Skip to main content

Manage audit log access

Access to audit logs is governed by a role-based access model that determines access within an account and project. For more information, see the Access management in Selectel products instructions.

member

A user with full access to all services. Has no access to managing: users, service users, user groups, and federations.

Access scopes
  • Account;
  • Project
Can be assigned to
  • Users;
  • service users;
  • user groups
Available operations with audit logs

In the Account access scope:

  • audit log download

In the Project access scope, audit log operations are unavailable

iam.admin

A user with access to user management and without access to services and billing. Cannot manage their account: change permissions, manage notifications, or delete the user. The first user with the iam.admin role is created by the Account Owner.

Access scopesAccount
Can be assigned to
  • Users;
  • service users;
  • user groups
Available operations with audit logs

iam.viewer

A user with access to view everything managed by iam.admin.

Access scopesAccount
Can be assigned to
  • Users;
  • service users;
  • user groups
Available operations with audit logsViewing control panel users, service users, user groups with access to audit logs, as well as viewing federations

audit_logs.admin

A user with access to audit logs. Has no access to other products. For more information, see the Manage access to audit logs instructions.

Access scopes
  • Account
Can be assigned to
  • Users;
  • service users;
  • user groups
Available operations
  • Audit log download