User Roles and Permissions


The Enterprise Analytics Platform uses the EnOS Identity and Authorization Service (IAM) to control the user roles and permissions. EAP administrators can manage the products and resources accessible for users or user groups by assigning corresponding access policies to them.


For more information about using identity and authorization service for user and permission management, see Managing Users and Permissions.

User Roles in EAP

The main user roles of the Enterprise Analytics Platform services include:


EAP Administrator

Managers in the organization, who can configure model fields, function parameters, and resource configurations. EAP administrator can manage the basic attributes and information of users on the EnOS Management Console, and assign the roles of project managers, developers, and common personnel for users.


EAP Developer

The developers in the organization can perform operations such as creating data sources, creating data formats, creating algorithm development, and designing scenarios.


EAP Project Staff

The users in external organizations and the project staff can perform model registration, set production parameter, start or end model production, and manage online production.


EAP Customer

Common users can view and experience EAP products, and can be the users inside the organization or the users of external organizations. Common users can experience operations that have no impact on production safety.

Permission Policies

The EnOS Identity and Authorization service predefines the following permission policies for user roles of the Enterprise Analytics Platform service.

Predefined policies Accessible resources and permissions
EAP Administrator
  • Public model hub (Read, Write, Delete)
  • Private model hub (Read, Write, Delete)
  • Model deployment (Read, Write, Delete)
  • Model version (Read, Write, Delete)
  • Model production monitoring (Read, Write, Delete)
  • Administrator model hub (Read, Write, Delete)
EAP Developer
  • Public model hub (Read, Write)
  • Private model hub (Read, Write, Delete)
  • Model deployment (Read, Write, Delete)
  • Model version (Read, Write, Delete)
  • Model production monitoring (Read, Write, Delete)
EAP Project Staff
  • Public model hub (Read, Write)
  • Private model hub (Read, Write, Delete)
  • Model deployment (Read, Write, Delete)
  • Model version (Read, Write)
  • Model production monitoring (Read, Write, Delete)
EAP Customer
  • Public model hub (Read)
  • Private model hub (Read)
  • Model deployment (Read)
  • Model version (Read)
  • Model production monitoring (Read)