Access management in Yandex Cloud AI Studio
Access management
Yandex Cloud AI Studio integrates with Yandex Identity and Access Management (IAM) to govern operations with resources. Identity and Access Management implements access control through roles and access policies. Roles define allowed operations, while access policies enforce restrictions on access to resources and operations.
Note
Access policies can deny operations even if a user holds the required roles. Such operations include calling and managing MCP servers, calling Responses API methods from specific cloud networks or IP addresses, or associating MCP servers with specific cloud networks.
Roles and access policies are assigned to a subject for a specific resource: organization, cloud, or folder. Child resources inherit access permissions from their parent resources. For example, a role assigned for a cloud grants access to all folders within that cloud.
Before performing an operation in AI Studio, IAM verifies that:
- The subject has the required roles.
- No active access policies restrict the requested operation.
If both conditions are met, IAM authorizes the action. Otherwise, it returns an access error.
For more information about access management in Yandex Cloud, see How access management works in Yandex Cloud.
A subject is an identity performing the operation, to which you can assign roles. Subjects may include users, user groups, service accounts, and other accounts in Yandex Cloud.
For more information, see How access management works in Yandex Cloud.
Roles this service has
The diagram below shows available service roles and their permission inheritance hierarchy. For example, editor inherits all viewer permissions. You can find all role descriptions below the diagram:
- General roles
- AI agents
- Datasets
- Text and image generation models
- Experiments
- Model response moderation
- Speech recognition and synthesis
- Text recognition
- Translating text
- Search queries
- MCP servers
- Workflows
Service roles
General roles in Yandex Cloud AI Studio
ai.auditor
The ai.auditor role enables viewing info on quotas for Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio, on uploaded files, Vector Store search indexes, datasets, and text generation models in Yandex Cloud AI Studio, view metadata on guardrails for model responses, as well as info on the relevant cloud and folder.
This role includes the ai.assistants.auditor, ai.datasets.auditor, ai.models.auditor, and ai.guardrails.auditor permissions.
ai.viewer
The ai.viewer role enables viewing info on quotas for Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio, on text generation models, guardrails for model responses, datasets, uploaded files, and Vector Store search indexes in Yandex Cloud AI Studio, read such files and conduct searches using these indexes, as well as view info on the relevant cloud and folder.
This role includes the ai.auditor, ai.assistants.viewer, ai.datasets.viewer, ai.models.viewer, and ai.guardrails.viewer permissions.
ai.editor
The ai.editor role enables using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio.
Users with this role can:
- Use Yandex Translate to translate texts.
- Use Yandex Vision OCR to analyze images.
- Use Yandex SpeechKit for speech recognition and synthesis.
- View info on text generation models in Yandex Cloud AI Studio.
- View info on guardrails for model responses, as well as create, apply, modify, and delete guardrails.
- Use AI agents, text and image generation models, text embedding models, and classifier models in Yandex Cloud AI Studio.
- View info on uploaded files as well as create, update, view, and delete them.
- View info on Vector Store search indexes, create, modify, and delete them, as well as conduct searches using these indexes.
- Fine-tune Yandex Cloud AI Studio models as well as create, modify, and delete fine-tuned models.
- View info on datasets, use them to fine-tune models, as well as create, modify, and delete datasets.
- View info on the relevant cloud and folder.
- View info on quotes for Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio.
This role includes the ai.viewer, ai.translate.user, ai.vision.user, ai.speechkit-stt.user, ai.speechkit-tts.user, ai.languageModels.user, ai.imageGeneration.user, ai.assistants.editor, ai.datasets.editor, ai.models.editor, and ai.guardrails.editor permissions.
ai.admin
The ai.admin role enables using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio.
Users with this role can:
- Use Yandex Translate to translate texts.
- Use Yandex Vision OCR to analyze images.
- Use Yandex SpeechKit for speech recognition and synthesis.
- View info on text generation models in Yandex Cloud AI Studio.
- View info on guardrails for model responses, as well as create, apply, modify, and delete guardrails.
- Use AI agents, text and image generation models, text embedding models, and classifier models in Yandex Cloud AI Studio.
- View info on uploaded files as well as create, update, view, and delete them.
- View info on Vector Store search indexes, create, modify, and delete them, as well as conduct searches using these indexes.
- Fine-tune Yandex Cloud AI Studio models as well as create, modify, and delete fine-tuned models.
- View info on datasets, use them to fine-tune models, as well as create, modify, and delete datasets.
- View info on the relevant cloud and folder.
- View info on Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio quotes.
This role includes the ai.editor, ai.assistants.admin, ai.datasets.admin, ai.models.admin, and ai.guardrails.admin permissions.
AI agents
ai.assistants.auditor
The ai.assistants.auditor role enables viewing info on uploaded files, Vector Store search indexes, Yandex Cloud AI Studio quotas, as well as on the relevant cloud and folder.
ai.assistants.viewer
The ai.assistants.viewer role enables viewing info on files and Vector Store search indexes as well as conducting searches using these indexes.
Users with this role can:
- View info on uploaded files and their contents.
- View info on Vector Store search indexes as well as conduct searches using these indexes.
- View info on Yandex Cloud AI Studio quotas.
- View info on the relevant cloud.
- View info on the relevant folder.
This role includes the ai.assistants.auditor permissions.
ai.assistants.editor
The ai.assistants.editor role enables using AI agents as well as managing files and Vector Store search indexes.
Users with this role can:
- Use AI agents.
- View info on uploaded files as well as create, update, view, and delete them.
- View info on Vector Store search indexes, create, modify, and delete them, as well as conduct searches using these indexes.
- View info on Yandex Cloud AI Studio quotas.
- View info on the relevant cloud.
- View info on the relevant folder.
This role includes the ai.assistants.viewer permissions.
ai.assistants.admin
The ai.assistants.admin role enables using AI agents as well as managing files and Vector Store search indexes.
Users with this role can:
- Use AI agents.
- View info on uploaded files as well as create, update, view, and delete them.
- View info on Vector Store search indexes, create, modify, and delete them, as well as conduct searches using these indexes.
- View info on Yandex Cloud AI Studio quotas.
- View info on the relevant cloud.
- View info on the relevant folder.
This role includes the ai.assistants.editor permissions.
Datasets
ai.datasets.auditor
The ai.datasets.auditor role enables viewing the dataset metadata.
ai.datasets.viewer
The ai.datasets.viewer role enables viewing the info on datasets.
This role includes the ai.datasets.auditor permissions.
ai.datasets.user
The ai.datasets.user role enables viewing info on datasets and using them to fine-tune models in AI Studio.
This role includes the ai.datasets.viewer permissions.
ai.datasets.editor
The ai.datasets.editor role enables viewing info on datasets, creating, modifying, and deleting them, as well as using them to fine-tune models in AI Studio.
This role includes the ai.datasets.user permissions.
ai.datasets.admin
The ai.datasets.admin role enables viewing info on datasets, creating, modifying, and deleting them, as well as using them to fine-tune models in AI Studio.
This role includes the ai.datasets.editor permissions.
Text and image generation models
ai.languageModels.user
The ai.languageModels.user role enables using text generation models, text embedding models, and classifier models in Yandex Cloud AI Studio, as well as viewing info on the relevant cloud, folder, and quotas.
ai.imageGeneration.user
The ai.imageGeneration.user role enables using the YandexART image generation models within Yandex Cloud AI Studio, as well as viewing info on the relevant cloud, folder, and quotas.
ai.models.auditor
The ai.models.auditor role enables viewing the text generation model metadata in Yandex Cloud AI Studio.
ai.models.viewer
The ai.models.viewer role enables viewing info on the text generation models in Yandex Cloud AI Studio.
This role includes the ai.models.auditor permissions.
ai.models.user
The ai.models.user role enables using AI agents, text and image generation models, text embedding models, and classifier models in Yandex Cloud AI Studio, as well as employing Yandex Translate, Yandex Vision OCR, and Yandex SpeechKit.
Users with this role can:
- View info on text generation models in Yandex Cloud AI Studio.
- Use AI agents, text and image generation models, text embedding models, and classifier models in Yandex Cloud AI Studio.
- Use Yandex Translate to translate texts.
- Use Yandex Vision OCR to analyze images.
- Use Yandex SpeechKit for speech recognition and synthesis.
This role includes the ai.models.viewer permissions.
ai.models.editor
The ai.models.editor role enables managing the fine-tuning of Yandex Cloud AI Studio models as well as using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio.
Users with this role can:
- View info on text generation models in Yandex Cloud AI Studio.
- Fine-tune Yandex Cloud AI Studio models as well as create, modify, and delete fine-tuned models.
- Use AI agents, text and image generation models, text embedding models, and classifier models in Yandex Cloud AI Studio.
- Use Yandex Translate to translate texts.
- Use Yandex Vision OCR to analyze images.
- Use Yandex SpeechKit for speech recognition and synthesis.
This role includes the ai.models.user permissions.
ai.models.admin
The ai.models.admin role enables managing the fine-tuning of Yandex Cloud AI Studio models as well as using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio.
Users with this role can:
- View info on text generation models in Yandex Cloud AI Studio.
- Fine-tune Yandex Cloud AI Studio models as well as create, modify, and delete fine-tuned models.
- Use AI agents, text and image generation models, text embedding models, and classifier models in Yandex Cloud AI Studio.
- Use Yandex Translate to translate texts.
- Use Yandex Vision OCR to analyze images.
- Use Yandex SpeechKit for speech recognition and synthesis.
This role includes the ai.models.editor permissions.
ai.playground.user
The ai.playground.user role enables creating experiments, getting a list of all available models, and using these models in AI Playground in the Yandex Cloud management console. To work with search indexes in the management console, you also need the ai.assistants.editor role.
Model response moderation
ai.guardrails.auditor
The ai.guardrails.auditor role enables viewing metadata on guardrails for model responses.
ai.guardrails.viewer
The ai.guardrails.viewer role enables viewing info on guardrails for model responses.
This role includes the ai.guardrails.auditor permissions.
ai.guardrails.user
The ai.guardrails.user role enables applying guardrails for model responses and viewing metadata on such rules.
ai.guardrails.editor
The ai.guardrails.editor role enables viewing info on guardrails for model responses, as well as creating, applying, modifying, and deleting such rules.
This role includes the ai.guardrails.viewer and ai.guardrails.user permissions.
ai.guardrails.admin
The ai.guardrails.admin role enables viewing info on guardrails for model responses, as well as creating, applying, modifying, and deleting such rules.
This role includes the ai.guardrails.editor permissions.
Speech synthesis and recognition
ai.speechkit-stt.user
The ai.speechkit-stt.user role allows you to use Yandex SpeechKit for speech recognition, as well as view info on the relevant cloud, folder, and quotas.
ai.speechkit-tts.user
The ai.speechkit-tts.user role allows you to use Yandex SpeechKit for speech synthesis, as well as view info on the relevant cloud, folder, and quotas.
Search queries
search-api.webSearch.user
The search-api.webSearch.user role enables running search queries in Yandex Search API, as well as viewing info on the cloud, folder, and Yandex Search API quotas.
search-api.executor
The search-api.executor role was used by an API that is now deprecated.
The search-api.executor role is no longer available.
search-api.auditor
The search-api.auditor role was used by an API that is now deprecated. The role enables viewing Yandex Search API quotas, as well as information on the relevant cloud and folder.
The search-api.auditor role should no longer be used.
search-api.viewer
The search-api.viewer role was used by an API that is now deprecated. The role enables viewing Yandex Search API quotas, as well as information on the relevant cloud and folder.
The search-api.viewer role should no longer be used.
search-api.editor
The search-api.editor role was used by an API that is now deprecated. The role enables viewing Yandex Search API quotas, as well as information on the relevant cloud and folder.
The search-api.editor role should no longer be used.
search-api.admin
The search-api.admin role was used by an API that is now deprecated. The role enables viewing Yandex Search API quotas, as well as information on the relevant cloud and folder.
The search-api.admin role should no longer be used.
Text recognition in images and PDF files
ai.vision.user
The ai.vision.user role allows you to use Yandex Vision OCR to analyze images, as well as view info on the relevant cloud, folder, and quotas.
Text translation
ai.translate.user
The ai.translate.user role allows you to use Yandex Translate to translate texts, as well as view info on the relevant cloud, folder, and quotas.
MCP servers
serverless.mcpGateways.auditor
The serverless.mcpGateways.auditor role allows the user to view info on MCP servers and their access permissions.
serverless.mcpGateways.viewer
The serverless.mcpGateways.viewer role allows the user to view info on MCP servers and their access permissions.
This role includes the serverless.mcpGateways.auditor permissions.
serverless.mcpGateways.invoker
The serverless.mcpGateways.invoker role allows the user to access MCP servers, including access via MCP Hub.
serverless.mcpGateways.anonymousInvoker
The serverless.mcpGateways.anonymousInvoker role allows the user to access MCP servers, including access via MCP Hub.
serverless.mcpGateways.editor
The serverless.mcpGateways.editor role allows the user to create, modify and delete MCP servers, view info on them and their access permissions.
This role includes the serverless.mcpGateways.viewer permissions.
serverless.mcpGateways.admin
The serverless.mcpGateways.admin role allows the user to manage MCP servers and access to them.
Users with this role can:
- View MCP server info, create, update, and delete MCP servers.
- View MCP server access permission info, modify MCP server access permissions.
- Access MCP servers, including external ones, via MCP Hub.
This role includes the serverless.mcpGateways.editor, serverless.mcpGateways.invoker, and serverless.mcpGateways.anonymousInvoker permissions.
Workflows
With Workflows service roles, you can manage user access to Workflows workflows.
Note
The ability to execute and manage workflows from specific cloud networks or IP addresses, or associate workflows with specific cloud networks, may be restricted by access policies at the folder, cloud, or organization level.
serverless.workflows.auditor
The serverless.workflows.auditor role enables viewing info on workflows and access permissions assigned to them, viewing the history of workflow executions, as well as info on Yandex Workflows quotas.
serverless.workflows.viewer
The serverless.workflows.viewer role enables viewing info on workflows and access permissions assigned to them, viewing the history of workflow executions, as well as info on Yandex Workflows quotas.
This role includes the serverless.workflows.auditor permissions.
serverless.workflows.executor
The serverless.workflows.executor role enables executing, pausing, resuming, and stopping workflows.
serverless.workflows.editor
The serverless.workflows.editor role enables managing workflows.
Users with this role can:
- View info on workflows and access permissions assigned to them;
- Create, update, and delete workflows.
- Execute, pause, resume, and stop workflows.
- View the history of workflow executions.
- View info on Yandex Workflows quotas.
This role includes the serverless.workflows.viewer and serverless.workflows.executor permissions.
serverless.workflows.admin
The serverless.workflows.admin role enables managing workflows.
Users with this role can:
- View info on workflows as well as create, update, and delete them.
- View info on access permissions assigned to workflows and modify such permissions.
- Execute, pause, resume, and stop workflows.
- View the history of workflow executions.
- View info on Yandex Workflows quotas.
This role includes the serverless.workflows.editor permissions.
Primitive roles
Primitive roles allow users to perform actions in all Yandex Cloud services.
auditor
The auditor role grants a permission to read configuration and metadata of any Yandex Cloud resources without any access to data.
For instance, users with this role can:
- View info on a resource.
- View the resource metadata.
- View the list of operations with a resource.
auditor is the most secure role that does not grant any access to the service data. This role suits the users who need minimum access to the Yandex Cloud resources.
viewer
The viewer role grants the permissions to read the info on any Yandex Cloud resources.
This role includes the auditor permissions.
Unlike auditor, the viewer role provides access to service data in read mode.
editor
The editor role provides permissions to manage any Yandex Cloud resources, except for assigning roles to other users, transferring organization ownership, removing an organization, and deleting Key Management Service encryption keys.
For instance, users with this role can create, modify, and delete resources.
This role includes the viewer permissions.
admin
The admin role enables assigning any roles, except for resource-manager.clouds.owner and organization-manager.organizations.owner, and provides permissions to manage any Yandex Cloud resources (except for transferring organization ownership and removing an organization).
Prior to assigning the admin role for an organization, cloud, or billing account, make sure to check out the information on protecting privileged accounts.
This role includes the editor permissions.
Instead of primitive roles, we recommend using service roles with more granular access control, allowing you to implement the least privilege principle.
Required roles
The table shows actions and minimum roles required to perform them. You can always assign a role granting more permissions than the role specified, e.g., ai.editor instead of ai.viewer.
| Action | Required roles |
|---|---|
| Viewing data | |
| Viewing metadata of all Yandex Cloud AI Studio resources, information about quotas in Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio, as well as cloud and folder info | ai.auditor |
| Viewing information about all Yandex Cloud AI Studio resources, reading uploaded files, and searching within Vector Store search indexes | ai.viewer |
| Viewing info on uploaded files and Vector Store search indexes | ai.assistants.auditor |
| Viewing the contents of uploaded files and searching within Vector Store search indexes | ai.assistants.viewer |
| Viewing dataset metadata | ai.datasets.auditor |
| Viewing dataset info | ai.datasets.viewer |
| Viewing metadata of text generation models | ai.models.auditor |
| Viewing info on text generation models | ai.models.viewer |
| Viewing traces of models and agents in the folder | ai.models.viewer |
| Viewing metadata on model response guardrails | ai.guardrails.auditor |
| Viewing info on model response guardrails | ai.guardrails.viewer |
| Viewing info on MCP servers and access permissions granted for them | serverless.mcpGateways.auditor |
| View info on workflows and access permissions assigned for them, execution history, and Yandex Workflows quotas | serverless.workflows.auditor |
| Using models and services | |
| Using text generation models, text embedding models, and classifiers | ai.languageModels.user |
| Using image generation models | ai.imageGeneration.user |
| Using AI agents, as well as text and image generation models, text embedding models, and classifiers | ai.models.user |
| Creating experiments and using available models in AI Playground within the AI Studio UI | ai.playground.user |
| Performing search queries in Yandex Search API | search-api.webSearch.user |
| Translating a text using Yandex Translate | ai.translate.user |
| Image-to-text recognition with Yandex Vision OCR | ai.vision.user |
| Speech recognition using Yandex SpeechKit | ai.speechkit-stt.user |
| Speech synthesis using Yandex SpeechKit | ai.speechkit-tts.user |
| Enabling model response guardrails | ai.guardrails.user |
| Using datasets for model fine-tuning | ai.datasets.user |
| Accessing MCP servers, including via MCP Hub | serverless.mcpGateways.invoker |
| Accessing external MCP servers | serverless.mcpGateways.anonymousInvoker |
| Starting, pausing, resuming, and stopping workflows | serverless.workflows.executor |
| Managing resources | |
| Using Yandex Translate, Yandex Vision OCR, Yandex SpeechKit, and Yandex Cloud AI Studio, as well as managing files, Vector Store search indexes, datasets, fine-tuned models, and guardrails | ai.editor |
| Uploading, updating, and deleting files; creating, updating, and deleting Vector Store search indexes | ai.assistants.editor |
| Working with files, search indexes, and AI agents in the AI Studio UI | ai.playground.user and ai.assistants.editor |
| Deleting AI agents and search indexes via the AI Studio UI | ai.playground.user |
| Creating, editing, and deleting datasets | ai.datasets.editor |
| Creating and deleting datasets via the AI Studio UI | ai.playground.user and ai.datasets.editor |
| Running a model in batch mode in the AI Studio UI | ai.playground.user and ai.datasets.editor |
| Fine-tuning models, as well as creating, updating, and deleting fine-tuned models | ai.models.editor |
| Fine-tuning models and classifiers via the AI Studio UI | ai.playground.user, ai.datasets.user, and ai.models.editor |
| Creating, editing, deleting, starting, and stopping Yandex Cloud AI Studio instances | ai.models.editor |
| Enabling tracing for models and agents | ai.models.editor |
| Creating, enabling, updating, and deleting model response guardrails | ai.guardrails.editor |
| Creating and connecting MCP servers | serverless.mcpGateways.editor and iam.serviceAccounts.user |
| Updating and deleting MCP servers | serverless.mcpGateways.editor |
| Creating, editing, and deleting workflows | serverless.workflows.editor |
| Creating an API key in the AI Studio UI | resource-manager.admin |
| Managing resource access | |
| Assigning a role, revoking a role, and viewing roles assigned for a folder | admin |
| Managing access to MCP servers | serverless.mcpGateways.admin |
| Managing access to workflows | serverless.workflows.admin |
Note
The search-api.executor, search-api.auditor, search-api.viewer, search-api.editor, and search-api.admin roles were previously used to work with the Yandex Search API API. These roles are deprecated and should no longer be used. To perform search queries, assign the search-api.webSearch.user role.