinguished by scope

✅ Not distinguished by scope

Create private gateway

eas:CreateGateway

eas:CreateGateway

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View private gateway details

eas:DescribeGateway

eas:DescribeGateway

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Update private gateway

eas:UpdateGateway

eas:UpdateGateway

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Create private gateway internal endpoint

eas:CreateGatewayIntranetLinkedVpc

eas:CreateGatewayIntranetLinkedVpc

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List private gateway internal endpoints

eas:ListGatewayIntranetLinkedVpc

eas:ListGatewayIntranetLinkedVpc

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete private gateway internal endpoint

eas:DeleteGatewayIntranetLinkedVpc

eas:DeleteGatewayIntranetLinkedVpc

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete private gateway

eas:DeleteGateway

eas:DeleteGateway

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List supported availability zones for gateway intranet

eas:ListGatewayIntranetSupportedZone

eas:ListGatewayIntranetSupportedZone

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List peered VPCs

eas:ListGatewayIntranetLinkedVpcPeer

eas:ListGatewayIntranetLinkedVpcPeer

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Add peered VPC

eas:CreateGatewayIntranetLinkedVpcPeer

eas:CreateGatewayIntranetLinkedVpcPeer

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete peered VPC

eas:DeleteGatewayIntranetLinkedVpcPeer

eas:DeleteGatewayIntranetLinkedVpcPeer

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Detach custom domain from a gateway

eas:DetachGatewayDomain

eas:DetachGatewayDomain

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Attach custom domain to a gateway

eas:AttachGatewayDomain

eas:AttachGatewayDomain

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List gateway custom domains

eas:ListGatewayDomains

eas:ListGatewayDomains

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List private gateways

eas:ListGateway

eas:ListGateway

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List gateway access permissions

eas:ListAclPolicy

eas:ListAclPolicy

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete gateway access permission

eas:DeleteAclPolicy

eas:DeleteAclPolicy

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Create gateway access permission

eas:CreateAclPolicy

eas:CreateAclPolicy

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Update tenant addon information

eas:ReinstallTenantAddon

eas:ReinstallTenantAddon

✅ Not distinguished by scope

✅ Not distinguished by scope

List tenant addons

eas:ListTenantAddons

eas:ListTenantAddons

✅ Not distinguished by scope

✅ Not distinguished by scope

Update virtual resource group information

eas:UpdateVirtualResource

eas:UpdateVirtualResource

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List virtual resource groups

eas:ListVirtualResource

eas:ListVirtualResource

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

View virtual resource group details

eas:DescribeVirtualResource

eas:DescribeVirtualResource

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete virtual resource group

eas:DeleteVirtualResource

eas:DeleteVirtualResource

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Create virtual resource group

eas:CreateVirtualResource

eas:CreateVirtualResource

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Delete resource group instance tag

eas:DeleteResourceInstanceLabel

eas:DeleteResourceInstanceLabel

✅ Not distinguished by scope

✅ Not distinguished by scope

Update resource group instance tag

eas:UpdateResourceInstanceLabel

eas:UpdateResourceInstanceLabel

✅ Not distinguished by scope

✅ Not distinguished by scope

List group endpoints

eas:DescribeGroupEndpoints

eas:DescribeGroupEndpoints

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

List service endpoints

eas:DescribeServiceEndpoints

eas:DescribeServiceEndpoints

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

Get a signed web link for a service

eas:DescribeServiceSignedUrl

eas:DescribeServiceSignedUrl

✅ Not distinguished by scope

✅ Not distinguished by scope

✅ Not distinguished by scope

ArtLab

Table 1. ArtLab - services

Permission description

Action (PAI workspace)

Action (RAM console)

Resource

Workspace owner/administrator

Algorithm developer

Algorithm O&M engineer

Guest

Private (created by me)

Private (created by others)

Public (created by me)

Public (created by others)

Private (created by me)

Private (created by others)

Public

Private (created by me)

Private (created by others)

Public

Create an AI4D service

PaiArtLab:CreateService

PaiArtLab:CreateAI4DService

ai4dServices/*

List AI4D services

PaiArtLab:ListServices

PaiArtLab:ListAI4DServices

ai4dServices/*

Delete an ArtLab service

PaiArtLab:DeleteService

PaiArtLab:DeleteService

artlabservice/servicename

Generate a signed URL for an ArtLab service

PaiArtLab:DescribeServiceSignedUrl

PaiArtLab:DescribeServiceSignedUrl

artlabservice/servicename

Table 2. ArtLab - resources

Permission description

Action (PAI workspace)

Action (RAM console)

Resource

Workspace owner/administrator

Algorithm developer

Algorithm O&M engineer

Guest

Private (created by me)

Private (created by others)

Public (created by me)

Public (created by others)

Private (created by me)

Private (created by others)

Public

Private (created by me)

Private (created by others)

Public

Get an ArtLab resource

PaiArtLab:GetResource

PaiArtLab:GetResource

artlabresource/{ResourceId}

Create an ArtLab resource

PaiArtLab:CreateResource

PaiArtLab:CreateResource

artlabresource/*

Update an ArtLab resource

PaiArtLab:UpdateResource

PaiArtLab:UpdateResource

artlabresource/{ResourceId}

List ArtLab resources

PaiArtLab:ListResources

PaiArtLab:ListResources

artlabresource/*

Delete an ArtLab resource

PaiArtLab:DeleteResource

PaiArtLab:DeleteResource

artlabresource/{ResourceId}

AI asset

Table 1. AI Assets: Datasets

Description

Action (managed by PAI workspace)

Action (managed by RAM)

Resource

Workspace owner / admin

Algorithm developer

Algorithm O&M engineer

Labeling administrator

Visitor

Private (created by me)

Private (created by others)

Public (created by me)

Public (created by others)

Private (created by me)

Private (created by others)

Public

Private (created by me)

Private (created by others)

Public

Private (created by me)

Private (created by others)

Public

Create dataset

PaiDataset:CreateDataset

PaiDataset:CreateDataset

dataset/*

Get dataset

PaiDataset:GetDataset

PaiDataset:GetDataset

dataset/{datasetId}

Update dataset

PaiDataset:UpdateDataset

PaiDataset:UpdateDataset

dataset/{datasetId}

Delete dataset

PaiDataset:DeleteDataset

PaiDataset:DeleteDataset

dataset/{datasetId}

List all datasets in the workspace

PaiDataset:ListAllDatasets

PaiDataset:ListAllDatasets

dataset/*

List public and owned datasets

PaiDataset:ListDatasets

PaiDataset:ListDatasets

dataset/*

Publish dataset to the workspace

PaiDataset:PublishDataset

PaiDataset:PublishDataset

dataset/{datasetId}

Change dataset owner

PaiDataset:ChangeDatasetOwner

PaiDataset:ChangeDatasetOwner

dataset/{datasetId}

Create dataset labels

PaiDataset:CreateDatasetLabels

PaiDataset:CreateDatasetLabels

dataset/{datasetId}

Delete dataset labels

PaiDataset:DeleteDatasetLabels

PaiDataset:DeleteDatasetLabels

dataset/{datasetId}

Create dataset version

PaiDataset:CreateDatasetVersion

PaiDataset:CreateDatasetVersion

dataset/{datasetId}/datasetVersion/*

Get dataset version

PaiDataset:GetDatasetVersion

PaiDataset:GetDatasetVersion

dataset/{datasetId}/datasetVersion/{versionName}

Delete dataset version

PaiDataset:DeleteDatasetVersion

PaiDataset:DeleteDatasetVersion

dataset/{datasetId}/datasetVersion/{versionName}

Update dataset version

PaiDataset:UpdateDatasetVersion

PaiDataset:UpdateDatasetVersion

dataset/{datasetId}/datasetVersion/{versionName}

Create dataset version labels

PaiDataset:CreateDatasetVersionLabels

PaiDataset:CreateDatasetVersionLabels

dataset/{datasetId}/datasetVersion/{versionName}

Delete dataset version labels

PaiDataset:DeleteDatasetVersionLabels

PaiDataset:DeleteDatasetVersionLabels

dataset/{datasetId}/datasetVersion/{versionName}

List dataset versions

PaiDataset:ListDatasetVersions

PaiDataset:ListDatasetVersions

dataset/{datasetId}/datasetVersion/*

Create dataset file metadata

PaiDataset:CreateDatasetFileMetas

PaiDataset:CreateDatasetFileMetas

dataset/{datasetId}/datasetfilemeta/*

Get dataset file metadata

PaiDataset:GetDatasetFileMeta

PaiDataset:GetDatasetFileMeta

dataset/{datasetId}/datasetfilemeta/{datasetfilemetaId}

Update dataset file metadata

PaiDataset:UpdateDatasetFileMetas

PaiDataset:UpdateDatasetFileMetas

dataset/{datasetId}/datasetfilemeta/{datasetfilemetaId}

Delete dataset file metadata

PaiDataset:DeleteDatasetFileMetas

PaiDataset:DeleteDatasetFileMetas

dataset/{datasetId}/datasetfilemeta/{datasetfilemetaId}

List dataset file metadata

PaiDataset:ListDatasetFileMetas

PaiDataset:ListDatasetFileMetas

dataset/{datasetId}/datasetfilemeta/*

Get dataset file metadata statistics

PaiDataset:GetDatasetFileMetasStatistics

PaiDataset:GetDatasetFileMetasStatistics

dataset/{datasetId}/datasetfilemeta/*

Create dataset task configuration

PaiDataset:CreateDatasetJobConfig

PaiDataset:CreateDatasetJobConfig

dataset/{datasetId}/datasetjobconfig/*

Update dataset task configuration

PaiDataset:UpdateDatasetJobConfig

PaiDataset:UpdateDatasetJobConfig

dataset/{datasetId}/datasetjobconfig/{datasetJobConfigId}

Get dataset task configuration

PaiDataset:GetDatasetJobConfig

PaiDataset:GetDatasetJobConfig

dataset/{datasetId}/datasetjobconfig/{datasetJobConfigId}

List dataset task configurations

PaiDataset:ListDatasetJobConfigs

PaiDataset:ListDatasetJobConfigs

dataset/{datasetId}/datasetjobconfig/*

Delete dataset task configuration

PaiDataset:DeleteDatasetJobConfig

PaiDataset:DeleteDatasetJobConfig

dataset/{datasetId}/datasetjobconfig/{datasetJobConfigId}

Create dataset task

PaiDataset:CreateDatasetJob

PaiDataset:CreateDatasetJob

dataset/{datasetId}/datasetjob/*

Get dataset task

PaiDataset:GetDatasetJob

PaiDataset:GetDatasetJob

dataset/{datasetId}/datasetjob/{datasetjobId}

List dataset tasks

PaiDataset:ListDatasetJobs

PaiDataset:ListDatasetJobs

dataset/{datasetId}/datasetjob/*

Update dataset task

PaiDataset:UpdateDatasetJob

PaiDataset:UpdateDatasetJob

dataset/{datasetId}/datasetjob/{datasetjobId}

Delete dataset task

PaiDataset:DeleteDatasetJob

PaiDataset:DeleteDatasetJob

dataset/{datasetId}/datasetjob/{datasetjobId}

Notify dataset task status

PaiDataset:NotifyDatasetJobStatus

PaiDataset:NotifyDatasetJobStatus

dataset/{datasetId}/datasetjob/{datasetjobId}

Stop dataset task

PaiDataset:StopDatasetJob

PaiDataset:StopDatasetJob

dataset/{datasetId}/datasetjob/{datasetjobId}

Table 2. AI asset – Code configuration management

Permission

Action (PAI workspace)

Action (RAM console)

Workspace administrator/owner

Algorithm developer

Algorithm O&M engineer

Visitor

Private (own)

Private (others)

Public (own)

Public (others)

Private (own)

Private (others)

Public

Private (own)

Private (others)

Public

Create code

PaiCodeSource:CreateCodeSource

PaiCodeSource:CreateCodeSource

View code

PaiCodeSource:GetCodeSource

PaiCodeSource:GetCodeSource

Delete code

PaiCodeSource:DeleteCodeSource

PaiCodeSource:DeleteCodeSource

List public and self-created code

PaiCodeSource:ListCodeSources

PaiCodeSource:ListCodeSources

List all code in the workspace

PaiCodeSource:ListAllCodeSources

PaiCodeSource:ListAllCodeSources

Publish code to the workspace

PaiCodeSource:PublishCodeSource

PaiCodeSource:PublishCodeSource

Table 3. AI Assets: Image Management

Action

Action (PAI workspace)

Action (RAM)

Resource

Workspace owner/administrator

Algorithm developer

Algorithm O and M engineer

Visitor

Private (own)

Private (others)

Public (own)

Public (others)

Private (own)

Private (others)

Public

Private (own)

Private (others)

Public

Create an image

PaiImage:AddImage

PaiImage:AddImage

image/*

Get an image

PaiImage:GetImage

PaiImage:GetImage

image/{imageId}

Get an official image

PaiImage:GetImage (Allowed by default, unless explicitly denied in RAM.)

provider/pai/image/{imageId}

Delete an image

PaiImage:RemoveImage

PaiImage:RemoveImage

image/{imageId}

List images (public and created by you)

PaiImage:ListImages

PaiImage:ListImages

image/*

List all images in the workspace

PaiImage:ListAllImages

PaiImage:ListAllImages

image/*

List official images

PaiImage:ListImages (Allowed by default, unless explicitly denied in RAM.)

provider/pai/image/{imageId}

Get image statistics (public and created by you)

PaiImage:GetImagesStatistics

PaiImage:GetImagesStatistics

image/*

Get statistics for all images in the workspace

PaiImage:GetAllImagesStatistics

PaiImage:GetAllImagesStatistics

image/*

Get statistics for official images

PaiImage:GetImagesStatistics (Allowed by default, unless explicitly denied in RAM.)

provider/pai/image/{imageId}

List image tags

PaiImage:ListImageLabels

PaiImage:ListImageLabels

imagelabel/*

Delete image tags

PaiImage:RemoveImageLabels

PaiImage:RemoveImageLabels

image/{imageId}/imagelabel/{imageLabelKey}

List image tag keys

PaiImage:ListImageLabelKeys (Allowed by default, unless explicitly denied in RAM.)

imagelabel/*

Batch-update image tags

PaiImage:UpdateImageLabels

PaiImage:UpdateImageLabels

image/{imageId}/imagelabel/*

Add image tags

PaiImage:AddImageLabels

PaiImage:AddImageLabels

image/{imageId}/imagelabel/*

Publish an image to the workspace

PaiImage:PublishImage

PaiImage:PublishImage

image/{imageId}

Create an image build

PaiImage:CreateImageBuild

PaiImage:CreateImageBuild

imagebuild/*

Get an image build

PaiImage:GetImageBuild

PaiImage:GetImageBuild

imagebuild/{imageBuildId}

Update an image build

PaiImage:UpdateImageBuild

PaiImage:UpdateImageBuild

imagebuild/{imageBuildId}

List image builds (public and created by you)

PaiImage:ListImageBuilds

PaiImage:ListImageBuilds

imagebuild/*

List all image builds in the workspace

PaiImage:ListAllImageBuilds

PaiImage:ListAllImageBuilds

imagebuild/*

Table 4. AI assets: Model management

Permission

Action (managed by the PAI workspace)

Action (managed by RAM)

Resource

Workspace owner/administrator

Algorithm developer

Algorithm O&M engineer

Visitor

Private (created by me)

Private (created by others)

Public (created by me)

Public (created by others)

Private (created by me)

Private (created by others)

Public

Private (created by me)

Private (created by others)

Public

Create models

PaiModel:CreateModel

PaiModel:CreateModel

model/*

Get model

PaiModel:GetModel

PaiModel:GetModel

model/{modelId}

Update model

PaiModel:UpdateModel

PaiModel:UpdateModel

model/{modelId}

Delete model

PaiModel:DeleteModel

PaiModel:DeleteModel

model/{modelId}

List public and self-created models

PaiModel:ListModels

PaiModel:ListModels

model/*

List all models in a workspace

PaiModel:ListAllModels

PaiModel:ListAllModels

model/*

Create model versions

PaiModel:CreateModelVersion

PaiModel:CreateModelVersion

model/{modelId}/modelVersion/*

Get model version

PaiModel:GetModelVersion

PaiModel:GetModelVersion

model/{modelId}/modelVersion/{versionName}

Update model version

PaiModel:UpdateModelVersion

PaiModel:UpdateModelVersion

model/{modelId}/modelVersion/{versionName}

Delete model version

PaiModel:DeleteModelVersion

PaiModel:DeleteModelVersion

model/{modelId}/modelVersion/{versionName}

List model versions

PaiModel:ListModelVersions

PaiModel:ListModelVersions

model/{modelId}/modelVersion/*

Update model tags

PaiModel:CreateModelLabels

PaiModel:CreateModelLabels

model/{modelId}

Delete model tags

PaiModel:DeleteModelLabels

PaiModel:DeleteModelLabels

model/{modelId}

Update model version tags

PaiModel:CreateModelVersionLabels

PaiModel:CreateModelVersionLabels

model/{modelId}/modelVersion/{versionName}

Delete model version tags

PaiModel:DeleteModelVersionLabels

PaiModel:DeleteModelVersionLabels

model/{modelId}/modelVersion/{versionName}

Publish model to the workspace

PaiModel:PublishModel

PaiModel:PublishModel

model/{modelId}

Table 5. AI assets: Custom components

Permission

API action

Workspace owner/administrator

Algorithm developer

Algorithm O&M engineer

Visitor

Private (yours)

Private (others)

Public (yours)

Public (others)

Private (yours)

Private (others)

Public

Private (yours)

Private (others)

Public

Create component

PAIComponentManagement:CreateComponent

✅ All

✅ All

Get component

PAIComponentManagement:GetComponent

✅ All

✅ All

Update component

PAIComponentManagement:UpdateComponent

✅ All

✅ All

Delete component

PAIComponentManagement:DeleteComponent

✅ All

✅ All

List components

PAIComponentManagement:ListComponents

✅ All

✅ All

✅ All

Create component version

PAIComponentManagement:CreateComponentVersion

✅ All

✅ All

Get component version

PAIComponentManagement:GetComponentVersion

✅ All

✅ All

Update component version

PAIComponentManagement:UpdateComponentVersion

✅ All

✅ All

Delete component version

PAIComponentManagement:DeleteComponentVersion

✅ All

✅ All

List component versions

PAIComponentManagement:ListComponentVersions

✅ All

✅ All

✅ All

Table 6. AI assets: Connection management

Action

PAI Workspace action

RAM action

Workspace owner/workspace administrator

Algorithm developer

Algorithm O&M

Visitor

Private (self-created)

Private (created by others)

Public (self-created)

Public (created by others)

Private (self-created)

Private (created by others)

Public

Private (self-created)

Private (created by others)

Public

Create a connection

PaiWorkspace:CreateConnection

PaiWorkspace:CreateConnection

View a connection

PaiWorkspace:GetConnection

PaiWorkspace:GetConnection

Update a connection

PaiWorkspace:UpdateConnection

PaiWorkspace:UpdateConnection

Delete a connection

PaiWorkspace:DeleteConnection

PaiWorkspace:DeleteConnection

List public and your own connections

PaiWorkspace:ListConnections

PaiWorkspace:ListConnections

List all connections in the workspace

PaiWorkspace:ListAllConnections

PaiWorkspace:ListAllConnections