---
title: "Manage cloud server network volume access and snapshots"
sidebar_label: "Manage network volume access and snapshots"
sidebar_position: 2
description: "How cloud server network volume access and snapshots are governed by a role model"
---

import Formbricks from '@theme/MDXComponents/Formbricks'
import Tabs from '@theme/Tabs'
import TabItem from '@theme/TabItem'
import {TabItemLabel} from '@selectel/docux/components'
import {CustomTable} from '@selectel/docux/components'

# Manage access to cloud server network volumes and snapshots

Access to cloud server network volumes and snapshots is governed by a role-based access control model that defines access within an account and [project](/access-control/projects/about-projects.mdx). Read more in the [Access Control in Selectel Products](/access-control/access-management.mdx) manual.

## member \{#member}

A user with full access to all services. Does not have access to manage: [users](/access-control/manage/), [service users](/access-control/user-types.mdx#service-users), [user groups](/access-control/groups/), and [federations](/access-control/federations/).

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th>

        <td>
          * account;
          * project
        </td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th rowspan="2">Available operations with cloud server network volumes and snapshots</th>

        <td>
          In the Account access scope:

          * view a list of all network volumes and information about them: disk type, disk size, connected backup plans, created snapshots;
          * view general disk statistics;
          * create disks:
          * manage disks;
          * manage connected backup plans;
          * view a list of all snapshots: snapshot size, creation date, and status;
          * create and manage disk snapshots
        </td>
      </tr>

      <tr>
        <td>
          In the Project access scope:

          * view a list of all network volumes and information about them: disk type, disk size, connected backup plans, created snapshots;
          * view general disk statistics;
          * create disks;
          * manage disks;
          * manage connected backup plans;
          * view a list of all snapshots: snapshot size, creation date, and status;
          * create and manage disk snapshots
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## reader \{#reader}

User with access to view everything managed by [`member`](#member) in the same access scope.

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th>

        <td>
          * account;
          * project
        </td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th rowspan="2">Available operations with cloud server network volumes and snapshots</th>

        <td>
          In the Account access scope:

          * view a list of all network volumes and information about them in account projects: disk type, disk size, connected backup plans, created snapshots;
          * view general disk statistics;
          * view a list of all snapshots: snapshot size, creation date, and status
        </td>
      </tr>

      <tr>
        <td>
          In the Project access scope:

          * view a list of all network volumes and information about them in your project: disk type, disk size, connected backup plans, created snapshots;
          * view general disk statistics;
          * view a list of all snapshots: snapshot size, creation date, and status
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## billing \{#billing}

User with access to billing management and no access to service management.

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th><td>Account</td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th>Available operations with cloud server network volumes and snapshots</th>

        <td>
          * billing management
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## iam.admin \{#iam-admin}

A user with access to manage users and no access to services and billing. Cannot manage their account: modify permissions, manage notifications, delete the user. The first user with the `iam.admin` role is created by the [Account Owner](/access-control/user-types.mdx#account-owner).

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th><td>Account</td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th>Available operations with cloud server network volumes and snapshots</th>

        <td>
          * manage [users](/access-control/user-types.mdx#users), [service users](/access-control/user-types.mdx#service-users), [user groups](/access-control/groups/) with access to cloud server network volumes;
          * manage [federations](/access-control/federations/)
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## iam.viewer \{#iam-viewer}

User with access to view everything managed by [iam.admin](#iam-admin).

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th><td>Account</td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th>Available operations with cloud server network volumes and snapshots</th>

        <td>
          * view [users](/access-control/user-types.mdx#users), [service users](/access-control/user-types.mdx#service-users), [user groups](/access-control/groups/) and [federations](/access-control/federations/);
          * view user keys;
          * viewing [notifications](/account/notifications.mdx) of other users;
          * viewing [account access restrictions](/account/limit-access-to-account.mdx)
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## compute.volume.admin \{#compute-volume-admin}

A user with access to manage cloud server network volumes. Does not have access to other products.

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th>

        <td>
          * account;
          * project
        </td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th rowspan="2">Available operations with cloud server network volumes</th>

        <td>
          In the Account access scope:

          * view a list of all network volumes and information about them: disk type, disk size;
          * create disks;
          * manage disks;
          * move disks between projects;
          * view disk migration information
        </td>
      </tr>

      <tr>
        <td>
          In the Project access scope:

          * view a list of all network volumes and information about them: disk type, disk size;
          * create disks;
          * manage disks;
          * move disks between projects;
          * view disk migration information
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## compute.volume.user \{#compute-volume-user}

A user with access to manage cloud server network volumes. Does not have access to other products in their project or to network volumes in other projects.

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th>

        <td>
          * account;
          * project
        </td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th rowspan="2">Available operations with cloud server network volumes</th>

        <td>
          In the Account access scope:

          * view a list of all network volumes and information about them: disk type, disk size;
          * create disks;
          * manage disks
        </td>
      </tr>

      <tr>
        <td>
          In the Project access scope:

          * view a list of all network volumes and information about them: disk type, disk size;
          * create disks;
          * manage disks
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## compute.volume.viewer \{#compute-volume-viewer}

A user with access to view network volumes. Does not have access to other products.

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th>

        <td>
          * account;
          * project
        </td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th rowspan="2">Available operations with cloud server network volumes</th>

        <td>
          In the Account access scope:

          * view a list of all network volumes and information about them: disk type, disk size
        </td>
      </tr>

      <tr>
        <td>
          In the Project access scope:

          * view a list of all network volumes and information about them: disk type, disk size
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## compute.snapshot.admin \{#compute-snapshot-admin}

A user with access to manage network volume snapshots. Does not have access to other products.

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th>

        <td>
          * account;
          * project
        </td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th rowspan="2">Available operations with snapshots</th>

        <td>
          In the Account access scope:

          * view a list of all snapshots: snapshot size, creation date, and status;
          * create snapshots;
          * manage snapshots
        </td>
      </tr>

      <tr>
        <td>
          In the Project access scope:

          * view a list of all snapshots: snapshot size, creation date, and status;
          * create snapshots;
          * manage snapshots
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## compute.snapshot.viewer \{#compute-snapshot-viewer}

A user with access to view network volume snapshots. Does not have access to other products.

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Access scopes</th>

        <td>
          * account;
          * project
        </td>
      </tr>

      <tr>
        <th>Who can be assigned</th>

        <td>
          * users;
          * service users;
          * user groups
        </td>
      </tr>

      <tr>
        <th rowspan="2">Available operations with snapshots</th>

        <td>
          In the Account access scope:

          * view a list of all snapshots: snapshot size, creation date, and status
        </td>
      </tr>

      <tr>
        <td>
          In the Project access scope:

          * view a list of all snapshots: snapshot size, creation date, and status
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

<Formbricks />
