Create a Team

Updated at:

A Team is the resource ownership and isolation boundary in FC Agent Sandbox. API keys, templates, sandboxes, and volumes all belong to a specific Team. You must create a Team before you can use FC Agent Sandbox.

Teams and resource ownership

Object

Description

Alibaba Cloud UID

The account that owns FC Agent Sandbox resources. RAM users operate on behalf of the Alibaba Cloud account they belong to; they do not create a separate FC Agent Sandbox resource space.

ResourceGroupID

The Alibaba Cloud resource group ID, used for resource grouping, list filtering, and RAM authorization. One resource group can contain multiple Teams.

Team

An FC Agent Sandbox workspace. Each Team belongs to one Alibaba Cloud account and one resource group, and has a unique Team ID.

API key

A data-plane credential. Each API key is bound to one Team. Templates and sandboxes created with that key belong to the same Team.

Volume

A storage resource under a Team, whose ownership is determined by the Team ID.

The relationship is as follows:

Alibaba Cloud UID
└── ResourceGroupID
    └── Team (Team ID, subscription plan)
        ├── API key
        ├── Template
        ├── Sandbox
        └── Volume

Resource groups handle resource grouping and RAM authorization within an Alibaba Cloud account. Teams provide a finer-grained workspace inside a resource group, used to isolate different businesses, projects, or environments.

  • Resource ownership: API keys, templates, sandboxes, and volumes all belong to a specific Team, and inherit that Team's resource group and subscription plan.

  • Resource isolation: A resource group can contain multiple Teams. Resources in different Teams are isolated from each other and cannot be used across Teams.

  • Access entry: The console first filters Teams by resource group, then lists the resources under the selected Team. When you use the SDK, the API key determines the current Team.

  • Permission control: RAM users can be granted Team management permissions at the account or resource group scope, and permissions can be further restricted to specific Teams. A RAM user can only view and operate the Teams and resources within the granted scope.

Resource groups and Teams form a two-level hierarchy and cannot replace each other. Typically, plan resource groups by organization or permission boundary first, and then divide Teams by business, project, or environment. For example, create a production Team and a testing Team under the same resource group.

RAM authorization

On top of resource group authorization, you can further restrict a RAM user's permissions to specific Teams. Examples:

  • Isolate production and testing environments: Create a production Team and a testing Team under the same resource group. Production operators manage only the production Team, while developers use only the testing Team.

  • Isolate different projects: Use a dedicated Team per project. Grant project members access only to their Team so that they cannot reach resources in other projects.

  • Limit the scope of external collaboration: Create a dedicated Team for external partners and grant access only to that Team, so they cannot view or operate internal Teams.

  • Set up read-only auditing: Grant auditors read-only permissions on specific Teams. They can view resources but cannot create, modify, or delete them.

When you apply precise authorization, grant only the permissions required for the target Team and its sub-resources based on actual responsibilities. Do not grant access to all Teams under the account when it is not needed. For RAM policy configuration and Team-level Resource examples, see Configure RAM User Permissions.

Prerequisites

  • Function Compute and FC Agent Sandbox are activated.

  • Your Alibaba Cloud account or RAM user has permission to manage Teams.

  • If you need a custom resource group, the resource group has been created and the corresponding RAM authorization is in place.

Create a Team

Create a Team in the console

  1. Log on to the Function Compute console and open any FC Agent Sandbox page.

  2. Select a resource group in the upper-left corner. The new Team will belong to this resource group.

  3. Open the Team selector and click Create Team.

  4. Set the Team name, resource group, subscription plan, and description.

  5. Click Confirm.

Configuration items:

Item

Required

Description

Team name

Yes

Identifies the Team. Team names must be unique within the same Alibaba Cloud account.

Resource group

Yes

The Alibaba Cloud resource group that the Team belongs to. API keys, templates, sandboxes, and volumes under the Team inherit this resource group context.

Subscription plan

Yes

Determines the capabilities available to sandboxes under the Team. For plan differences and upgrades, see Teams and subscription plans.

Description

No

Describes the business, environment, or purpose of the Team.

Create a Team through the SDK

To automate Team creation, use an Alibaba Cloud SDK to call CreateTeam. This API is part of the FC Agent Sandbox OpenAPI. It authenticates with an Alibaba Cloud AK or STS credential, not an FC Agent Sandbox API key. For request parameters, authorization information, and per-language SDK examples, see the CreateTeam API.

Get the Team ID

Open the Team selector, click Manage Team, and view or copy the Team ID from the Team list.

The Team ID is the stable identifier of a Team. It is mainly used in the following scenarios:

  • Creating, querying, or deleting volumes through the FCSandbox POP API.

  • Configuring Team-level CPU and memory quotas.

  • Troubleshooting resource ownership for API keys, sandboxes, templates, or volumes.

For day-to-day sandbox creation with the E2B SDK, you only need to pass the API key bound to the Team. The Team ID is not required.

Next steps

  1. Create an Create an API Key for the Team.

  2. Use the API key to create a template or sandbox through the E2B SDK.

  3. If you need persistent storage, create a volume for the Team:

FAQ

What is the difference between ResourceGroupID and Team ID?

ResourceGroupID identifies an Alibaba Cloud resource group. It is used primarily for resource management and RAM authorization. Team ID identifies a specific FC Agent Sandbox workspace. One resource group can contain multiple Teams.

Can an API key access multiple Teams?

No. Each API key is bound to exactly one Team. To isolate different businesses or environments, create separate Teams and API keys.

How do I confirm that resources belong to the same Team?

Get the Team ID on the Team management page and check the Team ownership of the related API keys, templates, sandboxes, and volumes. Resources with different Team IDs cannot be used across Teams.

Who owns a Team created by a RAM user?

The Team belongs to the Alibaba Cloud account that the RAM user belongs to. Whether the RAM user can create, view, or operate Teams depends on their RAM permissions and resource group authorization.