All Products
Search
Document Center

Alibaba Cloud DevOps:Permission management

Last Updated:Aug 21, 2026

Assign appropriate permissions to team members to maintain enterprise security while keeping business processes running smoothly. You can configure global permissions for each role or set fine-grained permissions for specific resources, such as pipelines and host groups.

Role permissions

  1. Create roles and configure their permissions

    Log on to the Alibaba Cloud DevOps Flow console. In the left navigation bar, select Enterprise role permissions. On this page, you can view and configure permissions for each role. By default, the page displays cards for roles such as Owner, Administrator, Member, and External member. You can also add custom roles as needed. To create a custom role, click New Role in the upper-right corner. To edit an existing role, click its card to expand the permission configuration panel, select the permissions to assign, and then click Save.

    Available permissions for roles

    Permission

    Sub-permission

    Description

    Permission settings

    Create role

    Manage roles in Global Settings.

    Modify role permissions

    Delete role

    Pipeline management

    Create pipeline

    Manage pipelines.

    All management permissions

    View all pipelines

    Host group management

    Create deployment group

    Manage a host group.

    All management permissions

    Service connection management

    Create service connection

    Manage service authorizations on Alibaba Cloud, such as ECS and OSS.

    All management permissions

    Pipeline template management

    Create pipeline template

    Manage a pipeline template.

    All management permissions

    Variable group management

    Create variable group

    Manage common variable groups. For more information, see environment variables.

    All management permissions

    Tag category management

    Create tag category

    Manage tag categories.

    All management permissions

    Tag management

    Create tag

    Manage tags.

    All management permissions

    Step management

    All management permissions

    Perform operations in step management.

    Job management

    Create permission

    Perform operations in job management.

    All management permissions

    Build cluster management

    Create build cluster

    Manage a build cluster.

    All management permissions

    Enterprise Maven configuration management

    All management permissions

    Configure custom Maven configurations in organization settings.

    Pipeline group management

    All management permissions

    Manage permissions for pipeline groups and their members to control access to development, testing, and production environments.

    Kubernetes cluster management

    Create Kubernetes cluster

    Manage a Kubernetes cluster and its usage permissions.

    All management permissions

    General settings

    Visibility management

    When enabled, users can view only the pipelines or pipeline groups to which they have access, enhancing data security.

    Redline gating

    When enabled, pipeline administrators can bypass manual gates. This allows an administrator to advance the process if a designated approver is unavailable.

    Rollback permission

    When enabled, only pipeline administrators can perform rollbacks, preventing unauthorized rollbacks that may introduce system risks.

    Organization public key management

    Use or reset the organization's public key when configuring a code source.

    Resource usage

    View resource usage

    View and download resource usage information for pipelines.

    Download resource usage details

  2. Assign roles to team members

    Log on to the Alibaba Cloud DevOps workbench. Go to Organization Management and select . In the member list, assign a role to each member.

    Available roles include Owner and Member. To change a member's role, click the dropdown arrow next to the current role.

Pipeline member permissions

Log on to the Alibaba Cloud DevOps Flow console. In the My Pipelines list, click the target pipeline. In the upper-right corner, click the image icon and select Pipeline Settings > Member Permissions. In the member list, you can set permissions for each member.

From the permissions dropdown menu, select All permissions, Run permission, or View permission. You can also click Remove to remove the member from the pipeline, or click Transfer Ownership to make them the new owner.

The following table describes the available permissions.

Actions

Owner permission

All permissions

Run permission

View permission

View pipeline

Yes

Yes

Yes

Yes

Edit pipeline

Yes

Yes

No

No

Delete pipeline

Yes

Yes

No

No

Run pipeline

Yes

Yes

Yes

No

Add members

Yes

Yes

No

No

Pipeline group permissions

Log on to the Alibaba Cloud DevOps Flow console. In the Groups section of the left-side navigation pane, click the target group. On the group page, click the member icon at the top. In the member list, you can set permissions for each member.

The following table describes the available permissions.

Actions

All permissions

Run permission

View permission

View pipelines in the group

Yes

Yes

Yes

Edit pipelines in the group

Yes

No

No

Delete pipelines in the group

Yes

No

No

Run pipelines in the group

Yes

Yes

No

Add members to pipelines in the group

Yes

No

No

Add members to the group

Yes

No

No

Permissions for pipeline groups and individual pipelines follow these rules:

  • If a member's permissions are set at the group level but not for an individual pipeline, the group-level permissions apply to the pipeline.

  • If a member has permissions set at both the group level and the pipeline level, the more permissive of the two scopes applies.

  • To move a pipeline to a group, you must have 'All permissions' for the pipeline.

  • With 'All permissions' for a pipeline group, you can add group members, create pipelines in the group, and move pipelines to the group.

Host group member permissions

Log on to the Alibaba Cloud DevOps Flow console. In the left-side navigation pane, choose . Select the target host group and click Invite in the upper-right corner. In the dialog box that appears, add members and assign a role to each.

The following table describes the available roles and permissions.

Actions

Administrator

User

Use host group

Yes

Yes

Edit host group

Yes

No

Delete host group

Yes

No

Add members

Yes

No