All Products
Search
Document Center

Simple Log Service:Authorization

Last Updated:Jun 04, 2026

Alert management in Simple Log Service requires two types of permissions: operation permissions to create and manage alert tasks, and data access permissions when alerts monitor data across projects, regions, accounts, or write records to an EventStore.

Operation permissions

Alert operations include creating, deleting, modifying, and viewing alert tasks.

  • Alibaba Cloud account: An Alibaba Cloud account has management permissions on Simple Log Service. No additional permissions are needed to perform alert operations with this account.

  • Resource Access Management (RAM) user: To perform alert operations as a RAM user, an Alibaba Cloud account must first grant the necessary permissions to the RAM user. For security best practices, we recommend that you use a RAM user to perform alert operations. For more information, see Grant a RAM user permissions to manage alerts.

Data access permissions

  • Cross-project, cross-region, or cross-account monitoring: To monitor data across projects, regions, or Alibaba Cloud accounts, Simple Log Service assumes a RAM role to access the required Logstores or Metricstores. Grant the required permissions to the RAM role before configuring such alert rules. For more information, see Configure authorization for data monitoring across projects.

  • Writing alert records to an EventStore: To record alert information in an EventStore, Simple Log Service assumes a RAM role to access the required EventStore. Grant the required permissions to the RAM role before enabling this feature. For more information, see Grant permissions to write alerts to an eventstore.