Predefined roles
The system provides initial roles to address common business scenarios and enterprise management risks.
Predefined roles
You can use predefined roles to quickly grant permissions to accounts. You can also customize these roles to meet your specific business needs. For more information, see Manage custom roles.
After you enable the multi-account management service, the following roles are available by default:
|
No. |
Role name |
Role type |
Description |
|
1 |
Standard Member |
functional role |
This role is assigned by default to new accounts and existing non-financial cloud accounts. It grants all permissions available to an individual account. |
|
2 |
Basic Financial Member |
functional role |
By default, this role is assigned only to financial management sub-accounts from the legacy Enterprise Finance system. Unlike the Standard Member role, it does not include the permission to make withdrawals. |
|
3 |
Basic Financial Administrator |
management role |
Manages basic financial data, including bills, invoices, and payments. |
|
4 |
Organization and Account Administrator |
management role |
Manages custom organizational nodes under the 'Organization and Accounts' menu, including creating, retrieving, updating, and deleting nodes. It also grants permissions to perform the following actions on accounts within these custom nodes: view accounts, modify display names, modify security phone numbers, move accounts, grant permissions, freeze or unfreeze logins, set billing policies, and remove account management relationships. |
|
5 |
Account Operations Administrator |
functional role |
Grants permissions to manage uninvited accounts, manage accounts in the default directory, create accounts, query the enterprise directory, and manage roles and permissions. |
-
The primary financial account in the legacy Enterprise Finance system is assigned four roles by default in the new version: Standard Member, Basic Financial Administrator, Organization and Account Administrator, and Account Operations Administrator.
-
In the new version, financial management sub-accounts from the legacy Enterprise Finance system are assigned the Basic Financial Member role by default. This role does not include withdrawal permissions.
Initialize Role Permissions
-
coupon management1: With the coupon management (
couponmanagement) permission, administrator accounts cannot access "voucher management" or "coupon management" for member accounts. -
savings plan management2: With the savings plan management (
savingplanmanagement) permission, administrator accounts cannot access "purchase recommendation" or "discount details" for member accounts.
Each initialization role has the following permissions:
|
Permission name |
Permission code |
Description |
General member |
Basic financial member |
Basic financial administrator |
Organization and account administrator |
Account operations administrator |
|
Available credit warning settings |
setavailablecreditwarning |
Grants permission to set and modify the available credit warning. |
√ |
√ |
√ |
× |
× |
|
Auto-payment settings |
setautopay |
Grants permission to enable or disable auto-payment. |
√ |
√ |
√ |
× |
× |
|
Extended suspension service settings |
setextendedsuspensionservice |
Grants permission to enable or disable the extended suspension service. |
√ |
√ |
√ |
× |
× |
|
Top-up |
chargefund |
Grants permission to top up an account balance via bank transfer, Alipay, or corporate online banking in the Billing and Costs console or the Alibaba Cloud app. |
√ |
√ |
√ |
× |
× |
|
Withdrawal |
withdrawfund |
Grants permission to initiate withdrawals and query withdrawal records. |
√ |
× |
√ |
× |
× |
|
Fund record query |
queryfund |
Grants permission to query and export fund transaction records, and to query enterprise assets. |
√ |
√ |
√ |
× |
× |
|
Bill and settlement query |
querybill |
Grants permission to query monthly bills and bill details, and to export bill details and product usage details. |
√ |
√ |
√ |
× |
× |
|
Manual payment |
payforbill |
Grants permission to make manual payments. |
√ |
√ |
√ |
× |
× |
|
Cost allocation settings |
setcostallocation |
Grants permission to configure cost allocation, query cost tags and financial units, and create, edit, or delete financial units. |
√ |
√ |
√ |
× |
× |
|
Cost analysis management |
costmanagement |
Grants permission to access and manage cost analysis and reports. |
√ |
√ |
√ |
× |
× |
|
Budget management |
budgetmanagement |
Grants permission to manage budgets. This includes creating, editing, deleting, and copying budgets, subscribing to budget vs. actual analysis, querying budget lists and analysis, and exporting reports. |
√ |
√ |
√ |
× |
× |
|
Cost optimization management |
optimizemanagement |
Grants permission to access and use cost optimization features. |
√ |
√ |
√ |
× |
× |
|
Cost bill management |
gaapbillmanagement |
Grants permission to access and use cost bill features. |
√ |
√ |
√ |
× |
× |
|
Order query |
queryorder |
Grants permission to query orders and their details, and to export order details. |
√ |
√ |
√ |
× |
× |
|
Order cancellation |
cancelorder |
Grants permission to cancel unpaid orders from the order list in the Billing and Costs console. |
√ |
√ |
√ |
× |
× |
|
Order payment |
payorder |
Grants permission to pay for orders from the order list in the Billing and Costs console. |
√ |
√ |
√ |
× |
× |
|
Renewable item list query |
queryrenew |
Grants permission to query the renewable item list in Renewal Management in the Billing and Costs console. |
√ |
√ |
√ |
× |
× |
|
Order renewal settings |
configrenew |
Grants permission to configure renewal settings (such as auto-renewal or do-not-renew) in Renewal Management. |
√ |
√ |
√ |
× |
× |
|
Export renewal list |
expotrenew |
Grants permission to export the renewal list from Renewal Management in the Billing and Costs console. |
√ |
√ |
√ |
× |
× |
|
Renewal operation |
writerenew |
Grants permission to perform renewal operations in Renewal Management. |
√ |
√ |
√ |
× |
× |
|
Refund query |
queryrefund |
Grants permission to query the list of refundable resources and their cost details in Refund Management. |
√ |
√ |
√ |
× |
× |
|
Refund operation |
writerefund |
Grants permission to perform refund operations for resources in Refund Management. |
√ |
√ |
√ |
× |
× |
|
Coupon queryNote 1 |
couponmanagement |
Grants permission to query coupons. |
√ |
√ |
√ |
× |
× |
|
Savings Plan managementNote 2 |
savingplanmanagement |
Grants permission to manage Savings Plans. |
√ |
√ |
√ |
× |
× |
|
Resource package management |
resourcemanagement |
Grants permission to query and manage resource packages. |
√ |
√ |
√ |
× |
× |
|
Invoice query |
queryinvoice |
Grants permission to query invoice details. |
√ |
√ |
√ |
× |
× |
|
Invoicing information management |
invoiceinformationmanagement |
Grants permission to edit invoicing information, such as invoice titles and addresses. |
√ |
√ |
√ |
× |
× |
|
Invoice application |
applyinvoice |
Grants permission to apply for invoices based on monthly bills. |
√ |
√ |
√ |
× |
× |
|
Order price query |
queryprice |
Grants permission to query prices when placing an order. |
√ |
√ |
√ |
× |
× |
|
Unified settlement |
unifiedsettlement |
Grants permission to configure unified settlement. |
× |
× |
√ |
× |
× |
|
Asset sharing settings |
assetsharing |
Grants permission to configure asset sharing. |
× |
× |
√ |
× |
× |
|
Account credit information query |
queryusercredit |
Grants permission to query the credit limit change history for managed accounts. |
× |
× |
√ |
× |
× |
|
Enterprise credit information query |
queryenterprisecredit |
Grants permission to query the credit limit change history for the managed enterprise entity. |
× |
× |
√ |
× |
× |
|
Credit limit settings |
setcredit |
Grants permission to set and modify the credit limits for managed accounts. |
× |
× |
√ |
× |
× |
|
Fund transfer |
fundtransfer |
Grants permission to transfer and reclaim funds from the balances of managed accounts. |
× |
× |
√ |
× |
× |
|
Organization management |
organization.manage |
Grants permission to view, add, rename, move, and delete organization folders. |
× |
× |
× |
√ |
× |
|
Account management |
account.manage |
Grants permission to view accounts, modify display names and security phone numbers, move accounts, grant permissions, freeze or unfreeze logins, and set settlement policies. |
× |
× |
× |
√ |
× |
|
Uninvited account management |
uninvite.directory |
Grants permission to view, invite, and cancel invitations for uninvited accounts. |
× |
× |
× |
× |
√ |
|
Default folder account management |
default.directory |
Grants permission to view and move accounts within the default folder. |
× |
× |
× |
× |
√ |
|
Account creation |
account.create |
Grants permission to create new enterprise member accounts. |
× |
× |
× |
× |
√ |
|
Enterprise directory query |
enterprise.manage |
Grants permission to query enterprise relationships. |
× |
× |
× |
× |
√ |
|
Role and permission management |
role.manage |
Grants permission to view, create, modify, and delete roles, and to manage the permissions they contain. |
× |
× |
× |
× |
√ |