Help Center/ Cloud Operations Center/ User Guide/ COC Enablement/ Enabling COC Cross-Account Management
Updated on 2026-06-23 GMT+08:00

Enabling COC Cross-Account Management

COC provides secure and reliable cross-account data aggregation and resource O&M capabilities. If your account is an organization account, you can centrally manage resources of all your member accounts, perform automated O&M, and access the O&M BI dashboards. You do not need to log in as the member accounts one by one.

Prerequisites

  • You have created an organization by referring to Creating an Organization.
    • Only the enterprise master account in the enterprise center can create organizations.
    • After an organization is created in the enterprise center, you need to be re-authorized on the Organizations console to access all its functions.
    • After the Organizations service is enabled, your organization and the root are automatically created, and your login account is defined as the management account.
      • An organization administrator needs to create an organization. Each account can have only one organization.
      • Member accounts can only view the control panel.
      • The member account must also be an enterprise-level account.
    Figure 1 Enabling an organization service
  • COC has been authorized as a trusted service. For details, see Enabling or Disabling a Trusted Service.
    Figure 2 Enabling a trusted service
  • You have logged in as an administrator or a delegated administrator. For details, see Specifying, Viewing, or Removing a Delegated Administrator.
    Figure 3 Adding a delegated administrator

Constraints

After inviting member accounts to join the organization, the administrator or service delegated administrator can view and manage the data and resources of member accounts in the organization on COC. Currently, the following functions are supported: resource management, job management, patch management, and O&M BI dashboard.

Enabling Cross-Account Management

After the cross-account management function is enabled, the organization or delegated administrator can perform unified resource management, use the automated O&M feature, and access O&M BI dashboards for all member accounts in the organization on COC without logging in to the member accounts one by one. This section describes how to enable the cross-account management function.

Suppose that account A needs to manage account B. To use COC for cross-account O&M and management on account B, perform the following operations:
  1. If account A is an organization administrator, skip this step. If account A is not an organization administrator, the organization administrator should add account A as a delegated administrator. For details, see Specifying, Viewing, or Removing a Delegated Administrator.

    The administrator can delegate the administrator rights to a member and revoke them. The right change takes effect after you refresh the page 1 to 2 minutes later.

  2. The organization administrator or delegated administrator invites account B to join the organization. For details, see Inviting an Account to Join Your Organization.
  3. After account B is added to the organization, log in to the COC console as account A and perform cross-account O&M and management on the O&M BI dashboard, resource management, and job management pages.

    For details about organizations, see the Overview of Organizations.

    To access the data asset information of account B, COC automatically creates a service agency in account B.

    • The agency is a cloud service agency. Its permission is COCAssumeServiceLinkedAgencyPolicy, and name is ServiceLinkedAgencyForCOC.
    • If account B is deleted, COC automatically deletes the COC agency in account B.

Helpful Links

After cross-account management is enabled, the organization administrator can enable COC for member accounts in batches.