Overall access policies for Expenses and Costs

更新时间:
复制 MD 格式

Overall access policies for Expenses and Costs

The Alibaba Cloud Expenses and Costs Management Console is managed by logging on with an Alibaba Cloud account. Permission management is required for different accounts to access the console. In practice, there are two permission control scenarios:

  1. Cross-account management permissions: An enterprise with multiple accounts requires Account A to act as the administrator managing other member accounts, necessitating appropriate permission controls.

  2. Role-based permissions within a single account: When multiple roles share one account, permission controls must be tailored to each user’s responsibilities.

To address these two scenarios, Expenses and Costs provides the following permission policies:

  1. Enterprise account permission policy—for cross-account management scenarios.

  2. RAM permission policy—for multi-user scenarios within a single account.

Unlike individual e-commerce purchases, cloud resource procurement and consumption often involve multiple roles, such as O&M engineers, procurement staff, business development (BD), finance, and legal teams. As enterprises grow and their operations become more complex, multiple business units may migrate to the cloud simultaneously. The following recommendations outline optimal permission strategies for Expenses and Costs based on customer scale:

Small and medium-sized enterprises with a single cloud account

We recommend using the RAM permission policy for access control.

For simpler business structures, register a single Alibaba Cloud account to purchase and deploy cloud resources. For different team members, such as IT O&M, finance, procurement, and legal staff, create separate Resource Access Management (RAM) users and assign each role a corresponding RAM permission policy to meet role-specific access requirements.

Large enterprises with multiple cloud accounts

We recommend a combined strategy using the enterprise account permission policy + RAM permission policy.

You can enable the Enterprise Account Center feature. Then register or invite member accounts to build your enterprise’s organizational hierarchy. Apply both enterprise account permissions and RAM user permissions as follows:

image.png

For account setup, we recommend clear role separation to simplify management. Use the following account types:

  1. Management account:

  • Use the management account strictly for administrative tasks. Avoid using it for actual resource purchases or consumption.

  • Different management roles, such as procurement, finance, and O&M, should use separate accounts.

  • If your organization has multiple management levels, create management accounts at each level as needed.

  1. Tenant account:

  • Use tenant accounts for purchasing and managing cloud resources tied to specific business operations.

  • Create one account per smallest business management unit. This enables fine-grained isolation of assets, data, and control policies, and simplifies cost reconciliation and accounting later.

  • Tenant accounts require budget support for consumption. Administrators can configure settlement accounts based on management needs:

    • Dedicated scenario: Each business unit requires dedicated funding that does not affect others. Assign a separate settlement account to each business. In this model, funds are isolated. Overdue payments or service suspension in one account do not impact other business accounts.

    • Shared scenario: All business accounts share a unified settlement account when dedicated funding is unnecessary.

  1. RAM users:

    A single business typically involves multiple O&M personnel. When multiple users must share one account, create separate RAM users to enforce permission isolation and delegation.

Enterprise account permission policy

The enterprise account permission policy applies when an enterprise uses multiple Alibaba Cloud accounts and requires cross-account operations and management.

How to use the enterprise account permission policy?

To use this policy, first enable the Enterprise Account Center. Invite accounts to build your enterprise’s organizational tree. Then grant permissions based on each account’s defined role. For more information, see What is the Enterprise Account Center.

How to set account permissions under an enterprise account?

Grant enterprise account permissions by assigning roles to accounts. Accounts inherit all functional permissions associated with their assigned role. Follow these steps:

image
  • You can define which features a role can access. For more information, see Create a role.

  • Roles are either member roles or administrator roles:

    • Member accounts assigned a member role can use features tied to that role but can only operate on their own account.

    • Administrator accounts assigned an administrator role can use role-specific features and manage all member accounts under their organizational node and its child nodes.

List of Expenses and Costs enterprise account permission points:

Permission name

Permission code

Applicable role type

Description

Available credit warning setting

setavailablecreditwarning

Member, administrator

Set and modify available credit warning thresholds.

Automatic Write-off Settings Permission

setautopay

Member, administrator

Permissions to manage automatic write-off

Extended suspension setting

setextendedsuspensionservice

Member, administrator

Enable or disable extended suspension benefits.

Recharge permission

chargefund

Member, administrator

Recharge the account balance. With this permission, you can recharge via bank transfer, Alipay, or corporate online banking in the Expenses and Costs console or Alibaba Cloud app.

Withdrawal permission

withdrawfund

Member, administrator

Initiate withdrawals and view withdrawal records.

Fund record query permission

queryfund

Member, administrator

Query and export fund transaction records. Also includes enterprise asset queries.

Bill and statement query permission

querybill

Member, administrator

View monthly bills, query bill details, export bill details, and export selected product usage details.

Manual Write-off Permissions

payforbill

Member, administrator

Manual Write-off Permission

Cost allocation setting permission

setcostallocation

Member, administrator

Configure cost allocation. Includes querying, creating, editing, and deleting cost centers.

Cost management permission

costmanagement

Member, administrator

Manage cost analysis, self-service analytics, reports, cost optimization, and cost bill queries.

Budget management permission

budgetmanagement

Member, administrator

Manage budgets: create, edit, delete, copy, and subscribe to budget vs. actual analysis. Also includes querying budget lists, budget vs. actual analysis, and exporting reports.

Order query permission

queryorder

Member, administrator

Query orders and details, and export order details.

Order cancellation permission

cancelorder

Member and administrator types

Cancel unpaid orders in the Expenses and Costs order list.

Order operation permission

payorder

Member, administrator

Pay orders in the Expenses and Costs order list.

Query renewable items

queryrenew

Member, administrator

View the list of renewable items in Renewal Management.

Renewal configuration

configrenew

Member, administrator

Configure renewal settings (auto-renewal, no renewal, etc.) in Renewal Management.

Export renewal list

expotrenew

Member, administrator

Export the pending renewal list in Renewal Management.

Renewal operation management

writerenew

Member, administrator

Perform renewals in Renewal Management.

Refund request permission

queryrefund

Member, administrator

View refundable resources and fee details in Refund Management.

Unsubscription Management

writerefund

Member, administrator

Managing Resource Unsubscriptions

Voucher query permission

couponmanagement

Member, administrator

Coupon query permissions

Savings plan management permission

savingplanmanagement

Member, administrator

Manage savings plans.

Resource plan management permission

resourcemanagement

Member, administrator

Manage resource plans: query and operate.

Invoice query permission

queryinvoice

Member, administrator

Query invoice content.

Invoice information edit permission

invoiceinformationmanagement

Member, administrator

Edit master data such as invoice title and address.

Requesting invoicing permission

applyinvoice

Member, administrator

Apply for invoices, including monthly bill invoices.

Unified settlement permission

unifiedsettlement

Administrator type

Unified Settlement Permissions

Asset sharing setting permission

assetsharing

Administrator Type

Configure asset sharing.

Cost optimization management permission

optimizemanagement

Member, administrator

Access and use cost optimization features.

Cost bill management permission

gaapbillmanagement

Member, administrator

Access and use cost bill features.

Credit limit setting permission

setcredit

Administrator Type

Modify credit limits for managed accounts.

Fund transfer permission

fundtransfer

Administrator Type

Transfer and revoke funds between managed accounts.

Order price query permission

queryprice

Member, administrator

Query prices during order placement.

Modify billing account name

ModifyBillingAccount

Member, administrator

Modifying the Funding Account Name

Modify billing account settlement currency

ModifyCurrency

Member, administrator

Modify the billing account settlement currency.

Modify billing account payment methods

ModifyPaymentMethods

Member, administrator

Modify the payment methods bound to the billing account.

Modify the billing account linked to an account for payments

ModifyPaymentRelationship

Administrator type

Modify the billing account linked to an account for payments.

Modify billing account administrator

ModifyBillingAccountAdministrator

Administrator type

Modify the administrator of the funding account

Resource transfer permission

TransferResources

Member, administrator

Transfer cloud resources from one Alibaba Cloud account to another.

Contract management operation permission

operatecontract

Administrator, member

Contract management operation permissions, such as request, confirm, and void.

Contract download permission

downloadcontract

Administrator, member

Download contracts.

Contract detail query permission

querycontractdetail

Administrator, member

Contract Details Query Permission

Contract query permission

querycontract

Administrator, member

Permission to Query Contracts

Important

Some permissions apply only to the new Expenses and Costs console. They are not effective in the legacy (orange) Expenses and Costs console. Visit the new console to use them.

RAM permission policy

For an overview of RAM permission policies, see What is Resource Access Management.

To create RAM users and manage permissions, go to the RAM console.

To log on as a RAM user, go to RAM user logon.

RAM permission policies support two types: default policies and custom policies.

Default RAM permission policies for Expenses and Costs

Alibaba Cloud Expenses and Costs integrates with RAM to provide RAM-based permission control. The following default policies are available:

  • AliyunBSSReadOnlyAccess: read-only access to Expenses and Costs (BSS)

  • AliyunBSSOrderAccess: view and pay orders in Expenses and Costs (BSS)

  • AliyunBSSFullAccess: full access to Expenses and Costs (BSS)

  • AliyunBSSCartReadOnlyAccess: view shopping cart

  • AliyunBSSCartFullAccess: full shopping cart access (add/remove items, modify quantity and duration, create orders from cart)

Features and operations allowed by default policies

AliyunBSSFullAccess grants full permissions for Expenses and Costs.

AliyunBSSReadOnlyAccess and AliyunBSSOrderAccess cover the following menu items:

Menu

Submenu

AliyunBSSReadOnlyAccess

AliyunBSSOrderAccess

Account Overview

View page. No operations allowed.

Page not visible. No operations allowed.

Account Overview

Recharge

View page. No operations allowed.

Page not visible. No operations allowed.

Account Overview

Withdrawal

View page. Operations allowed.

Page not visible. No operations allowed.

Account Overview

Refund

View page. No operations allowed.

Page not visible. No operations allowed.

Account Overview

Apply for MYbank loan

View page. Operations allowed.

Page not visible. No operations allowed.

Account Overview

Apply for Alipay down payment tool

View page. Operations allowed.

Page not visible. No operations allowed.

Account Overview

View details

View page. No operations allowed.

Page not visible. No operations allowed.

Account Overview

Voucher management

View page. No operations allowed.

Page not visible. No operations allowed.

Account Overview

Resource plan management

View page. No operations allowed.

Page not visible. No operations allowed.

Account Overview

Request invoice

View page. No operations allowed.

Page not visible. No operations allowed.

Account Overview

Apply for contract

View page. No operations allowed.

Page not visible. No operations allowed.

Transaction Details

View page. No operations allowed.

Page not visible. No operations allowed.

Usage Records

Usage Overview

View page. Operations allowed.

Page not visible. No operations allowed.

Usage Records

Usage Details

View page. Operations allowed.

Page not visible. No operations allowed.

Usage Records

Usage Records

View page. Operations allowed.

Page not visible. No operations allowed.

Usage Records

Instance Usage Details

View page. Operations allowed.

Page not visible. No operations allowed.

Usage Records

Monthly Cost Consumption

View page. Operations allowed.

Page not visible. No operations allowed.

Usage Records

Export Records

View page. Operations allowed.

Page not visible. No operations allowed.

Usage Records

Store to OSS

View page. Operations allowed.

Page not visible. No operations allowed.

Bill Analysis

Product Bill Analysis

View page. Operations allowed.

Page not visible. No operations allowed.

Deposit Management

View page. No operations allowed.

Page not visible. No operations allowed.

Order Management

View page. No operations allowed.

View page. Operations allowed.

Voucher Management

View page. No operations allowed.

Page not visible. No operations allowed.

Coupon Management

Page not visible. No operations allowed.

Page not visible. No operations allowed.

Stored-value Card Management

Page not visible. No operations allowed.

Page not visible. No operations allowed.

Redemption Voucher Management

Page not visible. No operations allowed.

Page not visible. No operations allowed.

Purchase Order

Page not visible. No operations allowed.

Page not visible. No operations allowed.

Resource Plan Management

Resource Plan Overview

View page. No operations allowed.

Page not visible. No operations allowed.

Resource Plan Management

Usage Details

View page. No operations allowed.

Page not visible. No operations allowed.

Invoice Management

Request Invoice

View page. No operations allowed.

Page not visible. No operations allowed.

Invoice Management

Invoice List

View page. No operations allowed.

Page not visible. No operations allowed.

Invoice Management

Invoice Information Management

View page. No operations allowed.

Page not visible. No operations allowed.

Invoice Management

Invoice Shipping Address Management

View page. No operations allowed.

Page not visible. No operations allowed.

Remittance Slip Management

View page. No operations allowed.

Page not visible. No operations allowed.

Subscription Management

No-questions-asked refund within five days

View page. No operations allowed.

Page not visible. No operations allowed.

Subscription Management

Unsubscription Record

View page. No operations allowed.

Page not visible. No operations allowed.

Contract Management

Contract Application

View page. No operations allowed.

Page not visible. No operations allowed.

Contract Management

Contract Management

View page. No operations allowed.

Page not visible. No operations allowed.

Availability Center

Page not visible. No operations allowed.

Page not visible. No operations allowed.

Renewal Management

Page not visible. No operations allowed.

Page not visible. No operations allowed.

Purchase Page

Product Purchase Pages

View page. No operations allowed.

View page. No operations allowed.

Custom RAM permission policies for Expenses and Costs

Custom policy configuration:

You can create custom permission policies in the RAM console under Permission Policy Management:

Select Script Editor and add the required Expenses and Costs permission points in the Action field.

After configuring the custom policy, attach it to the relevant RAM users to enforce custom permissions.

Custom policy authorization:

In the RAM console under Permissions, add a new authorization. Select the target user, choose Custom Policy, and select your preconfigured custom policy to complete the authorization.

Custom permission points supported by Expenses and Costs:

Product module

Permission point

Permission Point Description

Permission type

Order

bss:DescribeOrderList

Query order list

Query

bss:DescribeOrderDetail

Query order details

Query

bss:PayOrder

Pay order

Operation

bss:CancelOrder

Cancel order

Operation

Renewal

bss:ModifyRenew*

Renew resources

Operation

bss:DescribeRenew*

Query renewable resources

Query

Unsubscribe from a Resource

bss:Refund

Unsubscribe from a resource

Operation

Funds

bss:DescribeAccount

Query account balance

Query

bss:ModifyBalance

Recharge account balance

Operation

bss:DescribeWithdraw

Query withdrawable amount and withdrawal records

Query

bss:ModifyWithdraw

Request withdrawal

Operation

bss:DescribeFund

Query fund transactions and vouchers

Query

bss:DescribeAsset

Query remittance records

Query

bss:ModifyRemittance

Claim remittance

Operation

bss:DescribeCredit

Query credit limit

Query

bss:DescribeAlarm

Query available credit warnings

Query

bss:ModifyAlarm

Set available credit warnings

Operation

bss:DescribeStoredCard

Query stored-value cards

Query

Bill

bss:DescribeBill

Query bills, amortized cost bills, and cost analysis

Query

bss:DescribeBillMonth

Query monthly bills

Query

bss:DescribeReport

Export bills

Query

bss:DescribeOss

Query bill subscriptions

Query

bss:ModifyOssSub

Manage bill subscriptions

Operation

Contract

bss:DescribeContractBasicInfo

Retrieve order list information and download contract files.

Get order list info, download contract files, view contract list, query contract cancellation reasons, check if multi-title invoice contract, check if user is restricted from creating contracts, get basic info, get contract count, view contract details, get party A entity info

Query

bss:ModifyContractCreate

Create order contracts, query order list, query bill list, create multi-title invoice contracts

Operation

bss:DescribeContractPartyA

Get user info: Captcha phone number and email, get multi-entity info

Query

bss:ModifyContractApplyPaper

Request paper contract

Operation

bss:ModifyContractBasicAction

Modify contract info

Operation

bss:ModifyContractStatus

Verify SMS Captcha for key accounts, finalize multi-title invoice contracts, cancel contracts, delete contracts

Operation

bss:QueryPrice

Hide discount info

Query

Cost management

bss:DescribeSubject

Query cost overview

Query

bss:DescribeDimension

Query cost analysis by dimension

Query

bss:DescribeMeta

Query source data for cost analysis dimensions

Query

bss:ModifyReport

Modify cost report templates

Operation

bss:ModifyBudget

Edit permissions for budget management

Operation

bss:DescribeBudget

Query budget management

Query

bss:DescribeAnomaly

Query anomaly detection results

Query

bss:ModifyAnomaly

Edit and resolve anomaly detection issues

Operation

bss:DescribeOptimize

Query cost optimization suggestions

Query

bss:ModifyOptimize

Edit and implement cost optimization suggestions

Operation

bss:DescribeCostUnit

Query permission for cost centers

Query

bss:ModifyCostUnit

Cost center editing permission

Operation

Resource plan

bss:DescribeFrInstances

Query resource plan instances

Query

bss:DescribeDistinctProductFromInstance

bss:DescribeDistinctCommodityFromInstance

bss:DescribeDistinctSpecFromInstance

bss:DescribeDistinctTemplateFromInstance

bss:DescribeDeductLogs

Query resource plan deduction logs

Query

bss:DescribeDistinctCommodityFromDeductLog

bss:DescribeDistinctBillingCommodityFromDeductLog

bss:DescribeDistinctRelationAccountIdFromDeductLog

bss:DescribeHourOrDayStat

Query statistical analysis of resource plan usage

Query

bss:DescribeMonthStat

bss:DescribeAnalysis

Query resource plan utilization and coverage analysis

Query

bss:ModifyWarnConfig

Modify resource plan balance alert rules

Operation

bss:DescribeWarnConfig

Query resource plan balance alert settings

Query

Alibaba Cloud Billing OpenAPI authorization

Alibaba Cloud Billing OpenAPI supports authorization for RAM users. After attaching the AliyunBSSFullAccess policy to a RAM user, the user can access all Billing OpenAPI operations. For more information, see Alibaba Cloud Billing OpenAPI documentation.