全部產品
Search
文件中心

AgentLoop:RAM權限原則參考

更新時間:Jul 25, 2026

在使用AgentLoop 服務時,不同的使用人員可能需要不同的存取權限,此時主帳號使用者可以通過對RAM設定不同的權限原則來實現對AgentLoop的資源的存取控制。

權限原則類型

若您使用RAM,請根據需要向主帳號使用者申請權限原則。授權操作請參考管理RAM使用者的許可權。

阿里雲為使用者提供了兩類策略類型,分別是系統權限原則與自訂策略。

  • 系統權限原則:由阿里雲統一建立,使用更簡單,無法修改。

  • 自訂策略:需要使用者自訂策略內容,若系統權限原則不能滿足要求,可建立自訂權限原則實現最小授權,實現許可權精細化管控。

系統權限原則

系統權限原則統一由阿里雲建立,策略的版本更新由阿里雲維護,使用者只能使用不能修改。AgentLoop的系統權限原則如下:

  • AliyunAgentLoopFullAccess:授予管理AgentLoop的許可權。

  • AliyunAgentLoopReadOnlyAccess:授予唯讀訪問AgentLoop的許可權。

自訂許可權配置

使用情境:客戶希望針對子帳號以及角色,配置細粒度管控許可權,可以按需添加自訂許可權點,適合精細管理情境。

讀許可權

許可權點

說明

{
      "Action": [
        "agentloop:Get*",
        "agentloop:List*",
        "agentloop:Describe*",
        "agentloop:ExecuteQuery"
      ],
      "Resource": "*",
      "Effect": "Allow"
    }

AgentLoop 服務讀許可權,包含Agent空間,資料集,經驗庫等

{
    "Action": [
        "log:GetLogStoreLogs",
        "log:GetLogStoreHistogram",
        "log:GetIndex",
        "log:GetLogStore",
        "log:GetProject",
        "log:ListLogStores",
        "log:ListProject"
    ],
    "Resource": "*",
    "Effect": "Allow"
}

查詢Log Service已有的 LogStore 中資料

{
    "Action": [
        "airegistry:ListNamespaces",
        "airegistry:ListPrompts",
        "airegistry:ListPromptVersions",
        "airegistry:ListSkills",
        "airegistry:GetNamespace",
        "airegistry:GetPrompt",
        "airegistry:GetPromptVersion",
        "airegistry:GetPromptVersionDetail",
        "airegistry:GetPromptGovernance",
        "airegistry:GetSkillDetail",
        "airegistry:GetSkillVersionDetail",
        "airegistry:DownloadSkillVersion",
        "airegistry:DownloadSkillVersionViaOss"
    ],
    "Resource": "*",
    "Effect": "Allow"
}

包含 AI 治理中心 Prompt 和Skill 讀許可權。

{
    "Action": [
        "cms:GetWorkspace",
        "cms:GetEntityStoreData",
        "cms:GetServiceObservability",
        "cms:GetUmodelCommonSchemaRef",
        "cms:GetAddon",
        "cms:GetAddonSchema",
        "cms:GetAddonCodeTemplate",
        "cms:GetAddonMetrics",
        "cms:GetAddonAlertTemplates",
        "cms:GetAddonRelease",
        "cms:GetPrometheusUserSetting",
        "cms:GetCmsService",
        "cms:GetCloudResource",
        "cms:GetCloudResourceData",
        "cms:ListWorkspaces",
        "cms:ListServices",
        "cms:ListAddons",
        "cms:ListIntegrationPolicies",
        "cms:ListAddonReleases",
        "cms:ListIntegrationPolicyResources",
        "cms:ListIntegrationPolicyCollectors",
        "cms:ListPrometheusInstances"
    ],
    "Resource": "*",
    "Effect": "Allow"
}

CloudMonitor2.0 工作空間,資料實體,Addon,APM服務,Umodel 相關讀許可權

{
      "Action": [
"resourcecenter:GetResourceCenterServiceStatus"
      ],
      "Resource": "*",
      "Effect": "Allow"
    }

查詢資源中心服務狀態的許可權

寫入權限

在讀許可權基礎上,額外新增寫操作許可權點如下:

許可權點

說明

  {
    "Action": [
      "agentloop:*"
    ],
    "Resource": "*",
    "Effect": "Allow"
  }

AgentLoop 服務系統管理權限

{
    "Action": [
        "airegistry:CreatePrompt",
        "airegistry:UpdatePrompt",
        "airegistry:DeletePrompt",
        "airegistry:CreatePromptVersion",
        "airegistry:UpdatePromptVersion",
        "airegistry:SubmitPromptVersion",
        "airegistry:DeletePromptVersion",
        "airegistry:CreateSkillDraft",
        "airegistry:UpdateSkillDraft",
        "airegistry:DeleteSkillDraft",
        "airegistry:SubmitSkillVersion",
        "airegistry:PublishSkillVersion",
        "airegistry:ForcePublishSkillVersion",
        "airegistry:UpdateSkillBizTags",
        "airegistry:UpdateSkillLabels",
        "airegistry:OnlineSkill",
        "airegistry:OfflineSkill",
        "airegistry:UpdateSkillScope",
        "airegistry:DeleteSkill",
        "airegistry:UploadSkill",
        "airegistry:UploadSkillViaOss"
    ],
    "Resource": "*",
    "Effect": "Allow"
}

AI 治理中心 Prompt 和Skill 建立、編輯、發布、刪除、調試等全部許可權。

{
    "Action": [
        "log:CreateIndex",
        "log:CreateLogStore"
    ],
    "Resource": "*",
    "Effect": "Allow"
}

Log Service建立LogStore 和索引配置許可權

{
    "Action": [
        "cms:CreateService",
        "cms:CreateIntegrationPolicy",
        "cms:CreateAddonRelease",
        "cms:CreateCloudResource",
        "cms:CreateServiceObservability",
        "cms:ProxyApiForMemberAccount",
        "cms:UpsertUmodelCommonSchemaRef",
        "cms:UpsertUmodelData"
    ],
    "Resource": "*",
    "Effect": "Allow"
}

CloudMonitor2.0 工作空間,APM服務,可觀測服務,Umodel 相關建立,修改許可權。

{
    "Action": "ram:CreateServiceLinkedRole",
    "Resource": "*",
    "Effect": "Allow",
    "Condition": {
        "StringEquals": {
            "ram:ServiceName": [
                "agentloop.aliyuncs.com"
            ]
        }
    }
}

建立AgentLoop 服務關聯角色