Team management

更新时间:
复制 MD 格式

Add and manage team members, assign and reclaim seats, and monitor Credits usage in the Token Plan console or management platform.

Access

Alibaba Cloud account or RAM users: Sign in to the Token Plan console and manage your team on the My Subscriptions page: click Settings in the Team Edition card to edit organization name, sign-in method (SSO/DingTalk), and more; click Assign Seats in the Subscription Details area to manage members.

Note

Before a RAM user can use Token Plan, the Alibaba Cloud account must complete the following:

  1. In the RAM console, attach the following system policies to the RAM user: either AliyunTokenPlanReadOnlyAccess (read-only) or AliyunTokenPlanFullAccess (full management) to use Token Plan (choose one based on the actual scope required); and AliyunBSSFullAccess (Billing Management access) to view the Token Plan subscriptions and usage of the Alibaba Cloud account on the My Subscriptions page. Without the Billing Management access, the My Subscriptions page appears empty after the RAM user signs in.

  2. On the Account Management page of the Model Studio console, assign the Administrator or Subscription plan role to the RAM user.

Members who joined via SSO or DingTalk: Sign in to the management platform through the Management Platform Address shared by the administrator. The address is available in the Basic Information section of the Settings page.

Roles and permissions

Role

Permissions

Owner

Add or remove members, assign or reclaim seats, change member roles, view usage for all members and models

Administrator

Same permissions as Owner. Assigned by the Owner and can be removed or demoted.

Member

Use the API Key and Base URL assigned by the administrator to call models

Member management

Add a member

  • Manual (cannot sign in to the management platform, API access only): On the Members page, click Add Member, enter a username (letters, digits, and underscores only) and role in the dialog box, and optionally assign a seat at the same time. Click Assign Seat in the member's operation column and select a seat tier. After assignment, the system automatically generates an API Key. Share it with the Base URL so the member can call models.

  • SSO or DingTalk sign-in (members can sign in to the management platform and manage their own seat and API Key): After SAML or DingTalk integration is configured, members sign in from the corresponding entry on the login page and join automatically.

Change a member's role

On the Members page, find the target member and click Change Role in the operation column. Select the new role (Administrator or Member) in the dialog box and save. The Owner role cannot be changed.

Reset API Key

On the Members page, find the target member and click Reset in the operation column. The original API Key is revoked immediately. Deliver the new API Key to the member.

Remove a member

On the Members page, find the target member and click Remove from Organization in the operation column. The seat is reclaimed and the API Key is revoked immediately.

SAML integration

Integrate a corporate IdP via standard SAML 2.0, corresponding to the SSO entry on the login page. Once configured, members sign in to the management platform with their IdP account and automatically join the organization.

SAML configuration

Prerequisite: SSO configuration cannot be edited when the organization has members. Remove all members first.

  1. Sign in to the Token Plan console. On the My Subscriptions page, click Settings in the Team Edition card and find the SSO Configuration section.

  2. Obtain the IdP information (IdP Entity ID, IdP SSO URL, IdP Certificate) from the enterprise IdP. Click Edit, enter your custom SP Entity ID and the IdP information above, and save.

  3. After saving, the system automatically generates the ACS URL. Enter the SP Entity ID and ACS URL into the enterprise IdP's SSO application configuration.

  4. In the Basic Information section, copy the Management Platform Address and share it with your team. Members open the address and select the SSO sign-in option on the login page to join the organization.

SP information (Model Studio side)

Parameter

Description

SP Entity ID

A unique identifier for Model Studio in the SSO flow. You define this value and must also enter it in the enterprise IdP's SSO application configuration.

ACS URL

The endpoint where the IdP sends authentication responses after successful authentication. Auto-generated by Model Studio after saving SSO configuration. Must be entered in the enterprise IdP.

SP Certificate

The SAML signing certificate on the Model Studio side. Auto-generated after saving SSO configuration. Used by the enterprise IdP to verify response signatures from Model Studio. Must be configured in the enterprise IdP's trust chain.

IdP information (enterprise side, obtained from the enterprise IdP)

Parameter

Description

IdP Entity ID

The unique identifier of the enterprise identity provider.

IdP SSO URL

The login entry URL of the enterprise IdP. Members are redirected here for authentication during sign-in.

IdP Certificate

The signing certificate of the enterprise IdP. Used by Model Studio to verify that responses actually come from the enterprise.

Configuration example: Alibaba Cloud IDaaS

Prerequisite: An Alibaba Cloud IDaaS EIAM instance is activated.

  1. Create a SAML application in IDaaS: Sign in to the IDaaS instance management platform, go to Application Management, click Add Application, select the Standard SAML 2.0 application template, enter an application name, and create the application.

  2. Obtain IdP information from IDaaS and enter it into Model Studio: In your IDaaS application, go to the Single Sign-On page and copy the IdP information from the Application Configuration section at the bottom. Enter it into the SSO Configuration section of the Token Plan console.

  3. Enter the SP Entity ID and ACS URL into IDaaS: After saving, the Model Studio SSO Configuration section displays the auto-generated ACS URL. In your IDaaS application, go to Login Access > Single Sign-On and enter the corresponding parameters.

  4. Create accounts and authorize in IDaaS: In IDaaS Account Management, create accounts for team members. In the SAML application, go to Login Access > Application Authorization and add authorization.

  5. Share the Management Platform Address with members: On the Settings page, copy the Management Platform Address from the Basic Information section. Members open the address and select SSO sign-in to join the organization.

DingTalk integration

Enterprises using DingTalk as their identity system can integrate directly, corresponding to the DingTalk entry on the login page. Once configured, members sign in to the management platform with their DingTalk account and automatically join the organization.

Prerequisite: A DingTalk enterprise has been created and the target members have been added to it.

  1. Create a DingTalk internal application: Sign in to the DingTalk Open Platform, go to Application Development > Internal Application > DingTalk Application, and click Create Application.

  2. Obtain application credentials: On the application details page, go to Basic Information > Credentials and Basic Information and record the Client ID and Client Secret.

  3. Configure the redirect domain: Go to Development Configuration > Security Settings and enter https://account-enterprise.bailian.aliyunportal.com/api/v1/auth/dingtalk/callback in Redirect URL (callback domain).

  4. Enable contact read permissions: On the Permission Management page, enable Contact personal information read permission.

  5. Publish the application: Go to Application Release > Version Management and Release, create a new version, and publish it.

  6. Enter the credentials in the Token Plan management platform: On the My Subscriptions page of the Token Plan console, click Settings in the Team Edition card. In the SSO Configuration section, switch to the DingTalk tab and enter the configuration name, DingTalk application AppKey, and AppSecret.

  7. Share the Management Platform Address with members: On the Settings page, copy the Management Platform Address from the Basic Information section. Members open the address and select DingTalk sign-in to join the organization.

Seat operations

View seat status

On the My Subscriptions page of the console, the Team Seats area shows the assigned count and total count per tier. The Subscription Details area shows each seat's status and expiration date.

Assign a seat

  1. On the Members page, find the target member and click Assign Seat in the operation column.

  2. In the dialog box, select a seat tier and click OK.

After assignment, the system automatically generates an API Key. Share it with the Base URL so the member can call models.

Reclaim a seat

On the Members page, find the target member and click Reclaim Seat in the operation column, then click OK in the confirmation dialog box. The seat returns to unassigned and the member loses access to the seat's Credits. Reassigning the seat generates a new API Key for the new member.

Add seats

On the My Subscriptions page of the Token Plan console, click Add Seats, select a seat tier and quantity, and submit the order. New seats share the existing subscription's expiration date. The price is prorated for the remaining time.

Upgrade a seat

On the My Subscriptions page of the Token Plan console, find the target seat in Subscription Details and click Upgrade. Select a higher tier and submit the order. To upgrade multiple seats at once, select them and click Batch Upgrade. The upgrade fee is the price difference prorated for the remaining time.

Usage analysis

Usage analysis is accessible from the My Subscriptions page of the Token Plan console or from the management platform. On the Usage Analysis page, an owner can view:

  • Usage trend: Credits consumption trend over the past 1, 7, or 30 days.

  • Model usage: Credits consumed per model within the organization.

  • Member usage: Credits consumed per member.