Skip to main content

Manage audit log access

Access to audit logs is governed by a role model that defines access within an account and project. For more information, see the Access Control in Selectel Products manual.

member

User with full access to all services. Does not have access to manage: users, service users, user groups and federations.

Access scopes
  • Account;
  • Project
Can be assigned to
  • Users;
  • service users;
  • user groups
Available operations with audit logs

In the Account access scope:

  • audit log download

In the Project access scope, audit log operations are unavailable

iam.admin

User with access to manage users and no access to services or billing. Cannot manage their own account: change permissions, manage notifications, or delete the user. The first user with the iam.admin role is created by the Account Owner.

Access scopesAccount
Can be assigned to
  • Users;
  • service users;
  • user groups
Available operations with audit logs

iam.viewer

A user with access to view everything managed by iam.admin.

Access scopesAccount
Can be assigned to
  • Users;
  • service users;
  • user groups
Available operations with audit logsView panel users, service users, user groups with access to audit logs, and view federations

audit_logs.admin

User with access to audit logs. Does not have access to other products. For more information, see the Manage access to audit logs manual.

Access scopes
  • Account
Can be assigned to
  • Users;
  • service users;
  • user groups
Available operations
  • Audit log download