Access management in Yandex Cloud AI Studio

Access management

Yandex Cloud AI Studio integrates with Yandex Identity and Access Management (IAM) to govern operations with resources. Identity and Access Management implements access control through roles and access policies. Roles define allowed operations, while access policies enforce restrictions on access to resources and operations.

Note

Access policies can deny operations even if a user holds the required roles. Such operations include calling and managing MCP servers, calling Responses API methods from specific cloud networks or IP addresses, or associating MCP servers with specific cloud networks.

Roles and access policies are assigned to a subject for a specific resource: organization, cloud, or folder. Child resources inherit access permissions from their parent resources. For example, a role assigned for a cloud grants access to all folders within that cloud.

Before performing an operation in AI Studio, IAM verifies that:

  • The subject has the required roles.
  • No active access policies restrict the requested operation.

If both conditions are met, IAM authorizes the action. Otherwise, it returns an access error.

For more information about access management in Yandex Cloud, see How access management works in Yandex Cloud.

A subject is an identity performing the operation, to which you can assign roles. Subjects may include users, user groups, service accounts, and other accounts in Yandex Cloud.

For more information, see How access management works in Yandex Cloud.

Roles this service has

The diagram below shows available service roles and their permission inheritance hierarchy. For example, editor inherits all viewer permissions. You can find all role descriptions below the diagram:

Service roles

General roles in Yandex Cloud AI Studio

ai.auditor

The ai.auditor role enables viewing info on quotas for Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio, on uploaded files, Vector Store search indexes, datasets, and text generation models in Yandex Cloud AI Studio, view metadata on guardrails for model responses, as well as info on the relevant cloud and folder.

This role includes the ai.assistants.auditor, ai.datasets.auditor, ai.models.auditor, and ai.guardrails.auditor permissions.

ai.viewer

The ai.viewer role enables viewing info on quotas for Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio, on text generation models, guardrails for model responses, datasets, uploaded files, and Vector Store search indexes in Yandex Cloud AI Studio, read such files and conduct searches using these indexes, as well as view info on the relevant cloud and folder.

This role includes the ai.auditor, ai.assistants.viewer, ai.datasets.viewer, ai.models.viewer, and ai.guardrails.viewer permissions.

ai.editor

The ai.editor role enables using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio.

Users with this role can:

This role includes the ai.viewer, ai.translate.user, ai.vision.user, ai.speechkit-stt.user, ai.speechkit-tts.user, ai.languageModels.user, ai.imageGeneration.user, ai.assistants.editor, ai.datasets.editor, ai.models.editor, and ai.guardrails.editor permissions.

ai.admin

The ai.admin role enables using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio.

Users with this role can:

This role includes the ai.editor, ai.assistants.admin, ai.datasets.admin, ai.models.admin, and ai.guardrails.admin permissions.

AI agents

ai.assistants.auditor

The ai.assistants.auditor role enables viewing info on uploaded files, Vector Store search indexes, Yandex Cloud AI Studio quotas, as well as on the relevant cloud and folder.

ai.assistants.viewer

The ai.assistants.viewer role enables viewing info on files and Vector Store search indexes as well as conducting searches using these indexes.

Users with this role can:

  • View info on uploaded files and their contents.
  • View info on Vector Store search indexes as well as conduct searches using these indexes.
  • View info on Yandex Cloud AI Studio quotas.
  • View info on the relevant cloud.
  • View info on the relevant folder.

This role includes the ai.assistants.auditor permissions.

ai.assistants.editor

The ai.assistants.editor role enables using AI agents as well as managing files and Vector Store search indexes.

Users with this role can:

  • Use AI agents.
  • View info on uploaded files as well as create, update, view, and delete them.
  • View info on Vector Store search indexes, create, modify, and delete them, as well as conduct searches using these indexes.
  • View info on Yandex Cloud AI Studio quotas.
  • View info on the relevant cloud.
  • View info on the relevant folder.

This role includes the ai.assistants.viewer permissions.

ai.assistants.admin

The ai.assistants.admin role enables using AI agents as well as managing files and Vector Store search indexes.

Users with this role can:

  • Use AI agents.
  • View info on uploaded files as well as create, update, view, and delete them.
  • View info on Vector Store search indexes, create, modify, and delete them, as well as conduct searches using these indexes.
  • View info on Yandex Cloud AI Studio quotas.
  • View info on the relevant cloud.
  • View info on the relevant folder.

This role includes the ai.assistants.editor permissions.

Datasets

ai.datasets.auditor

The ai.datasets.auditor role enables viewing the dataset metadata.

ai.datasets.viewer

The ai.datasets.viewer role enables viewing the info on datasets.

This role includes the ai.datasets.auditor permissions.

ai.datasets.user

The ai.datasets.user role enables viewing info on datasets and using them to fine-tune models in AI Studio.

This role includes the ai.datasets.viewer permissions.

ai.datasets.editor

The ai.datasets.editor role enables viewing info on datasets, creating, modifying, and deleting them, as well as using them to fine-tune models in AI Studio.

This role includes the ai.datasets.user permissions.

ai.datasets.admin

The ai.datasets.admin role enables viewing info on datasets, creating, modifying, and deleting them, as well as using them to fine-tune models in AI Studio.

This role includes the ai.datasets.editor permissions.

Text and image generation models

ai.languageModels.user

The ai.languageModels.user role enables using text generation models, text embedding models, and classifier models in Yandex Cloud AI Studio, as well as viewing info on the relevant cloud, folder, and quotas.

ai.imageGeneration.user

The ai.imageGeneration.user role enables using the YandexART image generation models within Yandex Cloud AI Studio, as well as viewing info on the relevant cloud, folder, and quotas.

ai.models.auditor

The ai.models.auditor role enables viewing the text generation model metadata in Yandex Cloud AI Studio.

ai.models.viewer

The ai.models.viewer role enables viewing info on the text generation models in Yandex Cloud AI Studio.

This role includes the ai.models.auditor permissions.

ai.models.user

The ai.models.user role enables using AI agents, text and image generation models, text embedding models, and classifier models in Yandex Cloud AI Studio, as well as employing Yandex Translate, Yandex Vision OCR, and Yandex SpeechKit.

Users with this role can:

This role includes the ai.models.viewer permissions.

ai.models.editor

The ai.models.editor role enables managing the fine-tuning of Yandex Cloud AI Studio models as well as using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio.

Users with this role can:

This role includes the ai.models.user permissions.

ai.models.admin

The ai.models.admin role enables managing the fine-tuning of Yandex Cloud AI Studio models as well as using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio.

Users with this role can:

This role includes the ai.models.editor permissions.

ai.playground.user

The ai.playground.user role enables creating experiments, getting a list of all available models, and using these models in AI Playground in the Yandex Cloud management console. To work with search indexes in the management console, you also need the ai.assistants.editor role.

Model response moderation

ai.guardrails.auditor

The ai.guardrails.auditor role enables viewing metadata on guardrails for model responses.

ai.guardrails.viewer

The ai.guardrails.viewer role enables viewing info on guardrails for model responses.

This role includes the ai.guardrails.auditor permissions.

ai.guardrails.user

The ai.guardrails.user role enables applying guardrails for model responses and viewing metadata on such rules.

ai.guardrails.editor

The ai.guardrails.editor role enables viewing info on guardrails for model responses, as well as creating, applying, modifying, and deleting such rules.

This role includes the ai.guardrails.viewer and ai.guardrails.user permissions.

ai.guardrails.admin

The ai.guardrails.admin role enables viewing info on guardrails for model responses, as well as creating, applying, modifying, and deleting such rules.

This role includes the ai.guardrails.editor permissions.

Speech synthesis and recognition

ai.speechkit-stt.user

The ai.speechkit-stt.user role allows you to use Yandex SpeechKit for speech recognition, as well as view info on the relevant cloud, folder, and quotas.

ai.speechkit-tts.user

The ai.speechkit-tts.user role allows you to use Yandex SpeechKit for speech synthesis, as well as view info on the relevant cloud, folder, and quotas.

Search queries

search-api.webSearch.user

The search-api.webSearch.user role enables running search queries in Yandex Search API, as well as viewing info on the cloud, folder, and Yandex Search API quotas.

search-api.executor

The search-api.executor role was used by an API that is now deprecated.

The search-api.executor role is no longer available.

search-api.auditor

The search-api.auditor role was used by an API that is now deprecated. The role enables viewing Yandex Search API quotas, as well as information on the relevant cloud and folder.

The search-api.auditor role should no longer be used.

search-api.viewer

The search-api.viewer role was used by an API that is now deprecated. The role enables viewing Yandex Search API quotas, as well as information on the relevant cloud and folder.

The search-api.viewer role should no longer be used.

search-api.editor

The search-api.editor role was used by an API that is now deprecated. The role enables viewing Yandex Search API quotas, as well as information on the relevant cloud and folder.

The search-api.editor role should no longer be used.

search-api.admin

The search-api.admin role was used by an API that is now deprecated. The role enables viewing Yandex Search API quotas, as well as information on the relevant cloud and folder.

The search-api.admin role should no longer be used.

Text recognition in images and PDF files

ai.vision.user

The ai.vision.user role allows you to use Yandex Vision OCR to analyze images, as well as view info on the relevant cloud, folder, and quotas.

Text translation

ai.translate.user

The ai.translate.user role allows you to use Yandex Translate to translate texts, as well as view info on the relevant cloud, folder, and quotas.

MCP servers

serverless.mcpGateways.auditor

The serverless.mcpGateways.auditor role allows the user to view info on MCP servers and their access permissions.

serverless.mcpGateways.viewer

The serverless.mcpGateways.viewer role allows the user to view info on MCP servers and their access permissions.

This role includes the serverless.mcpGateways.auditor permissions.

serverless.mcpGateways.invoker

The serverless.mcpGateways.invoker role allows the user to access MCP servers, including access via MCP Hub.

serverless.mcpGateways.anonymousInvoker

The serverless.mcpGateways.anonymousInvoker role allows the user to access MCP servers, including access via MCP Hub.

serverless.mcpGateways.editor

The serverless.mcpGateways.editor role allows the user to create, modify and delete MCP servers, view info on them and their access permissions.

This role includes the serverless.mcpGateways.viewer permissions.

serverless.mcpGateways.admin

The serverless.mcpGateways.admin role allows the user to manage MCP servers and access to them.

Users with this role can:

  • View MCP server info, create, update, and delete MCP servers.
  • View MCP server access permission info, modify MCP server access permissions.
  • Access MCP servers, including external ones, via MCP Hub.

This role includes the serverless.mcpGateways.editor, serverless.mcpGateways.invoker, and serverless.mcpGateways.anonymousInvoker permissions.

Workflows

With Workflows service roles, you can manage user access to Workflows workflows.

Note

The ability to execute and manage workflows from specific cloud networks or IP addresses, or associate workflows with specific cloud networks, may be restricted by access policies at the folder, cloud, or organization level.

serverless.workflows.auditor

The serverless.workflows.auditor role enables viewing info on workflows and access permissions assigned to them, viewing the history of workflow executions, as well as info on Yandex Workflows quotas.

serverless.workflows.viewer

The serverless.workflows.viewer role enables viewing info on workflows and access permissions assigned to them, viewing the history of workflow executions, as well as info on Yandex Workflows quotas.

This role includes the serverless.workflows.auditor permissions.

serverless.workflows.executor

The serverless.workflows.executor role enables executing, pausing, resuming, and stopping workflows.

serverless.workflows.editor

The serverless.workflows.editor role enables managing workflows.

Users with this role can:

  • View info on workflows and access permissions assigned to them;
  • Create, update, and delete workflows.
  • Execute, pause, resume, and stop workflows.
  • View the history of workflow executions.
  • View info on Yandex Workflows quotas.

This role includes the serverless.workflows.viewer and serverless.workflows.executor permissions.

serverless.workflows.admin

The serverless.workflows.admin role enables managing workflows.

Users with this role can:

  • View info on workflows as well as create, update, and delete them.
  • View info on access permissions assigned to workflows and modify such permissions.
  • Execute, pause, resume, and stop workflows.
  • View the history of workflow executions.
  • View info on Yandex Workflows quotas.

This role includes the serverless.workflows.editor permissions.

Primitive roles

Primitive roles allow users to perform actions in all Yandex Cloud services.

auditor

The auditor role grants a permission to read configuration and metadata of any Yandex Cloud resources without any access to data.

For instance, users with this role can:

  • View info on a resource.
  • View the resource metadata.
  • View the list of operations with a resource.

auditor is the most secure role that does not grant any access to the service data. This role suits the users who need minimum access to the Yandex Cloud resources.

viewer

The viewer role grants the permissions to read the info on any Yandex Cloud resources.

This role includes the auditor permissions.

Unlike auditor, the viewer role provides access to service data in read mode.

editor

The editor role provides permissions to manage any Yandex Cloud resources, except for assigning roles to other users, transferring organization ownership, removing an organization, and deleting Key Management Service encryption keys.

For instance, users with this role can create, modify, and delete resources.

This role includes the viewer permissions.

admin

The admin role enables assigning any roles, except for resource-manager.clouds.owner and organization-manager.organizations.owner, and provides permissions to manage any Yandex Cloud resources (except for transferring organization ownership and removing an organization).

Prior to assigning the admin role for an organization, cloud, or billing account, make sure to check out the information on protecting privileged accounts.

This role includes the editor permissions.

Instead of primitive roles, we recommend using service roles with more granular access control, allowing you to implement the least privilege principle.

Required roles

The table shows actions and minimum roles required to perform them. You can always assign a role granting more permissions than the role specified, e.g., ai.editor instead of ai.viewer.

Action Required roles
Viewing data
Viewing metadata of all Yandex Cloud AI Studio resources, information about quotas in Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio, as well as cloud and folder info ai.auditor
Viewing information about all Yandex Cloud AI Studio resources, reading uploaded files, and searching within Vector Store search indexes ai.viewer
Viewing info on uploaded files and Vector Store search indexes ai.assistants.auditor
Viewing the contents of uploaded files and searching within Vector Store search indexes ai.assistants.viewer
Viewing dataset metadata ai.datasets.auditor
Viewing dataset info ai.datasets.viewer
Viewing metadata of text generation models ai.models.auditor
Viewing info on text generation models ai.models.viewer
Viewing traces of models and agents in the folder ai.models.viewer
Viewing metadata on model response guardrails ai.guardrails.auditor
Viewing info on model response guardrails ai.guardrails.viewer
Viewing info on MCP servers and access permissions granted for them serverless.mcpGateways.auditor
View info on workflows and access permissions assigned for them, execution history, and Yandex Workflows quotas serverless.workflows.auditor
Using models and services
Using text generation models, text embedding models, and classifiers ai.languageModels.user
Using image generation models ai.imageGeneration.user
Using AI agents, as well as text and image generation models, text embedding models, and classifiers ai.models.user
Creating experiments and using available models in AI Playground within the AI Studio UI ai.playground.user
Performing search queries in Yandex Search API search-api.webSearch.user
Translating a text using Yandex Translate ai.translate.user
Image-to-text recognition with Yandex Vision OCR ai.vision.user
Speech recognition using Yandex SpeechKit ai.speechkit-stt.user
Speech synthesis using Yandex SpeechKit ai.speechkit-tts.user
Enabling model response guardrails ai.guardrails.user
Using datasets for model fine-tuning ai.datasets.user
Accessing MCP servers, including via MCP Hub serverless.mcpGateways.invoker
Accessing external MCP servers serverless.mcpGateways.anonymousInvoker
Starting, pausing, resuming, and stopping workflows serverless.workflows.executor
Managing resources
Using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio, as well as managing files, Vector Store search indexes, datasets, fine-tuned models, and guardrails ai.editor
Uploading, updating, and deleting files; creating, updating, and deleting Vector Store search indexes ai.assistants.editor
Working with files, search indexes, and AI agents in the AI Studio UI ai.playground.user and ai.assistants.editor
Deleting AI agents and search indexes via the AI Studio UI ai.playground.user
Creating, editing, and deleting datasets ai.datasets.editor
Creating and deleting datasets via the AI Studio UI ai.playground.user and ai.datasets.editor
Running a model in batch mode in the AI Studio UI ai.playground.user and ai.datasets.editor
Fine-tuning models, as well as creating, updating, and deleting fine-tuned models ai.models.editor
Fine-tuning models and classifiers via the AI Studio UI ai.playground.user, ai.datasets.user, and ai.models.editor
Creating, editing, deleting, starting, and stopping Yandex Cloud AI Studio instances ai.models.editor
Enabling tracing for models and agents ai.models.editor
Creating, enabling, updating, and deleting model response guardrails ai.guardrails.editor
Creating and connecting MCP servers serverless.mcpGateways.editor and iam.serviceAccounts.user
Updating and deleting MCP servers serverless.mcpGateways.editor
Creating, editing, and deleting workflows serverless.workflows.editor
Creating an API key in the AI Studio UI resource-manager.admin
Managing resource access
Assigning a role, revoking a role, and viewing roles assigned for a folder admin
Managing access to MCP servers serverless.mcpGateways.admin
Managing access to workflows serverless.workflows.admin

Note

The search-api.executor, search-api.auditor, search-api.viewer, search-api.editor, and search-api.admin roles were previously used to work with the Yandex Search API API. These roles are deprecated and should no longer be used. To perform search queries, assign the search-api.webSearch.user role.

Useful links