Skip to content

Scenario Overview - Platform Governance and Access Control ​

This cross-scenario overview combines identity permissions, resource authorization, model visibility, projects and keys, member quotas, API rate control, and License into one governance path. Complete configuration in the linked scenarios.

Applicable Roles ​

  • Administrator and Operator
  • Provider and End User used to verify the result

Goals ​

  • Define who may access each function, resource, and model.
  • Limit calls through keys, projects, model grants, quotas, and rate limits.
  • Ensure new requests fail after access is revoked.

Scenario Flow ​

Main path: Identify governed objects → Configure roles, keys, and quota → Verify allowed and denied paths → Audit and adjust

StageKey Result
1. Identify objectsAccounts, tenants, projects, models, resources, and actions are explicit
2. Configure controlsRoles, menus, keys, quota, and approval rules enforce least privilege
3. Verify both pathsAuthorized accounts complete the task and unauthorized accounts are clearly blocked
4. Audit and adjustAccess, calls, and quota records are traceable and expired access can be revoked

Before You Start ​

  • Define the governed object, owner, tenant, and business scope.
  • List allowed actions, forbidden actions, limits, and rate controls.
  1. Configure identity and roles
  2. Configure resource and model scope
  3. Configure personal keys, rate limits, and credits
  4. Verify with the target account and record the result

Document Index ​

DocumentDescription
Governance WorkflowIdentity, resource, model, calling, credit controls, and a key-page screenshot
Identity AuthorizationTenants, members, roles, menus, and button permissions
Project, Key, and Budget GovernanceProject budgets, model allowlists, and calling credentials
Member Quota Request and AllocationQuota request, allocation, limits, and validation
API Rate-Control Release and AuditAPI rules, node versions, hits, and audit
License Lifecycle ManagementAuthorization state, validity, quota, and managed objects

Completion Checklist ​

Purpose: These are the scenario exit criteria. Use them to decide whether the outcome is observable and reviewable and whether you can continue to the next scenario. They do not repeat the procedure; if any item fails, return to the relevant feature guide and follow its troubleshooting section.

CheckPass Criteria
1Roles, keys, project scope, quota, or approval rules are saved and take effect in a new session.
2The authorized account completes the intended action without exceeding configured limits.
3An unauthorized account is hidden or explicitly denied, and related access or call records are auditable.