Overall access policies for Expenses and Costs
Overall access policies for Expenses and Costs
The Alibaba Cloud Expenses and Costs Management Console is managed by logging on with an Alibaba Cloud account. Permission management is required for different accounts to access the console. In practice, there are two permission control scenarios:
-
Cross-account management permissions: An enterprise with multiple accounts requires Account A to act as the administrator managing other member accounts, necessitating appropriate permission controls.
-
Role-based permissions within a single account: When multiple roles share one account, permission controls must be tailored to each user’s responsibilities.
To address these two scenarios, Expenses and Costs provides the following permission policies:
-
Enterprise account permission policy—for cross-account management scenarios.
-
RAM permission policy—for multi-user scenarios within a single account.
Unlike individual e-commerce purchases, cloud resource procurement and consumption often involve multiple roles, such as O&M engineers, procurement staff, business development (BD), finance, and legal teams. As enterprises grow and their operations become more complex, multiple business units may migrate to the cloud simultaneously. The following recommendations outline optimal permission strategies for Expenses and Costs based on customer scale:
Small and medium-sized enterprises with a single cloud account
We recommend using the RAM permission policy for access control.
For simpler business structures, register a single Alibaba Cloud account to purchase and deploy cloud resources. For different team members, such as IT O&M, finance, procurement, and legal staff, create separate Resource Access Management (RAM) users and assign each role a corresponding RAM permission policy to meet role-specific access requirements.
Large enterprises with multiple cloud accounts
We recommend a combined strategy using the enterprise account permission policy + RAM permission policy.
You can enable the Enterprise Account Center feature. Then register or invite member accounts to build your enterprise’s organizational hierarchy. Apply both enterprise account permissions and RAM user permissions as follows:

For account setup, we recommend clear role separation to simplify management. Use the following account types:
-
Management account:
-
Use the management account strictly for administrative tasks. Avoid using it for actual resource purchases or consumption.
-
Different management roles, such as procurement, finance, and O&M, should use separate accounts.
-
If your organization has multiple management levels, create management accounts at each level as needed.
-
Tenant account:
-
Use tenant accounts for purchasing and managing cloud resources tied to specific business operations.
-
Create one account per smallest business management unit. This enables fine-grained isolation of assets, data, and control policies, and simplifies cost reconciliation and accounting later.
-
Tenant accounts require budget support for consumption. Administrators can configure settlement accounts based on management needs:
-
Dedicated scenario: Each business unit requires dedicated funding that does not affect others. Assign a separate settlement account to each business. In this model, funds are isolated. Overdue payments or service suspension in one account do not impact other business accounts.
-
Shared scenario: All business accounts share a unified settlement account when dedicated funding is unnecessary.
-
-
RAM users:
A single business typically involves multiple O&M personnel. When multiple users must share one account, create separate RAM users to enforce permission isolation and delegation.
Enterprise account permission policy
The enterprise account permission policy applies when an enterprise uses multiple Alibaba Cloud accounts and requires cross-account operations and management.
How to use the enterprise account permission policy?
To use this policy, first enable the Enterprise Account Center. Invite accounts to build your enterprise’s organizational tree. Then grant permissions based on each account’s defined role. For more information, see What is the Enterprise Account Center.
How to set account permissions under an enterprise account?
Grant enterprise account permissions by assigning roles to accounts. Accounts inherit all functional permissions associated with their assigned role. Follow these steps:
-
You can define which features a role can access. For more information, see Create a role.
-
Roles are either member roles or administrator roles:
-
Member accounts assigned a member role can use features tied to that role but can only operate on their own account.
-
Administrator accounts assigned an administrator role can use role-specific features and manage all member accounts under their organizational node and its child nodes.
-
List of Expenses and Costs enterprise account permission points:
| Permission name |
Permission code |
Applicable role type |
Description |
| Available credit warning setting |
setavailablecreditwarning |
Member, administrator |
Set and modify available credit warning thresholds. |
| Automatic Write-off Settings Permission |
setautopay |
Member, administrator |
Permissions to manage automatic write-off |
| Extended suspension setting |
setextendedsuspensionservice |
Member, administrator |
Enable or disable extended suspension benefits. |
| Recharge permission |
chargefund |
Member, administrator |
Recharge the account balance. With this permission, you can recharge via bank transfer, Alipay, or corporate online banking in the Expenses and Costs console or Alibaba Cloud app. |
| Withdrawal permission |
withdrawfund |
Member, administrator |
Initiate withdrawals and view withdrawal records. |
| Fund record query permission |
queryfund |
Member, administrator |
Query and export fund transaction records. Also includes enterprise asset queries. |
| Bill and statement query permission |
querybill |
Member, administrator |
View monthly bills, query bill details, export bill details, and export selected product usage details. |
| Manual Write-off Permissions |
payforbill |
Member, administrator |
Manual Write-off Permission |
| Cost allocation setting permission |
setcostallocation |
Member, administrator |
Configure cost allocation. Includes querying, creating, editing, and deleting cost centers. |
| Cost management permission |
costmanagement |
Member, administrator |
Manage cost analysis, self-service analytics, reports, cost optimization, and cost bill queries. |
| Budget management permission |
budgetmanagement |
Member, administrator |
Manage budgets: create, edit, delete, copy, and subscribe to budget vs. actual analysis. Also includes querying budget lists, budget vs. actual analysis, and exporting reports. |
| Order query permission |
queryorder |
Member, administrator |
Query orders and details, and export order details. |
| Order cancellation permission |
cancelorder |
Member and administrator types |
Cancel unpaid orders in the Expenses and Costs order list. |
| Order operation permission |
payorder |
Member, administrator |
Pay orders in the Expenses and Costs order list. |
| Query renewable items |
queryrenew |
Member, administrator |
View the list of renewable items in Renewal Management. |
| Renewal configuration |
configrenew |
Member, administrator |
Configure renewal settings (auto-renewal, no renewal, etc.) in Renewal Management. |
| Export renewal list |
expotrenew |
Member, administrator |
Export the pending renewal list in Renewal Management. |
| Renewal operation management |
writerenew |
Member, administrator |
Perform renewals in Renewal Management. |
| Refund request permission |
queryrefund |
Member, administrator |
View refundable resources and fee details in Refund Management. |
| Unsubscription Management |
writerefund |
Member, administrator |
Managing Resource Unsubscriptions |
| Voucher query permission |
couponmanagement |
Member, administrator |
Coupon query permissions |
| Savings plan management permission |
savingplanmanagement |
Member, administrator |
Manage savings plans. |
| Resource plan management permission |
resourcemanagement |
Member, administrator |
Manage resource plans: query and operate. |
| Invoice query permission |
queryinvoice |
Member, administrator |
Query invoice content. |
| Invoice information edit permission |
invoiceinformationmanagement |
Member, administrator |
Edit master data such as invoice title and address. |
| Requesting invoicing permission |
applyinvoice |
Member, administrator |
Apply for invoices, including monthly bill invoices. |
| Unified settlement permission |
unifiedsettlement |
Administrator type |
Unified Settlement Permissions |
| Asset sharing setting permission |
assetsharing |
Administrator Type |
Configure asset sharing. |
| Cost optimization management permission |
optimizemanagement |
Member, administrator |
Access and use cost optimization features. |
| Cost bill management permission |
gaapbillmanagement |
Member, administrator |
Access and use cost bill features. |
| Credit limit setting permission |
setcredit |
Administrator Type |
Modify credit limits for managed accounts. |
| Fund transfer permission |
fundtransfer |
Administrator Type |
Transfer and revoke funds between managed accounts. |
| Order price query permission |
queryprice |
Member, administrator |
Query prices during order placement. |
| Modify billing account name |
ModifyBillingAccount |
Member, administrator |
Modifying the Funding Account Name |
| Modify billing account settlement currency |
ModifyCurrency |
Member, administrator |
Modify the billing account settlement currency. |
| Modify billing account payment methods |
ModifyPaymentMethods |
Member, administrator |
Modify the payment methods bound to the billing account. |
| Modify the billing account linked to an account for payments |
ModifyPaymentRelationship |
Administrator type |
Modify the billing account linked to an account for payments. |
| Modify billing account administrator |
ModifyBillingAccountAdministrator |
Administrator type |
Modify the administrator of the funding account |
| Resource transfer permission |
TransferResources |
Member, administrator |
Transfer cloud resources from one Alibaba Cloud account to another. |
| Contract management operation permission |
operatecontract |
Administrator, member |
Contract management operation permissions, such as request, confirm, and void. |
| Contract download permission |
downloadcontract |
Administrator, member |
Download contracts. |
| Contract detail query permission |
querycontractdetail |
Administrator, member |
Contract Details Query Permission |
| Contract query permission |
querycontract |
Administrator, member |
Permission to Query Contracts |
Some permissions apply only to the new Expenses and Costs console. They are not effective in the legacy (orange) Expenses and Costs console. Visit the new console to use them.
RAM permission policy
For an overview of RAM permission policies, see What is Resource Access Management.
To create RAM users and manage permissions, go to the RAM console.
To log on as a RAM user, go to RAM user logon.
RAM permission policies support two types: default policies and custom policies.
Default RAM permission policies for Expenses and Costs
Alibaba Cloud Expenses and Costs integrates with RAM to provide RAM-based permission control. The following default policies are available:
-
AliyunBSSReadOnlyAccess: read-only access to Expenses and Costs (BSS)
-
AliyunBSSOrderAccess: view and pay orders in Expenses and Costs (BSS)
-
AliyunBSSFullAccess: full access to Expenses and Costs (BSS)
-
AliyunBSSCartReadOnlyAccess: view shopping cart
-
AliyunBSSCartFullAccess: full shopping cart access (add/remove items, modify quantity and duration, create orders from cart)
Features and operations allowed by default policies
AliyunBSSFullAccess grants full permissions for Expenses and Costs.
AliyunBSSReadOnlyAccess and AliyunBSSOrderAccess cover the following menu items:
| Menu |
Submenu |
AliyunBSSReadOnlyAccess |
AliyunBSSOrderAccess |
| Account Overview |
View page. No operations allowed. |
Page not visible. No operations allowed. |
|
| Account Overview |
Recharge |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Account Overview |
Withdrawal |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Account Overview |
Refund |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Account Overview |
Apply for MYbank loan |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Account Overview |
Apply for Alipay down payment tool |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Account Overview |
View details |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Account Overview |
Voucher management |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Account Overview |
Resource plan management |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Account Overview |
Request invoice |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Account Overview |
Apply for contract |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Transaction Details |
View page. No operations allowed. |
Page not visible. No operations allowed. |
|
| Usage Records |
Usage Overview |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Usage Records |
Usage Details |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Usage Records |
Usage Records |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Usage Records |
Instance Usage Details |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Usage Records |
Monthly Cost Consumption |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Usage Records |
Export Records |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Usage Records |
Store to OSS |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Bill Analysis |
Product Bill Analysis |
View page. Operations allowed. |
Page not visible. No operations allowed. |
| Deposit Management |
View page. No operations allowed. |
Page not visible. No operations allowed. |
|
| Order Management |
View page. No operations allowed. |
View page. Operations allowed. |
|
| Voucher Management |
View page. No operations allowed. |
Page not visible. No operations allowed. |
|
| Coupon Management |
Page not visible. No operations allowed. |
Page not visible. No operations allowed. |
|
| Stored-value Card Management |
Page not visible. No operations allowed. |
Page not visible. No operations allowed. |
|
| Redemption Voucher Management |
Page not visible. No operations allowed. |
Page not visible. No operations allowed. |
|
| Purchase Order |
Page not visible. No operations allowed. |
Page not visible. No operations allowed. |
|
| Resource Plan Management |
Resource Plan Overview |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Resource Plan Management |
Usage Details |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Invoice Management |
Request Invoice |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Invoice Management |
Invoice List |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Invoice Management |
Invoice Information Management |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Invoice Management |
Invoice Shipping Address Management |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Remittance Slip Management |
View page. No operations allowed. |
Page not visible. No operations allowed. |
|
| Subscription Management |
No-questions-asked refund within five days |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Subscription Management |
Unsubscription Record |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Contract Management |
Contract Application |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Contract Management |
Contract Management |
View page. No operations allowed. |
Page not visible. No operations allowed. |
| Availability Center |
Page not visible. No operations allowed. |
Page not visible. No operations allowed. |
|
| Renewal Management |
Page not visible. No operations allowed. |
Page not visible. No operations allowed. |
|
| Purchase Page |
Product Purchase Pages |
View page. No operations allowed. |
View page. No operations allowed. |
Custom RAM permission policies for Expenses and Costs
Custom policy configuration:
You can create custom permission policies in the RAM console under Permission Policy Management:
Select Script Editor and add the required Expenses and Costs permission points in the Action field.
After configuring the custom policy, attach it to the relevant RAM users to enforce custom permissions.
Custom policy authorization:
In the RAM console under Permissions, add a new authorization. Select the target user, choose Custom Policy, and select your preconfigured custom policy to complete the authorization.
Custom permission points supported by Expenses and Costs:
| Product module |
Permission point |
Permission Point Description |
Permission type |
| Order |
bss:DescribeOrderList |
Query order list |
Query |
| bss:DescribeOrderDetail |
Query order details |
Query |
|
| bss:PayOrder |
Pay order |
Operation |
|
| bss:CancelOrder |
Cancel order |
Operation |
|
| Renewal |
bss:ModifyRenew* |
Renew resources |
Operation |
| bss:DescribeRenew* |
Query renewable resources |
Query |
|
| Unsubscribe from a Resource |
bss:Refund |
Unsubscribe from a resource |
Operation |
| Funds |
bss:DescribeAccount |
Query account balance |
Query |
| bss:ModifyBalance |
Recharge account balance |
Operation |
|
| bss:DescribeWithdraw |
Query withdrawable amount and withdrawal records |
Query |
|
| bss:ModifyWithdraw |
Request withdrawal |
Operation |
|
| bss:DescribeFund |
Query fund transactions and vouchers |
Query |
|
| bss:DescribeAsset |
Query remittance records |
Query |
|
| bss:ModifyRemittance |
Claim remittance |
Operation |
|
| bss:DescribeCredit |
Query credit limit |
Query |
|
| bss:DescribeAlarm |
Query available credit warnings |
Query |
|
| bss:ModifyAlarm |
Set available credit warnings |
Operation |
|
| bss:DescribeStoredCard |
Query stored-value cards |
Query |
|
| Bill |
bss:DescribeBill |
Query bills, amortized cost bills, and cost analysis |
Query |
| bss:DescribeBillMonth |
Query monthly bills |
Query |
|
| bss:DescribeReport |
Export bills |
Query |
|
| bss:DescribeOss |
Query bill subscriptions |
Query |
|
| bss:ModifyOssSub |
Manage bill subscriptions |
Operation |
|
| Contract |
bss:DescribeContractBasicInfo |
Retrieve order list information and download contract files. Get order list info, download contract files, view contract list, query contract cancellation reasons, check if multi-title invoice contract, check if user is restricted from creating contracts, get basic info, get contract count, view contract details, get party A entity info |
Query |
| bss:ModifyContractCreate |
Create order contracts, query order list, query bill list, create multi-title invoice contracts |
Operation |
|
| bss:DescribeContractPartyA |
Get user info: Captcha phone number and email, get multi-entity info |
Query |
|
| bss:ModifyContractApplyPaper |
Request paper contract |
Operation |
|
| bss:ModifyContractBasicAction |
Modify contract info |
Operation |
|
| bss:ModifyContractStatus |
Verify SMS Captcha for key accounts, finalize multi-title invoice contracts, cancel contracts, delete contracts |
Operation |
|
| bss:QueryPrice |
Hide discount info |
Query |
|
| Cost management |
bss:DescribeSubject |
Query cost overview |
Query |
| bss:DescribeDimension |
Query cost analysis by dimension |
Query |
|
| bss:DescribeMeta |
Query source data for cost analysis dimensions |
Query |
|
| bss:ModifyReport |
Modify cost report templates |
Operation |
|
| bss:ModifyBudget |
Edit permissions for budget management |
Operation |
|
| bss:DescribeBudget |
Query budget management |
Query |
|
| bss:DescribeAnomaly |
Query anomaly detection results |
Query |
|
| bss:ModifyAnomaly |
Edit and resolve anomaly detection issues |
Operation |
|
| bss:DescribeOptimize |
Query cost optimization suggestions |
Query |
|
| bss:ModifyOptimize |
Edit and implement cost optimization suggestions |
Operation |
|
| bss:DescribeCostUnit |
Query permission for cost centers |
Query |
|
| bss:ModifyCostUnit |
Cost center editing permission |
Operation |
|
| Resource plan |
bss:DescribeFrInstances |
Query resource plan instances |
Query |
| bss:DescribeDistinctProductFromInstance |
|||
| bss:DescribeDistinctCommodityFromInstance |
|||
| bss:DescribeDistinctSpecFromInstance |
|||
| bss:DescribeDistinctTemplateFromInstance |
|||
| bss:DescribeDeductLogs |
Query resource plan deduction logs |
Query |
|
| bss:DescribeDistinctCommodityFromDeductLog |
|||
| bss:DescribeDistinctBillingCommodityFromDeductLog |
|||
| bss:DescribeDistinctRelationAccountIdFromDeductLog |
|||
| bss:DescribeHourOrDayStat |
Query statistical analysis of resource plan usage |
Query |
|
| bss:DescribeMonthStat |
|||
| bss:DescribeAnalysis |
Query resource plan utilization and coverage analysis |
Query |
|
| bss:ModifyWarnConfig |
Modify resource plan balance alert rules |
Operation |
|
| bss:DescribeWarnConfig |
Query resource plan balance alert settings |
Query |
Alibaba Cloud Billing OpenAPI authorization
Alibaba Cloud Billing OpenAPI supports authorization for RAM users. After attaching the AliyunBSSFullAccess policy to a RAM user, the user can access all Billing OpenAPI operations. For more information, see Alibaba Cloud Billing OpenAPI documentation.