Alibaba Cloud Bailian's permission management supports multi-dimensional access control at both the console page level and model level, meeting the complex organizational architecture requirements of multi-region and multi-user environments.
Alibaba Cloud Bailian Identity Management
A single business space is the smallest unit for fine-grained permission management (for models and users) and Alibaba Cloud billing allocation.
Bailian’s business space permission management is based on three roles:
- Super Administrator: Can manage user permissions, available models per space, model rate limiting per space, and API keys across spaces.
- Business Space Administrator: Responsible only for user permissions and resource management within a specific business space.
- Regular User: Uses resources according to assigned permissions.
| Business Space Permission | Super Administrator | Business Space Administrator | Regular User |
|---|---|---|---|
| Enable specific model invocation & rate limiting | Supported | Not supported | Not supported |
| Manage user permissions within the space | Supported | Supported | Not supported |
| Manage API keys | Supported | Supported | Limited |
| Use resources | Supported | Supported | Supported |
For the detailed permission matrix and configuration steps, refer to the Permission Management page in the Alibaba Cloud Bailian console. For RAM user permission policy configuration, see the Alibaba Cloud RAM console documentation.