All Products
Document Center

Service Catalog:Grant permissions to the administrator

Last Updated:Sep 27, 2023

The administrator can define, manage, and distribute compliant IT services. The administrator must have the permissions to access the Service Catalog console, manage products, product portfolios, and constraints, and grant end user permissions. The administrator can be an Alibaba Cloud account, a Resource Access Management (RAM) user, or a RAM role. In this topic, the administrator is a RAM user.


A RAM user is created. For more information, see Create a RAM user.


  1. Log on to the RAM console.

  2. In the left-side navigation pane, choose Identities > Users.

  3. On the Users page, find the RAM user to which you want to grant permissions and click Add Permissions in the Actions column.

  4. In the Add Permissions panel, set the Authorized Scope parameter to Alibaba Cloud Account and select one or more policies.

    • System Policy: the system policy. Select the AliyunServiceCatalogAdminFullAccess policy in the Authorization Policy Name column.


      If the AliyunServiceCatalogAdminFullAccess policy is attached to the administrator, the administrator has the full management permissions on Service Catalog. The administrator can access and configure all features of Service Catalog.

    • Custom Policy: the custom policies. To specify custom policies, select the required policies in the Authorization Policy Name column.

      For information about how to create a custom policy, see Create a custom policy.

  5. Click OK.

  6. Click Complete.