The following standards are formulated based on tenants. If an individual tenant needs to use beyond the limit, please submit a request for PMO approval.
Three service tiers are available: Band 1, Band 2, and Band 3. Tenants can select the appropriate tier based on their business scale and requirements.
Band Definitions
| Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Target users | Small teams / Trial | Mid-sized business | Large enterprise |
| Typical scale | < 50 users | 50 - 500 users | > 500 users |
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of account config | 10 | 50 | 200 |
| Number of templates | 100 | 500 | 2,000 |
| Email body size | 5M (including body and attachments) | 25M (including body and attachments) | 100M (including body and attachments) |
Send Quota
NON PROD:
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Daily send limit (recipients/day, UTC) | 1,000 | 5,000 | 20,000 |
PROD:
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Daily send limit (recipients/day, UTC) | 10,000 | 50,000 | 200,000 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| API request rate (concurrent) | 50 req/sec | 50 req/sec | 50 req/sec |
Note: Email send quotas and performance depend on the underlying email service provider. Actual throughput and deliverability may vary across different vendors.
- Usage rules:
- You shall not use the email service to send spam, phishing emails, or any unsolicited commercial messages.
- All email content must comply with applicable laws and regulations, including but not limited to data protection and anti-spam laws.
- You are responsible for obtaining proper consent from recipients before sending emails.
- Email sending must comply with the specified rate limits. Exceeding the limits may result in temporary suspension of sending privileges.
- You shall not use the service to send content that is unlawful, harmful, threatening, abusive, or otherwise objectionable.
- Attachments must not contain malicious software, viruses, or any harmful code.
- Public accounts are shared resources; you shall not use them for personal or unrelated business purposes.
SNS/Voice
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Single data size limit | Paid items, controlled by the operator | Paid items, controlled by the operator | Paid items, controlled by the operator |
| Number of accounts | 10 | 30 | 100 |
Send Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Daily SMS send limit | 1,000 | 5,000 | 20,000 |
| Daily Voice call limit | 1,000 | 5,000 | 20,000 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| API request rate (concurrent) | 50 req/sec | 50 req/sec | 50 req/sec |
Note: SNS and Voice send quotas and performance depend on the underlying telecom operator or service provider. Actual throughput, delivery rate, and latency may vary across different vendors and regions.
- Usage rules:
- You shall comply with all applicable laws and regulations regarding SMS and voice communications, including recipient consent requirements.
- You shall not send or transmit content that is unlawful, fraudulent, harassing, or infringes on the rights of others.
- Sending frequency and content must not cause nuisance to recipients. Recipients must have a clear opt-out mechanism.
- You are responsible for all charges incurred from the operator for paid services.
- Mass sending is limited to prevent abuse. Bulk messaging requires prior review and approval.
- You shall not use the service for identity theft, phishing, or any deceptive practices.
Account
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of accounts | 100 | 500 | 2,000 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Authentication requests | 50 req/sec | 100 req/sec | 200 req/sec |
| User management API rate | 100 req/sec | 200 req/sec | 400 req/sec |
- Usage rules:
- Each account must be associated with a unique, valid user. Account sharing is prohibited.
- You are responsible for maintaining the confidentiality of account credentials and for all activities under your account.
- Passwords must meet the complexity requirements defined by the system and must be changed periodically.
- You shall not attempt to gain unauthorized access to other accounts or interfere with the normal operation of the account system.
- Suspicious account activities must be reported to the administrator immediately.
- Accounts that are inactive for an extended period may be disabled or reclaimed.
PAT token
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of PATs | 20 | 100 | 200 |
- Usage rules:
- Personal Access Tokens (PAT) must be kept confidential and must not be shared with others or exposed in code repositories, logs, or public documents.
- You shall regularly rotate PAT tokens and revoke tokens that are no longer needed.
- Each PAT should be granted the minimum permissions necessary for its intended use.
- You are fully responsible for all actions performed using your PAT tokens.
- Lost or compromised PAT tokens must be revoked immediately.
SSO Config
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of SSO SP | 3 | 15 | 60 |
- Usage rules:
- SSO configurations must only be used for the approved business purposes of the tenant.
- You shall ensure that identity provider endpoints use secure transmission protocols (TLS).
- Configuration changes must be performed by authorized personnel only.
- You are responsible for the accuracy and validity of the SSO configuration parameters.
- Misconfigured SSO integrations may be disabled to prevent security risks.
Identity Provider
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of SSO IDP | 3 | 15 | 60 |
- Usage rules:
- You shall only register applications that you own or have explicit authorization to manage.
- User identity data transmitted through the Identity Provider must comply with applicable data protection laws.
- You are responsible for the security of application client IDs and client secrets.
- Applications must not request more user information than is necessary for their functionality.
- Applications that violate security policies or user privacy may have their access revoked.
Clouddisk
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| File size (single upload) | 10M | 50M | 200M |
| Number of buckets | 10 | 50 | 200 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Request rate (concurrent, based on 5MB files) | 20 req/sec | 20 req/sec | 20 req/sec |
- Usage rules:
- You shall not upload, store, or share files that contain illegal, infringing, or malicious content.
- You are responsible for scanning files for viruses and malware before uploading.
- File sharing must be set with appropriate access permissions. Public sharing requires approval.
- You shall not use the cloud disk service to store or distribute material that violates intellectual property rights.
- Data stored in the cloud disk should be backed up by the tenant as needed; the service does not guarantee permanent data retention.
- Bucket names and file paths must not contain sensitive or personally identifiable information.
TOTP(Time-Based One-Time Password)
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of modules | 5 | 20 | 100 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Verification requests | 50 req/sec | 100 req/sec | 200 req/sec |
Note: Cloud disk performance depends on the underlying object storage provider. Actual throughput and latency may vary across different vendors. Performance benchmarks below are based on a 5MB file size scenario.
- Usage rules:
- TOTP secret keys must be stored securely and must not be shared or transmitted in plain text.
- Users are responsible for keeping their TOTP devices secure. Lost devices must be reported immediately for re-provisioning.
- TOTP modules shall only be used for authorized business applications.
- You shall not attempt to bypass or disable TOTP authentication mechanisms.
- Recovery codes must be stored in a secure location separate from the primary authentication device.
OCR
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of configs | 5 | 20 | 100 |
| Monthly processing quota | 1,000 files | 5,000 files | 20,000 files |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Request rate (concurrent, based on 1MB files) | 10 req/sec | 10 req/sec | 10 req/sec |
Note: OCR performance depends on the underlying OCR service provider. Actual processing speed, accuracy, and supported languages may vary across different vendors. Performance benchmarks below are based on a 1MB file size scenario.
- Usage rules:
- You shall only use the OCR service to process documents and images that you have the legal right to process.
- You are responsible for ensuring that the content processed does not violate any laws or regulations.
- OCR recognition results are for reference only; you shall verify accuracy for critical business scenarios.
- Sensitive personal data processed through OCR must be handled in accordance with applicable data protection regulations.
- Processed images and recognition results must not be stored longer than necessary for the business purpose.
DevOps
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of CICDs | 100 | 500 | 2,000 |
| Number of Deployment Plans | 100 | 500 | 2,000 |
- Usage rules:
- CICD pipelines must only be used for building, testing, and deploying authorized software projects.
- You shall not use DevOps resources for cryptocurrency mining, unauthorized computing tasks, or any activity unrelated to software development.
- Pipeline configurations must not contain hard-coded credentials or sensitive information. Use the dedicated secrets management feature instead.
- You are responsible for the code quality and security of projects built through the service.
- Build and deployment activities must comply with the tenant’s internal change management policies.
- Excessive consumption of shared build resources may result in throttling or temporary suspension.
Audit
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Single data size limit | 1M | 1M | 1M |
| Number of modules | 10 | 50 | 200 |
| Number of transactions | 50 | 200 | 500 |
| Number of logs | 100,000 | 1,000,000 | 10,000,000 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Query rate | 50 req/sec | 100 req/sec | 200 req/sec |
- Usage rules:
- Audit data must not be modified, deleted, or tampered with by any user or process outside of the audit system.
- Access to audit logs must be restricted to authorized personnel only, based on the principle of least privilege.
- Audit data is provided for compliance and security investigation purposes only.
- You shall not use the audit module to store data unrelated to audit trails.
- Data exceeding the retention period will be automatically archived or deleted according to the backup policy.
ConfigCenter
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of keys | 100 | 500 | 2,000 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Read rate | 200 req/sec | 200 req/sec | 200 req/sec |
| Write rate | 100 req/sec | 100 req/sec | 100 req/sec |
- Usage rules:
- Configuration values must not contain plaintext passwords, API keys, or other sensitive credentials. Use encrypted configuration for sensitive data.
- Configuration changes must follow the tenant’s change management process and be properly documented.
- You are responsible for the correctness and validity of configuration values. Incorrect configurations may cause service outages.
- Deleted configurations cannot be recovered unless a backup exists. Use caution when performing delete operations.
- Configuration keys must follow the naming conventions defined by the tenant to avoid conflicts.
Api Management
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| API routes | 10 | 50 | 100 |
| APIs | 100 | 500 | 1,000 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| API call rate limit (per tenant) | 200 req/sec | 400 req/sec | 2,000 req/sec |
- Usage rules:
- APIs published through the API Management service must comply with the tenant’s API design and security standards.
- You shall not expose APIs that contain security vulnerabilities or could lead to data leakage.
- API usage must adhere to defined rate limits and throttling policies.
- You are responsible for managing API keys and access credentials, including regular rotation.
- APIs must not be used to transmit sensitive data without proper encryption and authorization controls.
- API versions must be properly managed. Deprecated APIs should provide a migration path before retirement.
URP role
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Quantity limit | 20 | 100 | 400 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Role read rate | 100 req/sec | 200 req/sec | 400 req/sec |
- Usage rules:
- Roles must be created and assigned based on the principle of least privilege.
- Role assignments must be reviewed periodically and revoked when no longer needed.
- You shall not create roles with excessive or unnecessary permissions.
- Role changes must be performed by authorized administrators and recorded in the audit log.
- Elevated privilege roles require additional approval and regular recertification.
URP permission
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Quantity limit | 100 | 500 | 2,000 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Permission read rate | 100 req/sec | 200 req/sec | 400 req/sec |
- Usage rules:
- Permissions must only be granted for legitimate business purposes.
- You shall not attempt to circumvent permission controls or gain unauthorized access to resources.
- Permission assignments must be traceable and auditable.
- Permission changes must follow the approval workflow defined by the tenant.
- Overly broad permission grants may be revoked by the administrator for security reasons.
Log
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Log retention time | 40 days | 90 days | 365 days |
| Quantity limit | 100,000 | 500,000 | 2,000,000 |
| Daily ingestion limit | 1G | 5G | 40G |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Query rate(1D) | 10 req/sec | 50 req/sec | 100 req/sec |
- Usage rules:
- You shall not write logs containing plaintext passwords, credit card numbers, or other sensitive personal information.
- Log content must comply with applicable data protection regulations.
- You shall not intentionally generate excessive log entries that could impact system performance or storage.
- Log data is for operational troubleshooting and analysis purposes only.
- Log retention beyond the standard period requires a retention extension request and may incur additional costs.
- You shall not attempt to alter or delete log entries stored in the system.
Resource Quota
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| Number of templates | 100 | 200 | 5,000 |
| print tasks | 100,000 | 200,000 | 500,000 |
Performance Limits
| Quota Item | Band 1 | Band 2 | Band 3 |
|---|---|---|---|
| File generation rate (single-page standard document) | 10 files/sec | 10 files/sec | 10 files/sec |
- Usage rules:
- Print templates and print data must not contain content that is unlawful, infringing, or otherwise prohibited.
- You are responsible for the accuracy and completeness of print data. The service does not verify the correctness of content.
- Print tasks containing sensitive personal information must be handled in accordance with data protection requirements.
- Print templates must be properly version-controlled. Changes to production templates require approval.
- Print resources are shared. Excessive print task submissions may be throttled to ensure fair usage.
- Print data and output files must not be retained longer than necessary for the intended business purpose.