User and group permissions
A permission determines what operations a user can perform and on which group of resources. It consists of a scope and a role.
A permission can be assigned to different entities: a control panel user, a service user, or a group. Multiple permissions can be assigned to a single entity.
Permissions can be assigned:
- when adding a user or group;
- when editing a user or group.
Permissions can be exported as a JSON file and imported to other users or groups.
Scopes
A scope is a group of resources to which a permission is granted. A permission scope can be:
- account (
account) — all account resources, including the resources of all projects; - projects (
project) — resources of the selected projects.
Roles
A role is a set of predefined rights that determine what actions a user can perform on resources of a certain type or account settings. A role grants access within the scope specified in the permission.
Depending on the user type, roles can be assigned to them in different scopes. For more information about the capabilities of each role, see the Role reference guide.
Export user or group permissions
The permissions will be exported to a .json file.
Exported permissions can be imported:
- when adding a user or group;
- when editing a user or group.
Export user permissions
Export group permissions
-
In the control panel, in the top menu, click IAM.
-
Go to the section with the desired user type:
- Panel users — for users with access to the control panel;
- Service users — for service users.
-
Open the user page → Permissions and groups tab.
-
In the Permissions block, click Edit.
-
In the Access settings block, click Export.