Skip to content

Role Comparison ​

Document Information

Version: v1.0 Updated: 2026-07-15

Role Summary ​

RolePositioningResponsible ForNot Responsible For
operatorPlatform operatorResource preparation, governance configuration, quotas, monitoring, reviews, customer finance, License, settings, audit, and API rate controlPublishing a provider-owned model or consuming models as an end user
providerModel providerPublishing and maintaining models, aggregate models, reviews, customer calls, provider revenue, and permitted team settingsPlatform-wide identity governance, finance operations, or reviewing its own publication
enduserEnd User and model consumerDeploying available services, discovering and experiencing models, API calls, personal usage, personal billing, personal settings, and authorized team members, projects, quotas, and Key usagePublishing or reviewing models and managing platform-wide resources

Capability Comparison ​

Capabilityoperatorproviderenduser
Manage tenants, members, and role assignmentsPrimary or handled through an authorized governance processNoNo
Prepare On-Prem resource pools and templatesPrimaryUse authorized resourcesUse authorized resources
Connect and authorize supported cloud resourcesPrimaryUse assigned access accounts or resourcesUse assigned access accounts or resources
Maintain Model Services base settingsPrimaryUse prepared settingsNo
Maintain Billing and License operationsPrimary for platform/customer financeView owned revenue and settlementsView own billing
Maintain Settings, audit, and API rate controlPrimary for platform settingsOwn team or personal scope when authorizedOwn personal or team scope when authorized
Publish a single or BYOK modelGovern and reviewPrimaryNo
Create an aggregate modelGovern and reviewPrimaryNo
Review models and appsPrimarySubmit for reviewNo
Discover models and use PlaygroundValidation when neededValidation when neededPrimary
Call model APIsValidation when neededValidate owned servicesPrimary
View customer calls and model revenuePlatform scope when authorizedPrimary for owned modelsNo
View personal calls, usage, and billingOperational scope when authorizedOwn scopeOwn scope
Manage user-side team membersPlatform policy or audit scopeAuthorized tenant or project scopeAuthorized tenant or project scope
View or adjust member quotasPlatform policy or audit scopeAuthorized tenant or project scopeAuthorized tenant or project scope
Submit or handle quota requestsPlatform policy or approval scopeAuthorized tenant or project scopeOwn or authorized team scope
Manage projects and Project Key usage scopePlatform policy or audit scopeAuthorized project scopeAuthorized project scope

"Primary" indicates normal task ownership. Actual visibility depends on tenant, role configuration, resource authorization, and the installed version.

User-Side Collaboration and Resource Scope ​

Team members and projects are not added as separate platform roles. They are collaboration objects and resource boundaries inside a tenant or project, usually maintained by an authorized enduser or provider account within its own tenant, team, or project scope.

ObjectPositioningMain ImpactTypical Handling Role
Team memberThe collaboration identity created when an account joins a tenant, team, or projectLogin status, collaboration relationship, role assignment, member quota, quota requests, and audit recordsAuthorized enduser or provider
ProjectBusiness workspace for model calls, budget, and collaborationProject members, Project Keys, project budget, model allowlist, usage, and activity recordsAuthorized enduser or provider
Member quotaManagement object that controls member quota and limitsPersonal Key quota, call-failure diagnosis, quota adjustment, and quota requestsAuthorized enduser or provider
Project KeyAccess credential for calling models within a project scopeCalling identity, project budget, model availability, and Key limitsAuthorized enduser or provider

When users see "Team Members," "Projects," "Member Quotas," or "Project Keys," first confirm whether the account is authorized in the corresponding tenant or project instead of directly expanding operator permissions. For the full object relationship, see Tenant, Member, Project, and Role Design Logic.

operator: Platform Operator ​

Typical users: platform operations, infrastructure, model governance, or delivery team.

Main responsibilities by subsystem:

SubsystemResponsibilitiesManual Entry
AI Infra On-PremPrepare resource topology, specifications, storage, images, templates, quotas, metering, and monitoringRegions & Zones
AI Infra On-CloudMaintain supported cloud access, accounts, resource pools, authorization, deployment assets, and scheduling policiesAccess Overview
Model ServicesMaintain meta-models, model sources, templates, tags, and currency settings; process model and app reviewsMeta Models
BillingMaintain customer finance, operation finance, reconciliation, settlement, adjustment, and License statusToday Tasks
SettingsMaintain members, roles, tenants, operation logs, platform settings, login properties, and API rate-control rulesMembers

Boundary:

  • The operator prepares supply and governance conditions but does not replace the provider that owns a model publication.
  • Huawei Cloud access is temporarily unsupported and must not be used as an operator onboarding scenario.

provider: Model Provider ​

Typical users: model team, AI developer, model service provider, or technical team responsible for publishing.

Main responsibilities:

  • Publish and maintain single models or BYOK endpoints.
  • Create aggregate models from eligible member models and select an available routing strategy.
  • Configure provider-owned publication information, submit reviews, and respond to review results.
  • View model usage, model revenue, and customer-call data for the permitted scope.
  • View provider-side earnings, customer lists, and settlement records within the permitted scope.
  • Manage personal Keys, profile, team members, roles, quotas, or tenant settings only when those entries are authorized to the provider account.
  • Use authorized On-Prem or On-Cloud resources when a deployment workflow requires them.

Boundary:

  • A provider cannot approve its own model or app publication.
  • A provider does not manage platform-wide tenants, menus, resource policies, or another provider's data.

See the Publish Model scenario.

enduser: End User and Model Consumer ​

Typical users: business user, application developer, API consumer, or a user deploying from prepared resources.

Main responsibilities:

  • Browse visible models and inspect model details.
  • Experience supported model interactions in Playground.
  • Obtain required access and call model APIs.
  • View personal-call overview, analytics, logs, usage, and deployment status.
  • View personal billing, transactions, top-up orders, monthly bills, and personal settings when available.
  • Manage user-side team members, projects, member quotas, quota requests, and Project Key usage scope within the authorized scope.
  • Create On-Prem or On-Cloud workloads from resources and templates already authorized to the account.

Boundary:

  • An end user does not publish single or aggregate models. Aggregate-model creation belongs to the model provider.
  • An end user does not process reviews or maintain platform-wide resource and identity configuration.
  • User-side team member and project permissions apply only within the corresponding tenant or project scope. They do not replace platform-level member, menu, system setting, or operations approval permissions.

See the User Manual and Scenario Guide.

Which Role Should Perform the Task? ​

TaskRecommended Role
Create a tenant or assign a roleoperator or authorized governance process
Onboard a local cluster or configure quotasoperator
Connect and authorize a supported cloud resource pooloperator
Maintain meta-models or review a modeloperator
Reconcile a billing cycle or maintain customer financeoperator
Maintain members, roles, login settings, or API rate-control rulesoperator
Publish a model or create an aggregate modelprovider
View customer calls and provider revenueprovider
Try a model or call its APIenduser
View personal usage, billing, or a personal deploymentenduser
Manage user-side team membersAuthorized enduser or provider
View or adjust member quotasAuthorized enduser or provider
Submit or handle quota requestsAuthorized enduser or provider; platform policy is maintained by operator
Manage project members and Project KeysAuthorized enduser or provider

If one person performs multiple responsibilities in a small deployment, assign multiple roles only after confirming the required boundary. Keep platform governance and review permissions limited and auditable.