Yandex Cloud
Search
Contact UsGet started
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI for business
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
Yandex Identity and Access Management
    • Overview
      • Overview
      • Roles
      • System groups
      • Public groups
      • Resources that roles can be assigned for
      • Impersonation
    • Service access to user resources
    • Identity federations
    • Workload identity federations
    • Quotas and limits
  • Secure use of Yandex Cloud
  • Access management
  • Pricing policy
  • Role reference
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes

In this article:

  • Role reference
  • Use cases
  1. Concepts
  2. How access management works
  3. Roles

Roles

Written by
Yandex Cloud
Updated at May 27, 2025
  • Role reference
  • Use cases

A role is a set of permissions to perform operations with resources in Yandex Cloud.

There are two types of roles:

  • Primitive roles contain permissions that apply to all types of Yandex Cloud resources. These are roles such as admin, editor, viewer, and auditor.

  • Service roles contain permissions only for a specific type of resource in a particular service. The service role ID is specified in service.resources.role format. For example, the compute.images.user role allows you to use images in Yandex Compute Cloud.

    A service role can be assigned for the resource the role is intended for or the one from which the permissions are inherited. For example, you can assign the compute.images.user role for a folder or cloud, because images inherit permissions from them.

Currently, users are not allowed to create new roles with a custom set of permissions.

Role referenceRole reference

Starting February 14, 2024, you can find the extended list of roles for all Yandex Cloud services on this page: Yandex Cloud role reference.

Use casesUse cases

  • Access control for user groups with different roles in Yandex Identity Hub
  • Using a service account with an OS Login profile for VM management via Ansible

Was the article helpful?

Previous
Overview
Next
System groups
© 2025 Direct Cursus Technology L.L.C.