Skip to navigationSkip to main contentSkip to footerScaleway DocsAsk our AI
Ask our AI

Permission sets

Permissions sets and their scope make up IAM rules, which define the access rights that a principal (user, group or application) should have. They consist of sets of one or multiple permissions.

Permission set names contain descriptions that clearly explain their purpose. For example, a permission set that grants access to all actions you can perform on Instances is called: InstancesFullAccess.

Below is a list of the permission sets available at Scaleway.

Scoped by Organization

Permission setDescription
ProjectManagerFull access to Project management. This means access to create, rename, list and delete projects. It does not include access to Project resources
ProjectReadOnlyRead access to Project management. Does not include access to Project resources
IAMReadOnlyRead access to IAM. This means list and read access to users, groups, applications, policies, and API keys
IAMManagerFull access to IAM. This means access to all possible actions for users, groups, applications, policies and API keys and all ProjectManager permissions
IAMApplicationManagerFull access to IAM Applications, including management of Applications API keys
IAMApplicationReadOnlyRead access to IAM Applications, including listing Applications API keys
IAMUserManagerFull access to IAM Users, including listing Users API keys
IAMUserReadOnlyRead access to IAM Users, including listing Users API keys
IAMGroupManagerFull access to IAM groups
IAMGroupReadOnlyRead access to IAM groups
IAMPolicyManagerFull access to IAM policies
IAMPolicyReadOnlyRead access to IAM policies
BillingReadOnlyList and read access to billing information
BillingManagerFull access to billing management. This means access to list, read and edit billing contact information, payment information, billing alerts and invoices
OrganizationManagerFull access to Organization management. This means access to all possible actions for Projects, IAM, billing and support/abuse tickets. Does not include access to list and create resources
OrganizationReadOnlyRead access to the Organization's general information (e.g. Organization ID and quotas)
SupportTicketManagerFull access to support tickets. This means access to create, read and update support tickets in the Organization
SupportTicketReadOnlyList and read access to support tickets
AbuseTicketManagerFull access to abuse tickets. This means access to create, read and update abuse tickets in the Organization
AuditTrailReadOnlyList and read access to Audit Trail events
AuditTrailExportReadRead access to Audit Trail exports
AuditTrailExportDeleteDelete access to Audit Trail exports
AuditTrailFullAccessFull access to Audit Trail
EnvironmentalImpactReadOnlyRead access to Environmental Impact information
NotificationManagerFullAccessFull access to the notification manager
NotificationManagerReadOnlyRead access to the notification manager
Important

Any user or application benefiting from the IAMManager and/or OrganizationManager permission sets is able to create policies giving themselves access to any other actions and resources within the Organization.

Scoped by Project

Permission sets for several / all Products

Permission setDescription
AllProductsFullAccessFull access to create, read, list, edit and delete all resources (products)
AllProductsReadOnlyRead access to list and read info for all resources (products)
SSHKeysReadOnlyRead access to SSH keys
SSHKeysFullAccessFull access to SSH keys

Compute

CPU & GPU Instances

Permission setDescription
InstancesFullAccessFull access to create, read, list, edit and delete Instances
InstancesReadOnlyList and read access to Instances
InstancesServerStartAllows starting Instance servers
InstancesServerStopAllows stopping Instance servers

Bare Metal

Elastic Metal

Permission setDescription
ElasticMetalReadOnlyList and read access to Elastic Metal
ElasticMetalFullAccessFull access to create, read, list, edit and delete Elastic Metal

Apple silicon

Permission setDescription
AppleSiliconReadOnlyList and read access to Apple silicon
AppleSiliconFullAccessFull access to create, read, list, edit and delete Apple silicon.

Dedibox

Permission setDescription
DediboxReadOnlyList and read access to Dedibox
DediboxFullAccessFull access to create, read, list, edit and delete Dedibox
DediboxConsoleFullAccessAccess to Dedibox Console. Use this permission set only if a member needs access to Dedibox Console

Storage

Object Storage

Permission setDescription
ObjectStorageReadOnlyList and read access to Object Storage
ObjectStorageFullAccessFull access to create, read, list, edit and delete Object Storage
ObjectStorageObjectsReadRead access to objects, tags, metadata, and storage class
ObjectStorageBucketsReadRead access to buckets and bucket configuration including lifecycle rules
ObjectStorageObjectsWriteAccess to create and edit objects, tags, metadata, and storage class
ObjectStorageObjectsDeleteAccess to delete objects
ObjectStorageBucketsWriteAccess to create and edit buckets, bucket configuration including lifecycle rules
ObjectStorageBucketsDeleteAccess to delete buckets
ObjectStorageBucketPolicyFullAccessFull access to object storage bucket policies

Block Storage

Permission setDescription
BlockStorageReadOnlyList and read access to Block Storage
BlockStorageFullAccessFull access to create, read, list, edit and delete in Block Storage

File Storage

Permission setDescription
FileStorageReadOnlyRead access to File Storage
FileStorageFullAccessFull access to File Storage

Container Registry

Permission setDescription
ContainerRegistryReadOnlyList and read access to Container Registry
ContainerRegistryFullAccessFull access to create, read, list, edit and delete Container Registry

Network

VPC

Permission setDescription
PrivateNetworksFullAccessFull access to create, read, list, edit and delete Private Networks
PrivateNetworksReadOnlyRead access to Private Networks
VPCFullAccessFull access to VPC
VPCReadOnlyRead access to VPC

IPAM

Permission setDescription
IPAMFullAccessFull access to IPAM
IPAMReadOnlyRead access to IPAM

Public Gateways

Permission setDescription
VPCGatewayReadOnlyList and read access to Public Gateways
VPCGatewayFullAccessFull access to create, read, list, edit and delete Public Gateways
Permission setDescription
InterlinkFullAccessFull access to Interlink
InterlinkReadOnlyRead access to Interlink
InterlinkPartnerReadOnlyRead access to Interlink Partner
InterlinkPartnerFullAccessFull access to Interlink Partner

Site-to-Site VPN

Permission setDescription
SiteToSiteVPNReadOnlyRead access to Site-to-Site VPN
SiteToSiteVPNFullAccessFull access to Site-to-Site VPN

Load Balancers

Permission setDescription
LoadBalancersReadOnlyList and read access to Load Balancer
LoadBalancersFullAccessFull access to create, read, list, edit and delete Load Balancer

Edge Services

Permission setDescription
EdgeServicesFullAccessFull access to Edge Services
EdgeServicesReadOnlyRead access to Edge Services

Containers

Kubernetes

Permission setDescription
KubernetesReadOnlyList and read access to Kubernetes
KubernetesFullAccessFull access to create, read, list, edit and delete Kubernetes
KubernetesExternalNodeRegisterAttach external nodes to a Kosmos cluster
KubernetesSystemMastersGroupAccessGives the Kubernetes system:masters role to perform any action on the cluster

Container Registry

Permission setDescription
ContainerRegistryReadOnlyList and read access to Container Registry
ContainerRegistryFullAccessFull access to create, read, list, edit and delete Container Registry

Serverless Compute

Functions

Permission setDescription
FunctionsReadOnlyList and read access to Functions
FunctionsFullAccessFull access to create, read, list, edit and delete Functions
FunctionsPrivateAccessCall private functions

Containers

Permission setDescription
ContainersReadOnlyList and read access to Containers
ContainersFullAccessFull access to create, read, list, edit and delete to Containers
ContainersPrivateAccessCall private containers

Jobs

Permission setDescription
ServerlessJobsFullAccessFull access to create, read, list, edit and delete job definition/run. Does not include permissions for Container Registry and Secret Manager
ServerlessJobsReadOnlyList and read access to job definition/run

Databases

PostgreSQL & MySQL

Permission setDescription
RelationalDatabasesReadOnlyList and read access to Managed Database for PostgreSQL and MySQL
RelationalDatabasesFullAccessFull access to create, read, list, edit and delete Managed Database for PostgreSQL and MySQL

ServerlessSQL

Permission setDescription
ServerlessSQLDatabaseReadOnlyList and read access to Serverless SQL Database
ServerlessSQLDatabaseReadWriteList, read and write access to Serverless SQL Database. Includes data and table structure edition. Does not include permissions to create databases or edit settings
ServerlessSQLDatabaseDataReadWriteRead, write, edit and delete data in Serverless SQL Database tables. Does not include data and table structure edition, creation of databases or settings edition
ServerlessSQLDatabaseFullAccessFull access to create, read, list, edit and delete Serverless SQL Database

Redis™

Permission setDescription
RedisReadOnlyList and read access to Managed Database for Redis™
RedisFullAccessFull access to create, read, list, edit and delete Managed Database for Redis™

MongoDB®

Permission setDescription
MongoDBReadOnlyRead access to MongoDB databases
MongoDBFullAccessFull access to MongoDB databases

OpenSearch

Permission setDescription
SearchDBReadOnlyRead access to SearchDB services
SearchDBFullAccessFull access to SearchDB services

AI

Generative APIs

Permission setDescription
GenerativeApisModelAccessAccess to Generative APIs models.
GenerativeApisFullAccessFull access to Generative APIs.

Managed Inference

Permission setDescription
InferenceReadOnlyRead access to Inference deployments
InferenceFullAccessFull access to Inference deployments

Data & Analytics

Data Lab for Apache Spark™

Permission setDescription
DistributedDataLabReadOnlyRead access to Data Warehouse service
DistributedDataLabFullAccessFull access to Data Warehouse service

Data Warehouse for ClickHouse®

Permission setDescription
DataWarehouseReadOnlyRead access to Data Warehouse service
DataWarehouseFullAccessFull access to Data Warehouse service

Apache Kafka®

Permission setDescription
KafkaClusterReadOnlyList and read access to Kafka Cluster
KafkaClusterFullAccessFull access to Kafka Cluster

Integration Services

Queues

Permission setDescription
MessagingAndQueuingReadOnlyList and read access to Messaging
MessagingAndQueuingFullAccessFull access to create, read, list, edit and delete Messaging

IoT Hub

Permission setDescription
IoTReadOnlyList and read access to IoT Hub
IoTFullAccessFull access to create, read, list, edit and delete IoT Hub

Domains & Web Hosting

Domains & DNS

Permission setDescription
DomainsDNSReadOnlyList and read access to Domains and DNS
DomainsDNSFullAccessFull access to create, read, list, edit and delete Domains and DNS

Web Hosting

Permission setDescription
WebHostingReadOnlyList and read access to Web Hosting
WebHostingFullAccessFull access to create, read, list, edit and delete Web Hosting

Transactional Emails

Permission setDescription
TransactionalEmailReadOnlyList and read access to Transactional Email
TransactionalEmailFullAccessFull access to create, read, list, edit and delete Transactional Email
TransactionalEmailBlocklistFullAccessFull access to blocklists in Transactional Email.
TransactionalEmailBlocklistReadOnlyRead access to blocklists in Transactional Email.
TransactionalEmailDomainReadOnlyRead access to domains in Transactional Email. Does not include permissions for e-mails
TransactionalEmailDomainFullAccessFull access to domains in Transactional Email. Does not include permissions for e-mails
TransactionalEmailEmailReadOnlyRead access to e-mails in Transactional Email. Does not include permissions for domain configuration
TransactionalEmailEmailFullAccessFull access to e-mails in Transactional Email. Does not include permissions for domain configuration
TransactionalEmailWebhookFullAccessFull access to Webhooks in Transactional Email
TransactionalEmailWebhookReadOnlyRead access to Webhooks in Transactional Email
TransactionalEmailProjectSettingsFullAccessFull access to Project settings in Transactional Email
TransactionalEmailProjectSettingsReadOnlyRead access to Project settings in Transactional Email
TransactionalEmailEmailSmtpCreatePermission to create emails via SMTP
TransactionalEmailEmailApiCreatePermission to create emails via the API
TransactionalEmailOfferSubscriptionReadOnlyRead access to project offer subscriptions in transactional email
TransactionalEmailOfferSubscriptionFullAccessFull access to project offer subscriptions in transactional email
TransactionalEmailPoolReadOnlyRead access to project pool in transactional email

Monitoring

Cockpit

Permission setDescription
ObservabilityReadOnlyList and read access to Observability
ObservabilityFullAccessFull access to create, read, list, edit and delete Observability

Security & Identity

Secret Manager

Permission setDescription
SecretManagerReadOnlyList and read secrets' metadata (name, tags, creation date, etc.). Does not include permissions for data (versions) accessing or editing
SecretManagerFullAccessFull access to create, read, list, edit, access, and delete secrets and their versions in Secret Manager
SecretManagerSecretAccessRead access to versions' data in Secret Manager. Does not include permissions for data editing
SecretManagerSecretCreatePermission to create secrets and their versions in Secret Manager. Does not include permission to update secrets and versions
SecretManagerSecretDeletePermission to delete secrets and their versions in Secret Manager
SecretManagerSecretWritePermission to edit the metadata (name, tags, description, etc.) of secrets and their versions in Secret Manager. Does not include permission to create secrets and versions
SecretManagerSecretRestoreRestore permission on Secret Manager secrets and their versions

Key Manager

Permission setDescription
KeyManagerFullAccessFull access to create, read, list, edit and delete in Key Manager
KeyManagerReadOnlyList and read access to Key Manager
KeyManagerKeyWriteWrite permission to key manager. Does not include creation and deletion permission on keys
KeyManagerKeyDecryptDecrypt permission to key manager
KeyManagerKeyEncryptEncrypt permission to key manager
KeyManagerKeySignSign permission to key manager
KeyManagerKeyVerifyVerify permission to key manager
KeyManagerKeyDeleteDelete permission to key manager
KeyManagerKeyCreateCreate permission to key manager
KeyManagerKeyRestoreRestore permission to key manager

Labs

Quantum

Permission setDescription
QaaSFullAccessFull access to Quantum as a Service
QaaSReadOnlyRead access to Quantum as a Service
Important

Some additional permission sets may appear on your Scaleway console if you are enrolled in beta testing for products or features.

Still need help?

Create a support ticket
No Results