When you log on to the Guardrails console for the first time, you must grant Guardrails permissions to access related cloud resources. This lets you use the services provided by Cloud Firewall. This topic describes how to use the Guardrails service-linked role AliyunServiceRoleForCIPAccessLogDelivery to grant permissions to access cloud resources. This topic also describes how to delete AliyunServiceRoleForCIPAccessLogDelivery.
Prerequisites
You are using an Alibaba Cloud account or a Resource Access Management (RAM) user that has permissions to create and delete service-linked roles.
Background information
Guardrails works with Simple Log Service to provide a new intelligent log analysis feature. This feature offers a one-stop service for real-time collection, storage, query, and in-depth analysis of logs for security detection of AI model inputs and outputs. Powered by a robust log processing engine, it can retrieve and analyze tens of billions of log entries in seconds. This helps you accurately detect abnormal behavior, trace threat sources, optimize security policies, and meet all compliance and audit requirements. By default, the pay-as-you-go edition of Guardrails provides 180 days of log storage. You can adjust the storage duration and capacity as needed to find the best balance between cost and security. You can grant access permissions using the Guardrails service-linked role AliyunServiceRoleForCIPAccessLogDelivery, which is created automatically by the system. You do not need to manually create or modify the service-linked role. For more information, see Service-linked Role.
Procedure
You can create the service-linked role on the purchase or upgrade/downgrade page.

You can view the service-linked role that Alibaba Cloud automatically creates for Guardrails on the Roles page of the RAM console. Your Guardrails instance can access Simple Log Service only after the service-linked role AliyunServiceRoleForCIPAccessLogDelivery is created.
Delete the service-linked role
You can delete the Guardrails service-linked role AliyunServiceRoleForCIPAccessLogDelivery. For more information, see Delete a RAM role.