---
title: Permission sets
description: Explore how to define and manage permission sets for user access control.
dates:
  validation: 2026-03-20
---

Permissions sets and their scope make up [IAM rules](/iam/concepts/#rule), which define the access rights that a principal (user, group or application) should have. They consist of sets of one or multiple [permissions](/iam/concepts/#permission).

Permission set names contain descriptions that clearly explain their purpose. For example, a permission set that grants access to all actions you can perform on Instances is called: `InstancesFullAccess`.

Below is a list of the permission sets available at Scaleway.

## Scoped by Organization

| Permission set                                                                                                                                        | Description                                                                                                                                        |
:----------------------------------------------------------------------------------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------------------------------------------------------------------------: |
| ProjectManager                                                                                                                                             | Full access to Project management. This means access to create, rename, list and delete projects. It does not include access to Project resources |
| ProjectReadOnly              | Read access to Project management. Does not include access to Project resources      |
| IAMReadOnly                  | Read access to IAM. This means list and read access to users, groups, applications, policies, and API keys                                                |
| IAMManager                   | Full access to IAM. This means access to all possible actions for users, groups, applications, policies and API keys and all ProjectManager permissions              |
| IAMApplicationManager        | Full access to IAM Applications, including management of Applications API keys             |
| IAMApplicationReadOnly       | Read access to IAM Applications, including listing Applications API keys                   |
| IAMUserManager               | Full access to IAM Users, including listing Users API keys                                 |
| IAMUserReadOnly              | Read access to IAM Users, including listing Users API keys                                 |
| IAMGroupManager              | Full access to IAM groups                                                                  |
| IAMGroupReadOnly             | Read access to IAM groups                                                                  |
| IAMPolicyManager             | Full access to IAM policies                                                                |
| IAMPolicyReadOnly            | Read access to IAM policies                                                                |
| BillingReadOnly              | List and read access to billing information                                                                                                        |
| BillingManager               | Full access to billing management. This means access to list, read and edit billing contact information, payment information, billing alerts and invoices |
| OrganizationManager          | Full access to Organization management. This means access to all possible actions for Projects, IAM, billing and support/abuse tickets. Does not include access to list and create resources                          |
| OrganizationReadOnly         | Read access to the Organization's general information (e.g. Organization ID and quotas)                                                                    |
| SupportTicketManager         | Full access to support tickets. This means access to create, read and update support tickets in the Organization                                                               |
| SupportTicketReadOnly        | List and read access to support tickets                                                                                                                             |
| AbuseTicketManager           | Full access to abuse tickets. This means access to create, read and update abuse tickets in the Organization                                                                   |
| AuditTrailReadOnly           | List and read access to Audit Trail events                                                                   |
| AuditTrailExportRead         | Read access to Audit Trail exports                                                         |
| AuditTrailExportDelete       | Delete access to Audit Trail exports                                                       |
| AuditTrailFullAccess         | Full access to Audit Trail                                                                 |
| EnvironmentalImpactReadOnly  | Read access to Environmental Impact information                                            |
| NotificationManagerFullAccess | Full access to the notification manager                                                   |
| NotificationManagerReadOnly  | Read access to the notification manager                                                       |

<Message type="important">
  Any user or application benefiting from the `IAMManager` and/or `OrganizationManager` permission sets is able to create policies giving themselves access to any other actions and resources within the Organization.
</Message>

## Scoped by Project

### Permission sets for several / all Products

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| AllProductsFullAccess        | Full access to create, read, list, edit and delete all resources (products)           |
| AllProductsReadOnly          | Read access to list and read info for all resources (products)                        |

### Compute

#### CPU & GPU Instances

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| InstancesFullAccess          | Full access to create, read, list, edit and delete Instances                          |
| InstancesReadOnly            | List and read access to Instances                                              |
| InstancesServerStart           | Allows starting Instance servers                                          |
| InstancesServerStop            | Allows stopping Instance servers                                         |
| SSHKeysReadOnly              | Read access to SSH keys                                                               |
| SSHKeysFullAccess            | Full access to SSH keys                                                               |

### Bare Metal

#### Elastic Metal

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| ElasticMetalReadOnly         | List and read access to Elastic Metal                                          |
| ElasticMetalFullAccess       | Full access to create, read, list, edit and delete Elastic Metal                      |
| SSHKeysReadOnly              | Read access to SSH keys                                                               |
| SSHKeysFullAccess            | Full access to SSH keys                                                               |

#### Apple silicon

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| AppleSiliconReadOnly         | List and read access to Apple silicon                                          |
| AppleSiliconFullAccess       | Full access to create, read, list, edit and delete Apple silicon.                     |
| SSHKeysReadOnly              | Read access to SSH keys                                                               |
| SSHKeysFullAccess            | Full access to SSH keys                                                               |

#### Dedibox

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| DediboxReadOnly              | List and read access to Dedibox                                               |
| DediboxFullAccess            | Full access to create, read, list, edit and delete Dedibox                            |
| DediboxConsoleFullAccess     | Access to Dedibox Console. Use this permission set only if a member needs access to Dedibox Console                        |

### Storage

#### Object Storage

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| ObjectStorageReadOnly        | List and read access to Object Storage                                        |
| ObjectStorageFullAccess      | Full access to create, read, list, edit and delete Object Storage                     |
| ObjectStorageObjectsRead     | Read access to objects, tags, metadata, and storage class                                  |
| ObjectStorageBucketsRead     | Read access to buckets and bucket configuration including lifecycle rules                    |
| ObjectStorageObjectsWrite    | Access to create and edit objects, tags, metadata, and storage class                                       |
| ObjectStorageObjectsDelete   | Access to delete objects	                     |
| ObjectStorageBucketsWrite    | Access to create and edit buckets, bucket configuration including lifecycle rules                                        |
| ObjectStorageBucketsDelete   | Access to delete buckets	                    |
| ObjectStorageBucketPolicyFullAccess  | Full access to object storage bucket policies               |


#### Block Storage

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| BlockStorageReadOnly         | List and read access to Block Storage                |
| BlockStorageFullAccess       | Full access to create, read, list, edit and delete in Block Storage            |


#### File Storage

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| FileStorageReadOnly         | Read access to File Storage                |
| FileStorageFullAccess       | Full access to File Storage            |



#### Container Registry

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| ContainerRegistryReadOnly    | List and read access to Container Registry                                    |
| ContainerRegistryFullAccess  | Full access to create, read, list, edit and delete Container Registry                 |

### Network

#### VPC

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| PrivateNetworksFullAccess    | Full access to create, read, list, edit and delete Private Networks                   |
| PrivateNetworksReadOnly      | Read access to Private Networks                   |
| VPCFullAccess                | Full access to VPC           |
| VPCReadOnly                  | Read access to VPC           |

#### IPAM

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| IPAMFullAccess               | Full access to IPAM           |
| IPAMReadOnly                 | Read access to IPAM          |

#### Public Gateways

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| VPCGatewayReadOnly           | List and read access to Public Gateways                                      |
| VPCGatewayFullAccess         | Full access to create, read, list, edit and delete Public Gateways                    |

#### InterLink

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| InterlinkFullAccess       | Full access to Interlink       |
| InterlinkReadOnly         | Read access to Interlink          |
| InterlinkPartnerReadOnly      | Read access to Interlink Partner   |
| InterlinkPartnerFullAccess         | Full access to Interlink Partner       |

#### Site-to-Site VPN

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| SiteToSiteVPNReadOnly      | Read access to Site-to-Site VPN      |
| SiteToSiteVPNFullAccess        | Full access to Site-to-Site VPN         |

#### Load Balancers

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| LoadBalancersReadOnly        | List and read access to Load Balancer                                         |
| LoadBalancersFullAccess      | Full access to create, read, list, edit and delete Load Balancer                      |

#### Edge Services

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| EdgeServicesFullAccess       | Full access to Edge Services         |
| EdgeServicesReadOnly         | Read access to Edge Services           |

### Containers

#### Kubernetes

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| KubernetesReadOnly           | List and read access to Kubernetes                                             |
| KubernetesFullAccess         | Full access to create, read, list, edit and delete Kubernetes                         |
| KubernetesExternalNodeRegister | Attach external nodes to a Kosmos cluster                         |
| KubernetesSystemMastersGroupAccess       | Gives the Kubernetes system:masters role to perform any action on the cluster           |

#### Container Registry

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| ContainerRegistryReadOnly    | List and read access to Container Registry                                    |
| ContainerRegistryFullAccess  | Full access to create, read, list, edit and delete Container Registry                 |

### Serverless Compute

#### Functions

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| FunctionsReadOnly            | List and read access to Functions                                              |
| FunctionsFullAccess          | Full access to create, read, list, edit and delete Functions                          |
| FunctionsPrivateAccess      | Call private functions                   |

#### Containers

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| ContainersReadOnly           | List and read access to Containers                                             |
| ContainersFullAccess         | Full access to create, read, list, edit and delete to Containers                      |
| ContainersPrivateAccess      | Call private containers                   |


#### Jobs

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| ServerlessJobsFullAccess     | Full access to create, read, list, edit and delete job definition/run. Does not include permissions for Container Registry and Secret Manager |
| ServerlessJobsReadOnly       | List and read access to job definition/run |

### Databases

#### PostgreSQL & MySQL

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| RelationalDatabasesReadOnly  | List and read access to Managed Database for PostgreSQL and MySQL                                             |
| RelationalDatabasesFullAccess| Full access to create, read, list, edit and delete Managed Database for PostgreSQL and MySQL |

#### ServerlessSQL

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| ServerlessSQLDatabaseReadOnly| List and read access to Serverless SQL Database |
| ServerlessSQLDatabaseReadWrite| List, read and write access to Serverless SQL Database. Includes data and table structure edition. Does not include permissions to create databases or edit settings |
| ServerlessSQLDatabaseDataReadWrite| Read, write, edit and delete data in Serverless SQL Database tables. Does not include data and table structure edition, creation of databases or settings edition |
| ServerlessSQLDatabaseFullAccess| Full access to create, read, list, edit and delete Serverless SQL Database |

#### Redis™

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| RedisReadOnly                | List and read access to Managed Database for Redis™                                   |
| RedisFullAccess              | Full access to create, read, list, edit and delete Managed Database for Redis™               |

#### MongoDB®

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| MongoDBReadOnly  | Read access to MongoDB databases                                          |
| MongoDBFullAccess | Full access to MongoDB databases |

#### OpenSearch

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| SearchDBReadOnly  | Read access to SearchDB services                                       |
| SearchDBFullAccess | Full access to SearchDB services |

### AI

#### Generative APIs - Serverless

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| GenerativeApisModelAccess            | Access to Generative APIs models.                          |
| GenerativeApisFullAccess            | Full access to Generative APIs.                            |

#### Generative APIs - Dedicated Deployment

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| InferenceReadOnly            | Read access to Inference deployments                           |
| InferenceFullAccess            | Full access to Inference deployments                           |

### Data & Analytics

#### Data Lab for Apache Spark™

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| DistributedDataLabReadOnly         | Read access to Data Warehouse service                        |
| DistributedDataLabFullAccess      | Full access to Data Warehouse service                     |

#### Data Warehouse for ClickHouse®

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| DataWarehouseReadOnly         | Read access to Data Warehouse service                        |
| DataWarehouseFullAccess      | Full access to Data Warehouse service                     |


#### Apache Kafka®

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| KafkaClusterReadOnly            | List and read access to Kafka Cluster   |
| KafkaClusterFullAccess            | Full access to Kafka Cluster   |

### Integration Services

#### Queues

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| MessagingAndQueuingReadOnly  | List and read access to Messaging                                             |
| MessagingAndQueuingFullAccess | Full access to create, read, list, edit and delete Messaging                          |


#### IoT Hub

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| IoTReadOnly                  | List and read access to IoT Hub                                               |
| IoTFullAccess                | Full access to create, read, list, edit and delete IoT Hub                            |

### Domains & Web Hosting

#### Domains & DNS

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| DomainsDNSReadOnly           | List and read access to Domains and DNS                                              |
| DomainsDNSFullAccess         | Full access to create, read, list, edit and delete Domains and DNS                          |

#### Web Hosting

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| WebHostingReadOnly           | List and read access to Web Hosting                                  |
| WebHostingFullAccess         | Full access to create, read, list, edit and delete Web Hosting               |

#### Transactional Emails

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| TransactionalEmailReadOnly   | List and read access to Transactional Email                                   |
| TransactionalEmailFullAccess | Full access to create, read, list, edit and delete Transactional Email                |
| TransactionalEmailBlocklistFullAccess  | Full access to blocklists in Transactional Email.                               |
| TransactionalEmailBlocklistReadOnly | Read access to blocklists in Transactional Email.               |
| TransactionalEmailDomainReadOnly  |  Read access to domains in Transactional Email. Does not include permissions for e-mails        |
| TransactionalEmailDomainFullAccess | Full access to domains in Transactional Email. Does not include permissions for e-mails              |
| TransactionalEmailEmailReadOnly | Read access to e-mails in Transactional Email. Does not include permissions for domain configuration               |
| TransactionalEmailEmailFullAccess | Full access to e-mails in Transactional Email. Does not include permissions for domain configuration              |
| TransactionalEmailWebhookFullAccess      | Full access to Webhooks in Transactional Email           |
| TransactionalEmailWebhookReadOnly      | Read access to Webhooks in Transactional Email             |
| TransactionalEmailProjectSettingsFullAccess    | Full access to Project settings in Transactional Email            |
| TransactionalEmailProjectSettingsReadOnly       | Read access to Project settings in Transactional Email       |
| TransactionalEmailEmailSmtpCreate   | Permission to create emails via SMTP           |
| TransactionalEmailEmailApiCreate       | Permission to create emails via the API     |
| TransactionalEmailOfferSubscriptionReadOnly  | Read access to project offer subscriptions in transactional email         |
| TransactionalEmailOfferSubscriptionFullAccess      | Full access to project offer subscriptions in transactional email    |
| TransactionalEmailPoolReadOnly  | Read access to project pool in transactional email     |

#### Mailbox

|  Permission set   |      Description       |
| :---------------: | :--------------------: |
| MailboxFullAccess | Full access to Mailbox |
|  MailboxReadOnly  | Read access to Mailbox |

### Monitoring

#### Cockpit

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| ObservabilityReadOnly        | List and read access to Observability                                         |
| ObservabilityFullAccess      | Full access to create, read, list, edit and delete Observability                      |


### Security & Identity

#### Secret Manager

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| SecretManagerReadOnly        | List and read secrets' metadata (name, tags, creation date, etc.). Does not include permissions for data (versions) accessing or editing                            |
| SecretManagerFullAccess      | Full access to create, read, list, edit, access, and delete secrets and their versions in Secret Manager                |
| SecretManagerSecretAccess    | Read access to versions' data in Secret Manager. Does not include permissions for data editing             |
| SecretManagerSecretCreate    | Permission to create secrets and their versions in Secret Manager. Does not include permission to update secrets and versions             |
| SecretManagerSecretDelete    | Permission to delete secrets and their versions in Secret Manager            |
| SecretManagerSecretWrite     | Permission to edit the metadata (name, tags, description, etc.) of secrets and their versions in Secret Manager. Does not include permission to create secrets and versions           |
| SecretManagerSecretRestore    | Restore permission on Secret Manager secrets and their versions         |

#### Key Manager

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| KeyManagerFullAccess       | Full access to create, read, list, edit and delete in Key Manager           |
| KeyManagerReadOnly       | List and read access to Key Manager            |
| KeyManagerKeyWrite      | Write permission to key manager. Does not include creation and deletion permission on keys           |
| KeyManagerKeyDecrypt    | Decrypt permission to key manager          |
| KeyManagerKeyEncrypt    | Encrypt permission to key manager           |
| KeyManagerKeySign    | Sign permission to key manager           |
| KeyManagerKeyVerify      | Verify permission to key manager           |
| KeyManagerKeyDelete     | Delete permission to key manager           |
| KeyManagerKeyCreate    | Create permission to key manager       |
| KeyManagerKeyRestore      | Restore permission to key manager           |

### Labs

#### Quantum

| Permission set               | Description                                                                           |
| :--------------------------: | :-----------------------------------------------------------------------------------: |
| QaaSFullAccess       | Full access to Quantum as a Service        |
| QaaSReadOnly       | Read access to Quantum as a Service        |

<Message type="important">
  Some additional permission sets may appear on your Scaleway console if you are enrolled in beta testing for products or features.
</Message>
