Default groups
From least to most access, the default groups in a tenant are the following:auditorscan view certain types of resources without access to data.viewerscan view most types of resources (except some resources related to access management, security, etc.) and access data in them (e.g. download objects in buckets).editorscan view and manage most types of resources and access data in them.adminscan view and manage all types of resources and access data in them.
Custom groups
Custom groups give you granular control over permissions. You can create custom groups in your tenant or in a specific project. To manage group permissions, you should then create access permits that assign roles for specific resources to the group. The access permits can assign roles to the resources at the following levels:- Tenant: A tenant, all projects and all resources within it.
- Project: A project and all resources within it.
-
Individual resource: A resource that supports access permits, and its child resources. For example:
- If you create an access permit for a group, it also applies to its group memberships because they are its child resources.
- If you create an access permit for a account, it does not apply to its access keys, because their parent is the project, not the account.
- Identity and Access Management resources (see the list in the Identity and Access Management section in Roles for Nebius AI Cloud groups)
- Buckets (Object Storage)
- Container registries (Container Registry)
- Secrets (MysteryBox)