Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity and Access Management
  • Secure use of Yandex Cloud
  • Access management
  • Pricing policy
  • Role reference
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes

In this article:

  • August 2026
  • Identity and Access Management updates
  • New roles
  • July 2026
  • Identity and Access Management updates
  • New roles
  • June 2026
  • Identity and Access Management updates
  • New roles
  • May 2026
  • Identity and Access Management updates
  • New roles
  • April 2026
  • Identity and Access Management updates
  • New roles
  • March 2026
  • New roles
  • February 2026
  • Identity and Access Management updates
  • New roles
  • December 2025
  • Identity and Access Management updates
  • New roles
  • November 2025
  • Identity and Access Management updates
  • New roles
  • October 2025
  • Identity and Access Management updates
  • New roles
  • Q3 2025
  • Q2 2025
  • Q1 2025
  • Q4 2024
  • Q3 2024
  • Q2 2024
  • Q1 2024

Yandex Identity and Access Management release notes

Written by
Yandex Cloud
Updated at October 6, 2026
View in Markdown
  • August 2026
    • Identity and Access Management updates
    • New roles
  • July 2026
    • Identity and Access Management updates
    • New roles
  • June 2026
    • Identity and Access Management updates
    • New roles
  • May 2026
    • Identity and Access Management updates
    • New roles
  • April 2026
    • Identity and Access Management updates
    • New roles
  • March 2026
    • New roles
  • February 2026
    • Identity and Access Management updates
    • New roles
  • December 2025
    • Identity and Access Management updates
    • New roles
  • November 2025
    • Identity and Access Management updates
    • New roles
  • October 2025
    • Identity and Access Management updates
    • New roles
  • Q3 2025
  • Q2 2025
  • Q1 2025
  • Q4 2024
  • Q3 2024
  • Q2 2024
  • Q1 2024

August 2026August 2026

Identity and Access Management updatesIdentity and Access Management updates

  • The compute.editor and compute.admin roles in Compute Cloud, as well as the baremetal.editor and baremetal.admin in BareMetal now include permissions of the backup.user role.

New rolesNew roles

Yandex Cloud Billing

billing.usagerecords.adminbilling.usagerecords.admin

To use the billing.usagerecords.admin role, you need to assign it for an organization, cloud, or folder. It enables viewing resource consumption details without access to the billing account.

Yandex Managed Service for ClickHouse®

managed-clickhouse.clusters.connectormanaged-clickhouse.clusters.connector

The managed-clickhouse.clusters.connector role enables Yandex Cloud users to connect to databases in ClickHouse® clusters via Yandex Identity and Access Management.

Yandex Managed Service for GitLab

gitlab.backupAdmingitlab.backupAdmin

The gitlab.backupAdmin role enables completely managing Managed Service for GitLab instance backups. Users with this role can create and delete backups, restore instances from them, as well as download backups, including GitLab secrets from such backups.

This role includes the gitlab.backupRestorer and gitlab.backupDownloader permissions.

gitlab.backupDownloadergitlab.backupDownloader

The gitlab.backupDownloader role enables downloading Managed Service for GitLab instance backups, including GitLab secrets from such backups.

gitlab.backupRestorergitlab.backupRestorer

The gitlab.backupRestorer role enables restoring Managed Service for GitLab instances from backups.

July 2026July 2026

Identity and Access Management updatesIdentity and Access Management updates

  • Added the ability to suspend a service account and manage its lifetime.
  • Added the resourceManager.denyFolderRemoval authorization policy template that allows you to prohibit folder deletion.
  • Added the aistudio.responses.restrictNetworkAccess authorization policy template that allows restricting access to the Responses API in Yandex Cloud AI Studio by IP addresses and cloud networks.

New rolesNew roles

Yandex Cloud Registry

cloud-registry.artifacts.scannercloud-registry.artifacts.scanner

The cloud-registry.artifacts.scanner role enables scanning registry artifacts for vulnerabilities, pulling artifacts, as well as viewing info on artifacts and registries, on the access permissions granted for registries, and on the Cloud Registry quotas.

Users with this role can:

  • Scan registry artifacts for vulnerabilities.
  • View vulnerability scanning results.
  • View info on artifacts and pull them.
  • View info on registries.
  • View registry access policies.
  • View info on the access permissions granted for registries, folders within registries, and artifacts.
  • View info on registry lifecycle policies.
  • View info on the Cloud Registry quotas.
  • View info on the relevant cloud and folder.

This role includes the cloud-registry.viewer permissions.

Yandex Security Deck

threat-detector.adminthreat-detector.admin

The threat-detector.admin role enables viewing info on Threat Detector security management rules, creating exceptions from such rules, as well as viewing info on access permissions granted for Threat Detector and modifying them.

This role includes the threat-detector.editor permissions.

threat-detector.auditorthreat-detector.auditor

The threat-detector.auditor role enables viewing info on Threat Detector security management rules and access permissions granted for Threat Detector.

threat-detector.editorthreat-detector.editor

The threat-detector.editor role enables viewing info on access permissions granted for Threat Detector and its security management rules, as well as creating exceptions from such rules.

This role includes the threat-detector.viewer permissions.

threat-detector.viewerthreat-detector.viewer

The threat-detector.viewer role enables viewing info on Threat Detector security management rules and access permissions granted for Threat Detector.

This role includes the threat-detector.auditor permissions.

threat-detector.workerthreat-detector.worker

The threat-detector.worker enables viewing logs registered in the customer's infrastructure using Yandex Audit Trails.

The role is issued to the service account to perform Threat Detector-driven security management and extends to an organization, cloud, or folder. This service account should be specified when creating the workspace.

vulnerability-manager.adminvulnerability-manager.admin

The vulnerability-manager.admin role enables viewing info on Vulnerability Management scan jobs, running and modifying them, as well as viewing their results.

This role includes the vulnerability-manager.editor permissions.

vulnerability-manager.auditorvulnerability-manager.auditor

The vulnerability-manager.auditor role enables viewing Vulnerability Management scan results.

vulnerability-manager.editorvulnerability-manager.editor

The vulnerability-manager.editor enables viewing info on Vulnerability Management scan jobs, running and modifying them, as well as viewing their results.

This role includes the vulnerability-manager.viewer permissions.

vulnerability-manager.viewervulnerability-manager.viewer

The vulnerability-manager.viewer enables viewing info on Vulnerability Management scan jobs and their results.

This role includes the vulnerability-manager.auditor permissions.

Yandex StoreDoc

managed-mongodb.clusters.connectormanaged-mongodb.clusters.connector

The managed-mongodb.clusters.connector role enables Yandex Cloud users to connect to databases in Yandex StoreDoc clusters via Yandex Identity and Access Management.

June 2026June 2026

Identity and Access Management updatesIdentity and Access Management updates

  • Added the resourceManager.denyCloudRemoval access policy template that allows you to prohibit cloud deletion.

New rolesNew roles

Apache Hive™ Metastore

managed-metastore.maintenanceTask.editormanaged-metastore.maintenanceTask.editor

The managed-metastore.maintenanceTask.editor role enables viewing info on maintenance tasks for Apache Hive™ Metastore clusters and modifying such tasks, as well as viewing info on Apache Hive™ Metastore clusters, on access permissions granted for them, and on the quotas for Yandex Cloud managed DB services.

This role includes the managed-metastore.maintenanceTask.viewer permissions.

managed-metastore.maintenanceTask.viewermanaged-metastore.maintenanceTask.viewer

The managed-metastore.maintenanceTask.viewer role enables viewing info on Apache Hive™ Metastore clusters, access permissions granted for them, their maintenance tasks, and on the quotas for Yandex Cloud managed DB services.

Yandex DataLens

datalens.collections.creatordatalens.collections.creator

The datalens.collections.creator is assigned for a collection and enables viewing it as well as creating objects within it without access to any other objects residing within the collection. In the DataLens UI, this role is referred to as Creator in collection. We recommend assigning this role only via the DataLens UI.

This role includes the datalens.collections.visitor permissions.

datalens.collections.entryBindingCreatordatalens.collections.entryBindingCreator

The datalens.collections.entryBindingCreator role is assigned for a collection and enables re-using common objects from it, both with and without delegation of access permissions. In the DataLens UI, this role is referred to as Bindings with delegation. We recommend assigning this role only via the DataLens UI.

This role includes the datalens.sharedEntries.entryBindingCreator permissions.

datalens.collections.limitedEntryBindingCreatordatalens.collections.limitedEntryBindingCreator

The datalens.collections.limitedEntryBindingCreator role is assigned for a collection and enables re-using common objects from it without delegation of access permissions. In the DataLens UI, this role is referred to as Bindings without delegation. We recommend assigning this role only via the DataLens UI.

This role includes the datalens.sharedEntries.limitedEntryBindingCreator permissions.

datalens.collections.visitordatalens.collections.visitor

The datalens.collections.visitor is assigned for a collection and enables viewing info on it without access to its nested objects. In the DataLens UI, this role is referred to as Visitor of collection. We recommend assigning this role only via the DataLens UI.

datalens.sharedEntries.admindatalens.sharedEntries.admin

The datalens.sharedEntries.admin role is assigned for a common object and enables viewing it and entirely managing it, including editing, moving, deleting, and configuring its access permissions. In the DataLens UI, this role is referred to as Admin. We recommend assigning this role only via the DataLens UI.

This role includes the datalens.sharedEntries.editor and datalens.sharedEntries.entryBindingCreator permissions.

datalens.sharedEntries.editordatalens.sharedEntries.editor

The datalens.sharedEntries.editor role is assigned for a common object and enables editing and viewing it, as well as viewing its access permissions. In the DataLens UI, this role is referred to as Editor. We recommend assigning this role only via the DataLens UI.

This role includes the datalens.sharedEntries.viewer permissions.

datalens.sharedEntries.entryBindingCreatordatalens.sharedEntries.entryBindingCreator

The datalens.sharedEntries.entryBindingCreator role is assigned for a common object and enables re-using it in workbooks, both with and without delegation of access permissions. In the DataLens UI, this role is referred to as Bindings with delegation. We recommend assigning this role only via the DataLens UI.

This role includes the datalens.sharedEntries.limitedEntryBindingCreator permissions.

datalens.sharedEntries.limitedEntryBindingCreatordatalens.sharedEntries.limitedEntryBindingCreator

The datalens.sharedEntries.limitedEntryBindingCreator role is assigned for a common object and enables re-using it in workbooks without delegation of access permissions. In the DataLens UI, this role is referred to as Bindings without delegation. We recommend assigning this role only via the DataLens UI.

datalens.sharedEntries.limitedViewerdatalens.sharedEntries.limitedViewer

The datalens.sharedEntries.limitedViewer role is assigned for a common object and enables viewing its charts and the dashboards that use it, without direct access to the common object itself. In the DataLens UI, this role is referred to as Limited viewer. We recommend assigning this role only via the DataLens UI.

datalens.sharedEntries.viewerdatalens.sharedEntries.viewer

The datalens.sharedEntries.viewer role is assigned for a common object and enables viewing it and its access permissions. In the DataLens UI, this role is referred to as Viewer. We recommend assigning this role only via the DataLens UI.

This role includes the datalens.sharedEntries.limitedViewer permissions.

May 2026May 2026

Identity and Access Management updatesIdentity and Access Management updates

  • Added new API key scopes: to work with Yandex Cloud Registry and to run workflows in Workflows.
  • Updated access policy templates: replaced the serverless.restrictPrivateNetworkInvocation and serverless.restrictPublicInvocation shared templates with separate templates for Yandex Serverless Containers, Yandex Cloud Functions, MCP Hub, and Workflows.

New rolesNew roles

Yandex Cloud Apps

cloudapps.admincloudapps.admin

The cloudapps.admin role enables viewing info on installed Cloud Apps, as well as creating, modifying, and deleting them.

This role includes the cloudapps.editor permissions.

cloudapps.auditorcloudapps.auditor

The cloudapps.auditor role enables viewing the metadata of installed Cloud Apps.

cloudapps.editorcloudapps.editor

The cloudapps.editor role enables viewing info on installed Cloud Apps, as well as creating, modifying, and deleting them.

This role includes the cloudapps.viewer permissions.

cloudapps.viewercloudapps.viewer

The cloudapps.viewer role enables viewing info on installed Cloud Apps.

This role includes the cloudapps.auditor permissions.

Yandex Cloud Marketplace

marketplace.productInstances.adminmarketplace.productInstances.admin

The marketplace.productInstances.admin role enables managing installed Marketplace products and access to them.

Users with this role can:

  • View info on installed Marketplace products.
  • View info on access permissions granted for installed Marketplace products and modify such permissions.
  • Create Marketplace products, modify their metadata, as well as activate and deactivate Marketplace products.
  • View info on the relevant folder.

This role includes the marketplace.productInstances.editor permissions.

marketplace.productInstances.auditormarketplace.productInstances.auditor

The marketplace.productInstances.auditor role enables viewing info on installed Marketplace products and access permissions granted for them, as well as viewing folder metadata.

marketplace.productInstances.editormarketplace.productInstances.editor

The marketplace.productInstances.editor role enables managing installed Marketplace products.

Users with this role can:

  • View info on installed Marketplace products and access permissions granted for them.
  • Create Marketplace products, modify their metadata, as well as activate and deactivate Marketplace products.
  • View info on the relevant folder.

This role includes the marketplace.productInstances.user permissions.

marketplace.productInstances.saasSupervisormarketplace.productInstances.saasSupervisor

The marketplace.productInstances.saasSupervisor role enables viewing info on installed Marketplace SaaS products and activating such products.

marketplace.productInstances.usermarketplace.productInstances.user

The marketplace.productInstances.user role enables viewing info on installed Marketplace products, activating and deactivating them, as well as viewing info on access permissions granted for them and on the relevant folder.

This role includes the marketplace.productInstances.viewer permissions.

marketplace.productInstances.viewermarketplace.productInstances.viewer

The marketplace.productInstances.viewer role enables enables viewing info on installed Marketplace products, access permissions granted for them, and on the relevant folder.

This role includes the marketplace.productInstances.auditor permissions.

Yandex Cloud Postbox

postbox.messages.readerpostbox.messages.reader

The postbox.messages.reader role enables viewing info on sent emails in the Sent emails section of the management console, including data on the sender, receivers, subject, sending date, deliverability and engagement metrics, complaints, and unsubscriptions.

postbox.statistics.readerpostbox.statistics.reader

The postbox.statistics.reader role enables viewing statistics on sent emails in the Statistics section of the management console.

Yandex Identity and Access Management

iam.serviceAccounts.ephemeralAccessKeyAdminiam.serviceAccounts.ephemeralAccessKeyAdmin

The iam.serviceAccounts.ephemeralAccessKeyAdmin role enables creating ephemeral access keys for service accounts.

Yandex Managed Service for Valkey™

managed-redis.clusters.connectormanaged-redis.clusters.connector

The managed-redis.clusters.connector role enables Yandex Cloud users to connect to databases in Valkey™ clusters via Yandex Identity and Access Management.

Yandex SIEM

ycem.executorycem.executor

The ycem.executor role enables managing queries, investigations, datasets, and correlation rules.

Users with this role can:
  • View info on investigations, as well as create, update, delete, and conduct them.
  • View info on datasets and their contents, as well as create, update, and delete datasets.
  • View info on queries, as well as create, update, delete, and run them.
  • View info on correlation rules and update them.
  • View info on exceptions and the list of queries that use these exceptions.
  • View info on Yandex SIEM instances and their components.

This role includes the ycem.inspector permissions.

ycem.inspectorycem.inspector

The ycem.inspector role enables managing queries, investigations, and datasets.

Users with this role can:
  • View info on investigations, as well as create, update, delete, and conduct them.
  • View info on datasets, as well as create, update, and delete them.
  • View info on queries, as well as create, update, delete, and run them.
  • View info on Yandex SIEM instances.

April 2026April 2026

Identity and Access Management updatesIdentity and Access Management updates

  • Added the MASKED KEY field to display the last six characters of the secret part of the key in the API key list.

New rolesNew roles

Yandex Cloud Notification Service

notifications.adminnotifications.admin

The notifications.admin role enables managing all notification channels and topics, as well as sending notifications to all channels and topics.

Users with this role can:

  • View info on topics and create, modify, and delete them.
  • View info on subscriptions in topics, as well as create and delete them.
  • View info on mobile push notification channels and their endpoints, as well as create, modify, and delete such channels and endpoints.
  • View info on browser push notification channels and their endpoints, as well as create, modify, and delete such channels and endpoints.
  • View info on text message (SMS) notification channels, as well as create, modify, and delete them.
  • View info on text message (SMS) templates and test phone numbers, as well as modify them.
  • Send notifications to all topics and channels.
  • View info on Cloud Notification Service quotas.

This role includes the notifications.editor permissions.

notifications.auditornotifications.auditor

The notifications.auditor role enables viewing metadata for all notification channels, topic metadata, and info on Cloud Notification Service quotas.

notifications.editornotifications.editor

The notifications.editor role enables managing all notification channels and topics, as well as sending notifications to all channels and topics.

Users with this role can:

  • View info on topics and create, modify, and delete them.
  • View info on subscriptions in topics, as well as create and delete them.
  • View info on mobile push notification channels and their endpoints, as well as create, modify, and delete such channels and endpoints.
  • View info on browser push notification channels and their endpoints, as well as create, modify, and delete such channels and endpoints.
  • View info on text message (SMS) notification channels, as well as create, modify, and delete them.
  • View info on text message (SMS) templates and test phone numbers, as well as modify them.
  • Send notifications to all topics and channels.
  • View info on Cloud Notification Service quotas.

This role includes the notifications.viewer and notifications.publisher permissions.

notifications.publishernotifications.publisher

The notifications.publisher role enables sending notifications to all channels and topics.

notifications.viewernotifications.viewer

The notifications.viewer role enables viewing info on topics, notification channels, and Cloud Notification Service quotas.

Users with this role can:

  • View info on topics and subscriptions in them.
  • View info on mobile push notification channels and their endpoints.
  • View info on browser push notification channels and their endpoints.
  • View info on text message (SMS) channels, SMS templates, and test phone numbers.
  • View info on Cloud Notification Service quotas.

This role includes the notifications.auditor permissions.

Yandex DataLens

datalens.metaReaderdatalens.metaReader

The datalens.metaReader role enables executing requests from the Audit section in the DataLens Public API, as well as requests to get DataLens entities.

You can get the following entities:

  • Connection: getConnection method
  • Dataset: getDataset method
  • Wizard chart: getWizardChart method
  • Editor chart: getEditorChart method
  • QL chart: getQLChart method
  • Dashboard: getDashboard method
  • Report: getReport method
  • Collection: getCollection method
  • Collection information: getCollectionContent method
  • Workbook: getWorkbook method
  • Workbook entries: getWorkbookEntries method
  • Entries: getEntries method
  • Entry relations: getEntriesRelations method

Warning

Getting entities will only work if the request includes the x-dl-audit-mode heading with the true value.

Yandex Cloud DNS

dns.firewallEditordns.firewallEditor

The dns.firewallEditor role enables managing DNS firewalls and using clouds, folders, and cloud networks as resources for them.

Users with this role can:

  • View info on DNS firewalls and access permissions granted for them.
  • Create, modify, and delete DNS firewalls.
  • Use clouds, folders, and cloud networks as resources for DNS firewalls.
  • View info on DNS zones and access permissions granted for them.
  • View info on Cloud DNS quotas.
  • View info on the relevant folder.

This role includes the dns.firewallUser permissions.

dns.firewallUserdns.firewallUser

The dns.firewallUser role enables using clouds, folders, and cloud networks as resources for DNS firewalls, as well as viewing info on Cloud DNS resources and quotas.

Users with this role can:

  • View info on DNS firewalls and access permissions granted for them.
  • Use clouds, folders, and cloud networks as resources for DNS firewalls.
  • View info on DNS zones and access permissions granted for them.
  • View info on Cloud DNS quotas.
  • View info on the relevant folder.

This role includes the dns.auditor permissions.

Yandex Identity Hub

organization-manager.groups.viewerorganization-manager.groups.viewer

The organization-manager.groups.viewer role enables viewing info on user groups and access permissions granted for them, as well as viewing the list of users and service accounts that are members of groups.

Yandex Managed Service for Kubernetes

k8s.cluster-api.admink8s.cluster-api.admin

Users with the k8s.cluster-api.admin role get the yc:k8s-core-admin group and the admin role in Kubernetes RBAC.

Managed databases

mdb.maintenanceTask.editormdb.maintenanceTask.editor

The mdb.maintenanceTask.editor role enables managing maintenance tasks for managed database clusters.

Users with this role can view information on maintenance tasks for managed database clusters and modify such tasks, view information on managed database clusters and access permissions granted for them, on cluster hosts and backups, as well as on service quotas and resource operations.

This role includes the mdb.maintenanceTask.viewer, managed-clickhouse.maintenanceTask.editor, managed-greenplum.maintenanceTask.editor, managed-kafka.maintenanceTask.editor, managed-mongodb.maintenanceTask.editor, managed-mysql.maintenanceTask.editor, managed-opensearch.maintenanceTask.editor, managed-postgresql.maintenanceTask.editor, managed-redis.maintenanceTask.editor, and managed-spqr.maintenanceTask.editor permissions.

mdb.maintenanceTask.viewermdb.maintenanceTask.viewer

The mdb.maintenanceTask.viewer role grants access to information on maintenance tasks for managed database clusters.

Users with this role can view information on managed database clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, as well as on service quotas and resource operations.

This role includes the mdb.auditor, managed-clickhouse.maintenanceTask.viewer, managed-greenplum.maintenanceTask.viewer, managed-kafka.maintenanceTask.viewer, managed-mongodb.maintenanceTask.viewer, managed-mysql.maintenanceTask.viewer, managed-opensearch.maintenanceTask.viewer, managed-postgresql.maintenanceTask.viewer, managed-redis.maintenanceTask.viewer, and managed-spqr.maintenanceTask.viewer permissions.

mdb.switchermdb.switcher

The mdb.switcher role enables re-assigning the master host in managed database clusters and grants access to information on such clusters and their logs.

Users with this role can re-assign the master host in managed database clusters, view info on such clusters, their hosts, databases, and users, as well as view cluster logs, service quotas, and resource operations.

This role includes the mdb.viewer, managed-mongodb.switcher, managed-mysql.switcher, managed-postgresql.switcher, and managed-redis.switcher permissions.

March 2026March 2026

New rolesNew roles

Yandex Cloud AI Studio

ai.guardrails.adminai.guardrails.admin

The ai.guardrails.admin role enables viewing info on guardrails for model responses, as well as creating, applying, modifying, and deleting such rules.

This role includes the ai.guardrails.editor permissions.

ai.guardrails.auditorai.guardrails.auditor

The ai.guardrails.auditor role enables viewing metadata on guardrails for model responses.

ai.guardrails.editorai.guardrails.editor

The ai.guardrails.editor role enables viewing info on guardrails for model responses, as well as creating, applying, modifying, and deleting such rules.

This role includes the ai.guardrails.viewer and ai.guardrails.user permissions.

ai.guardrails.userai.guardrails.user

The ai.guardrails.user role enables applying guardrails for model responses and viewing metadata on such rules.

ai.guardrails.viewerai.guardrails.viewer

The ai.guardrails.viewer role enables viewing info on guardrails for model responses.

This role includes the ai.guardrails.auditor permissions.

Yandex MPP Analytics for PostgreSQL

managed-greenplum.maintenanceTask.editormanaged-greenplum.maintenanceTask.editor

The managed-greenplum.maintenanceTask.editor role enables viewing info on maintenance tasks for Yandex MPP Analytics for PostgreSQL clusters and modifying such tasks, as well as viewing info on Yandex MPP Analytics for PostgreSQL clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex MPP Analytics for PostgreSQL.

This role includes the managed-greenplum.maintenanceTask.viewer permissions.

managed-greenplum.maintenanceTask.viewermanaged-greenplum.maintenanceTask.viewer

The managed-greenplum.maintenanceTask.viewer role enables viewing info on Yandex MPP Analytics for PostgreSQL clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex MPP Analytics for PostgreSQL.

This role includes the managed-greenplum.auditor permissions.

managed-greenplum.usermanaged-greenplum.user

The managed-greenplum.user role enables using Yandex MPP Analytics for PostgreSQL clusters.

Yandex Managed Service for Apache Airflow™

managed-airflow.maintenanceTask.editormanaged-airflow.maintenanceTask.editor

The managed-airflow.maintenanceTask.editor role enables viewing info on maintenance tasks for Apache Airflow™ clusters and modifying such tasks, as well as viewing info on Apache Airflow™ clusters, access permissions granted for them, and on quotas for Managed Service for Apache Airflow™.

This role includes the managed-airflow.maintenanceTask.viewer permissions.

managed-airflow.maintenanceTask.viewermanaged-airflow.maintenanceTask.viewer

The managed-airflow.maintenanceTask.viewer role enables viewing info on Apache Airflow™ clusters, access permissions granted for them, and their maintenance tasks, as well as on quotas for Managed Service for Apache Airflow™.

This role includes the managed-airflow.auditor permissions.

Yandex Managed Service for Apache Kafka®

managed-kafka.maintenanceTask.editormanaged-kafka.maintenanceTask.editor

The managed-kafka.maintenanceTask.editor role enables viewing info on maintenance tasks for Apache Kafka® clusters and modifying such tasks, as well as viewing info on Apache Kafka® clusters, access permissions granted for them, and on quotas and resource operations for Managed Service for Apache Kafka®.

This role includes the managed-kafka.maintenanceTask.viewer permissions.

managed-kafka.maintenanceTask.viewermanaged-kafka.maintenanceTask.viewer

The managed-kafka.maintenanceTask.viewer role enables viewing info on Apache Kafka® clusters, access permissions granted for them, their maintenance tasks, and on quotas and resource operations for Managed Service for Apache Kafka®.

This role includes the managed-kafka.auditor permissions.

managed-kafka.usermanaged-kafka.user

The managed-kafka.user role enables using Apache Kafka® clusters.

Yandex Managed Service for Apache Spark™

managed-spark.maintenanceTask.editormanaged-spark.maintenanceTask.editor

The managed-spark.maintenanceTask.editor role enables viewing info on maintenance tasks for Apache Spark™ clusters and modifying such tasks, as well as viewing info on Apache Spark™ clusters, access permissions granted for them, and on quotas for Managed Service for Apache Spark™.

This role includes the managed-spark.maintenanceTask.viewer permissions.

managed-spark.maintenanceTask.viewermanaged-spark.maintenanceTask.viewer

The managed-spark.maintenanceTask.viewer role enables viewing info on Apache Spark™ clusters, access permissions granted for them, their maintenance tasks, and on quotas for Managed Service for Apache Spark™.

This role includes the managed-spark.auditor permissions.

Yandex Managed Service for ClickHouse®

managed-clickhouse.maintenanceTask.editormanaged-clickhouse.maintenanceTask.editor

The managed-clickhouse.maintenanceTask.editor role enables viewing info on maintenance tasks for ClickHouse® clusters and modifying such tasks, as well as viewing info on ClickHouse® clusters, access permissions granted for them, and on quotas and resource operations for Managed Service for ClickHouse®.

This role includes the managed-clickhouse.maintenanceTask.viewer permissions.

managed-clickhouse.maintenanceTask.viewermanaged-clickhouse.maintenanceTask.viewer

The managed-clickhouse.maintenanceTask.viewer role enables viewing info on ClickHouse® clusters, their maintenance tasks, access permissions granted for them, and on quotas and resource operations for Managed Service for ClickHouse®.

This role includes the managed-clickhouse.auditor permissions.

managed-clickhouse.usermanaged-clickhouse.user

The managed-clickhouse.user role enables using ClickHouse® clusters.

Yandex Managed Service for MySQL®

managed-mysql.maintenanceTask.editormanaged-mysql.maintenanceTask.editor

The managed-mysql.maintenanceTask.editor role enables viewing info on maintenance tasks for MySQL® clusters and modifying such tasks, as well as viewing info on MySQL® clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex Managed Service for MySQL®.

This role includes the managed-mysql.maintenanceTask.viewer permissions.

managed-mysql.maintenanceTask.viewermanaged-mysql.maintenanceTask.viewer

The managed-mysql.maintenanceTask.viewer role enables viewing info on MySQL® clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex Managed Service for MySQL®.

This role includes the managed-mysql.auditor permissions.

managed-mysql.switchermanaged-mysql.switcher

The managed-mysql.switcher role enables re-assigning the master host in MySQL® clusters, viewing info on MySQL® clusters, hosts, databases, and users, as well as viewing cluster logs, quotas, and resource operations.

Users with this role can:

  • Re-assign the master host in MySQL® clusters.
  • View info on MySQL® clusters and access permissions granted for them.
  • View info on maintenance tasks for MySQL® clusters.
  • View info on MySQL® cluster hosts.
  • View info on MySQL® databases.
  • View info on MySQL® users.
  • View info on MySQL® cluster backups.
  • View info on MySQL® alerts.
  • View MySQL® cluster logs.
  • View info on the results of MySQL® cluster performance diagnostics.
  • View info on quotas for Managed Service for MySQL®.
  • View info on resource operations for Managed Service for MySQL®.

This role includes the managed-mysql.viewer permissions.

managed-mysql.usermanaged-mysql.user

The managed-mysql.user role enables using MySQL® clusters.

Yandex Managed Service for OpenSearch

managed-opensearch.maintenanceTask.editormanaged-opensearch.maintenanceTask.editor

The managed-opensearch.maintenanceTask.editor role enables viewing info on maintenance tasks for OpenSearch clusters and modifying such tasks, as well as viewing info on OpenSearch clusters, access permissions granted for them, and on quotas and resource operations for Managed Service for OpenSearch.

This role includes the managed-opensearch.maintenanceTask.viewer permissions.

managed-opensearch.maintenanceTask.viewermanaged-opensearch.maintenanceTask.viewer

The managed-opensearch.maintenanceTask.viewer role enables viewing info on OpenSearch clusters, access permissions granted for them, their maintenance tasks, and on quotas and resource operations for Managed Service for OpenSearch.

This role includes the managed-opensearch.auditor permissions.

managed-opensearch.usermanaged-opensearch.user

The managed-opensearch.user role enables using OpenSearch clusters.

Yandex Managed Service for PostgreSQL

managed-postgresql.maintenanceTask.editormanaged-postgresql.maintenanceTask.editor

The managed-postgresql.maintenanceTask.editor role enables viewing info on maintenance tasks for PostgreSQL clusters and modifying such tasks, as well as viewing info on PostgreSQL clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Managed Service for PostgreSQL.

This role includes the managed-postgresql.maintenanceTask.viewer permissions.

managed-postgresql.maintenanceTask.viewermanaged-postgresql.maintenanceTask.viewer

The managed-postgresql.maintenanceTask.viewer role enables viewing info on PostgreSQL clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Managed Service for PostgreSQL.

This role includes the managed-postgresql.auditor permissions.

managed-postgresql.switchermanaged-postgresql.switcher

The managed-postgresql.switcher role enables re-assigning the master host in PostgreSQL clusters, viewing info on PostgreSQL clusters, hosts, databases, and users, as well as viewing cluster logs, quotas, and resource operations.

Users with this role can:

  • Re-assign the master host in PostgreSQL clusters.
  • View info on PostgreSQL clusters and access permissions granted for them.
  • View info on maintenance tasks for PostgreSQL clusters.
  • View info on PostgreSQL cluster hosts.
  • View info on PostgreSQL databases.
  • View info on PostgreSQL users.
  • View info on PostgreSQL cluster backups.
  • View info on PostgreSQL alerts.
  • View PostgreSQL cluster logs.
  • View info on the results of PostgreSQL cluster performance diagnostics.
  • View info on quotas for Managed Service for PostgreSQL.
  • View info on resource operations for Managed Service for PostgreSQL.

This role includes the managed-postgresql.viewer permissions.

managed-postgresql.usermanaged-postgresql.user

The managed-postgresql.user role enables using PostgreSQL clusters.

Yandex Managed Service for Sharded PostgreSQL

managed-spqr.maintenanceTask.editormanaged-spqr.maintenanceTask.editor

The managed-spqr.maintenanceTask.editor role enables viewing info on maintenance tasks for Sharded PostgreSQL clusters and modifying such tasks, as well as viewing info on Sharded PostgreSQL clusters, access permissions granted for them, cluster hosts, quotas, and resource operations for Managed Service for Sharded PostgreSQL.

This role includes the managed-spqr.maintenanceTask.viewer permissions.

managed-spqr.maintenanceTask.viewermanaged-spqr.maintenanceTask.viewer

The managed-spqr.maintenanceTask.viewer role enables viewing info on Sharded PostgreSQL clusters, their maintenance tasks, access permissions granted for them, hosts, and on quotas and resource operations for Managed Service for Sharded PostgreSQL.

This role includes the managed-spqr.auditor permissions.

Yandex Managed Service for Trino

managed-trino.maintenanceTask.editormanaged-trino.maintenanceTask.editor

The managed-trino.maintenanceTask.editor role enables viewing info on maintenance tasks for Trino clusters and modifying such tasks, as well as viewing info on Trino clusters, access permissions granted for them, and on quotas for Managed Service for Trino.

This role includes the managed-trino.maintenanceTask.viewer permissions.

managed-trino.maintenanceTask.viewermanaged-trino.maintenanceTask.viewer

The managed-trino.maintenanceTask.viewer role enables viewing info on Trino clusters, access permissions granted for them, their maintenance tasks, and on quotas for Managed Service for Trino.

This role includes the managed-trino.auditor permissions.

Yandex Managed Service for Valkey™

managed-redis.maintenanceTask.editormanaged-redis.maintenanceTask.editor

The managed-redis.maintenanceTask.editor role enables viewing info on maintenance tasks for Valkey™ clusters and modifying such tasks, as well as viewing info on Valkey™ clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex Managed Service for Valkey™.

This role includes the managed-redis.maintenanceTask.viewer permissions.

managed-redis.maintenanceTask.viewermanaged-redis.maintenanceTask.viewer

The managed-redis.maintenanceTask.viewer role enables viewing info on Valkey™ clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex Managed Service for Valkey™.

This role includes the managed-redis.auditor permissions.

managed-redis.switchermanaged-redis.switcher

The managed-redis.switcher enables re-assigning the master host in Valkey™ clusters and viewing info on Valkey™ hosts, clusters and their logs, as well as on quotas and resource operations.

Users with this role can:

  • Re-assign the master host in Valkey™ clusters.
  • View info on Valkey™ clusters and access permissions granted for them.
  • View info on maintenance tasks for Valkey™ clusters.
  • View info on Valkey™ cluster hosts.
  • View info on Valkey™ cluster shards.
  • View info on Valkey™ users.
  • View info on Valkey™ cluster backups.
  • View info on Valkey™ alerts.
  • View Valkey™ cluster logs.
  • View info on quotas for Yandex Managed Service for Valkey™.
  • View info on resource operations for Yandex Managed Service for Valkey™.

This role includes the managed-redis.viewer permissions.

managed-redis.usermanaged-redis.user

The managed-redis.user role enables using Valkey™ clusters.

Yandex StoreDoc

managed-mongodb.maintenanceTask.editormanaged-mongodb.maintenanceTask.editor

The managed-mongodb.maintenanceTask.editor role enables viewing info on maintenance tasks for Yandex StoreDoc clusters and modifying such tasks, as well as viewing info on Yandex StoreDoc clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations.

This role includes the managed-mongodb.maintenanceTask.viewer permissions.

managed-mongodb.maintenanceTask.viewermanaged-mongodb.maintenanceTask.viewer

The managed-mongodb.maintenanceTask.viewer role enables viewing info on Yandex StoreDoc clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations.

This role includes the managed-mongodb.auditor permissions.

managed-mongodb.switchermanaged-mongodb.switcher

The managed-mongodb.switcher role enables re-assigning the master host in Yandex StoreDoc clusters and viewing info on Yandex StoreDoc clusters, hosts, shards, databases, users, cluster logs, quotas, and resource operations.

Users with this role can:

  • Re-assign the master host in Yandex StoreDoc clusters.
  • View info on Yandex StoreDoc clusters and access permissions granted for them.
  • View info on maintenance tasks for Yandex StoreDoc clusters and modify such tasks.
  • View info on Yandex StoreDoc cluster hosts.
  • View info on Yandex StoreDoc cluster shards.
  • View info on Yandex StoreDoc databases.
  • View info on Yandex StoreDoc users.
  • View info on Yandex StoreDoc cluster backups.
  • View info on Yandex StoreDoc alerts.
  • View Yandex StoreDoc cluster logs.
  • View info on the results of Yandex StoreDoc cluster performance diagnostics.
  • View info on Yandex StoreDoc quotas.
  • View info on resource operations for Yandex StoreDoc.

This role includes the managed-mongodb.viewer permissions.

managed-mongodb.usermanaged-mongodb.user

The managed-mongodb.user role enables using Yandex StoreDoc clusters.

February 2026February 2026

Identity and Access Management updatesIdentity and Access Management updates

  • Added access policies.

New rolesNew roles

Yandex Cloud Backup

backup.auditorbackup.auditor

The backup.auditor role enables viewing information on target resources connected to Cloud Backup, on backup policies and service quotas, as well as on the relevant cloud and folder.

Users with this role can:

  • View info on the connected backup providers.
  • View info on backup policies as well as on resources linked to such policies.
  • View info on access permissions granted for backup policies.
  • View info on resources connected to Cloud Backup.
  • View info on Cloud Backup quotas.
  • View info on the relevant cloud.
  • View info on the relevant folder and its statistics.

To assign the backup.auditor role, you need the admin role for the cloud or backup.admin for the folder.

December 2025December 2025

Identity and Access Management updatesIdentity and Access Management updates

  • Added ephemeral keys.
  • In the yandex_iam_oauth_client Terraform resource, fixed the comparison between the scopes and redirect_uris fields: now their type is set to avoid comparison conflicts.

New rolesNew roles

Yandex Cloud Backup

backup.userbackup.user

The backup.user role enables connecting backup providers, connecting target resources to Cloud Backup, linking backup policies to target resources and unlinking them, as well as viewing info on Cloud Backup resources and quotas and on the relevant cloud and folder.

Users with this role can:

  • View info on connected backup providers, as well as connect providers available in Cloud Backup.
  • View info on resources connected to Cloud Backup, as well as connect and disconnect resources to and from it.
  • View info on backup policies as well as on resources linked to such policies.
  • Link backup policies to target resources and unlink them.
  • View info on access permissions granted for backup policies.
  • View info on Cloud Backup quotas.
  • View info on the relevant cloud.
  • View info on the relevant folder and its statistics.

This role includes the backup.auditor permissions.

To assign the backup.user role, you need the admin role for the cloud or backup.admin for the folder.

Yandex Managed Service for MySQL®

managed-mysql.clusters.connectormanaged-mysql.clusters.connector

The managed-mysql.clusters.connector role enables Yandex Cloud users to connect to databases in MySQL® clusters via Yandex Identity and Access Management.

Yandex Managed Service for PostgreSQL

managed-postgresql.clusters.connectormanaged-postgresql.clusters.connector

The managed-postgresql.clusters.connector role enables Yandex Cloud users to connect to databases in PostgreSQL clusters via Yandex Identity and Access Management.

Yandex Monium

monium.adminmonium.admin

The monium.admin role enables managing Monium resources, read and write all types of telemetry, and manage projects and access to them.

Users with this role can:

  • View info on projects and create, set up, and delete them.
  • View info on access permissions granted for projects and modify such permissions.
  • Read and write all types of Monium telemetry, such as metrics, logs, and distributed tracing.
  • View dashboards and their widgets, as well as create, modify, and delete dashboards.
  • View the set-up context links on dashboard charts, as well as create, edit, and delete such links.
  • View the list of the set-up quick links and info on them in the project menu, as well as create, modify, and delete such links.
  • View info on shards, clusters, services and their quotas, as well as create, modify, and delete shards.
  • View the list of alerts, their settings, and trigger history, as well as create, modify, and delete alerts.
  • View the set-up service level objectives (SLOs), as well as create, modify, and delete SLOs.
  • View the list of alert notification channels and info on them, as well as create, modify, and delete such channels.
  • View the list and settings of alert escalation policies, as well as create, modify, and delete such policies.
  • View info on alert notifications and escalations, as well as create, modify, and delete escalations.
  • View, create, edit, and delete mutes, i.e., rules for temporarily disabling alert notifications.
  • View, add new, edit, and delete the existing labels to log errors.
  • View info on the Yandex Managed Service for Prometheus® rules, as well as create, modify, and delete such rules.
  • View info on the relevant folder.

This role includes the monium.editor permissions.

monium.editormonium.editor

The monium.editor role enables managing Monium resources, as well as reading and writing all types of telemetry.

Users with this role can:

  • View info on projects and access permissions assigned to them, as well as set up projects.
  • Read and write all types of Monium telemetry, such as metrics, logs, and distributed tracing.
  • View dashboards and their widgets, as well as create, modify, and delete dashboards.
  • View the set-up context links on dashboard charts, as well as create, edit, and delete such links.
  • View the list of the set-up quick links and info on them in the project menu, as well as create, modify, and delete such links.
  • View info on shards, clusters, services and their quotas, as well as create, modify, and delete shards.
  • View the list of alerts, their settings, and trigger history, as well as create, modify, and delete alerts.
  • View the set-up service level objectives (SLOs), as well as create, modify, and delete SLOs.
  • View the list of alert notification channels and info on them, as well as create, modify, and delete such channels.
  • View the list and settings of alert escalation policies, as well as create, modify, and delete such policies.
  • View info on alert notifications and escalations, as well as create, modify, and delete escalations.
  • View, create, edit, and delete mutes, i.e., rules for temporarily disabling alert notifications.
  • View, add new, edit, and delete the existing labels to log errors.
  • View info on the Yandex Managed Service for Prometheus® rules, as well as create, modify, and delete such rules.
  • View info on the relevant folder.

This role includes the monium.viewer, monium.telemetry.writer, monium.dashboards.editor, monium.shards.editor, monium.contextLinks.editor, monium.quickLinks.editor, monium.alerts.editor, monium.serviceLevelObjectives.editor, monium.channels.editor, monium.escalationPolicies.editor, monium.escalations.editor, monium.mutes.editor, and monium.logErrorLabels.editor permissions.

monium.viewermonium.viewer

The monium.viewer role enables viewing information on Monium resources. It also enables reading all types of telemetry data.

Users with this role can:

  • View info on projects and access permissions assigned to them.
  • Read all types of Monium telemetry, such as metrics, logs, and distributed tracing.
  • View dashboards and their widgets.
  • View the set-up context links on dashboard charts.
  • View the list of the set-up quick links and info on them in the project menu.
  • View info on shards, clusters, services and their quotas.
  • View the list of alerts, their settings, and trigger history.
  • View the set-up service level objectives (SLOs).
  • View the list of alert notification channels and info on them.
  • View the list and settings of alert escalation policies.
  • View info on alert notifications and escalations.
  • View mutes, i.e., rules for temporarily disabling alert notifications.
  • View labels assigned to log errors.
  • View info on the Yandex Managed Service for Prometheus® rules.
  • View info on the relevant folder.

This role includes the monium.auditor and monium.telemetry.reader permissions.

monium.auditormonium.auditor

The monium.auditor role enables viewing information on Monium resources. However, it does not allow reading the telemetry data.

Users with this role can:

  • View info on projects and access permissions assigned to them.
  • View dashboards and their widgets.
  • View the set-up context links on dashboard charts.
  • View the list of the set-up quick links and info on them in the project menu.
  • View info on shards, clusters, services and their quotas.
  • View the list of alerts, their settings, and trigger history.
  • View the set-up service level objectives (SLOs).
  • View the list of alert notification channels and info on them.
  • View the list and settings of alert escalation policies.
  • View info on alert notifications and escalations.
  • View mutes, i.e., rules for temporarily disabling alert notifications.
  • View labels assigned to log errors.
  • View info on the Yandex Managed Service for Prometheus® rules.

This role includes the monium.dashboards.viewer, monium.shards.viewer, monium.contextLinks.viewer, monium.quickLinks.viewer, monium.alerts.viewer, monium.serviceLevelObjectives.viewer, monium.channels.viewer, monium.escalationPolicies.viewer, monium.escalations.viewer, monium.mutes.viewer, and monium.logErrorLabels.viewer permissions.

monium.alerts.editormonium.alerts.editor

The monium.alerts.editor role enables viewing the list of alerts, their settings, and trigger history, as well as creating, modifying, and deleting alerts.

This role includes the monium.alerts.viewer permissions.

monium.alerts.viewermonium.alerts.viewer

The monium.alerts.viewer role enables viewing the list of alerts, their settings, and trigger history.

monium.channels.editormonium.channels.editor

The monium.channels.editor role enables viewing the list of alert notification channels and info on them, as well as creating, modifying, and deleting such channels.

This role includes the monium.channels.viewer permissions.

monium.channels.viewermonium.channels.viewer

The monium.channels.viewer role enables viewing the list of alert notification channels and info on them.

monium.contextLinks.editormonium.contextLinks.editor

The monium.contextLinks.editor role enables viewing the set-up context links on dashboard charts, as well as creating, editing, and deleting such links.

This role includes the monium.contextLinks.viewer permissions.

monium.contextLinks.viewermonium.contextLinks.viewer

The monium.contextLinks.viewer role enables viewing the set-up context links on dashboard charts.

monium.dashboards.editormonium.dashboards.editor

The monium.dashboards.editor role enables viewing dashboards and their widgets, as well as creating, modifying, and deleting dashboards.

This role includes the monium.dashboards.viewer permissions.

monium.dashboards.viewermonium.dashboards.viewer

The monium.dashboards.viewer role enables viewing dashboards and their widgets.

monium.escalationPolicies.editormonium.escalationPolicies.editor

The monium.escalationPolicies.editor role enables viewing the list and settings of alert escalation policies, as well as creating, modifying, and deleting such policies.

This role includes the monium.escalationPolicies.viewer permissions.

monium.escalationPolicies.viewermonium.escalationPolicies.viewer

The monium.escalationPolicies.viewer role enables viewing the list and settings of alert escalation policies.

monium.escalations.editormonium.escalations.editor

The monium.escalations.editor role enables viewing info on alert notifications and escalations, as well as creating, modifying, and deleting escalations.

This role includes the monium.escalations.viewer permissions.

monium.escalations.viewermonium.escalations.viewer

The monium.escalations.viewer role enables viewing info on alert notifications and escalations.

monium.logErrorLabels.editormonium.logErrorLabels.editor

The monium.logErrorLabels.editor role enables viewing, adding new, editing, and deleting the existing labels to log errors.

This role includes the monium.logErrorLabels.viewer permissions.

monium.logErrorLabels.viewermonium.logErrorLabels.viewer

The monium.logErrorLabels.viewer role enables viewing labels assigned to log errors.

monium.logs.readermonium.logs.reader

The monium.logs.reader role enables reading logs and viewing log error stats.

monium.logs.writermonium.logs.writer

The monium.logs.writer role enables writing Monium logs.

monium.metrics.readermonium.metrics.reader

The monium.metrics.reader role enables reading metrics, their values, and labels.

monium.metrics.writermonium.metrics.writer

The monium.metrics.writer role enables writing metrics.

monium.mutes.editormonium.mutes.editor

The monium.mutes.editor role enables viewing, creating, editing, and deleting mutes, i.e., rules for temporarily disabling alert notifications.

This role includes the monium.mutes.viewer permissions.

monium.mutes.viewermonium.mutes.viewer

The monium.mutes.viewer role enables viewing mutes, i.e., rules for temporarily disabling alert notifications.

monium.quickLinks.editormonium.quickLinks.editor

The monium.quickLinks.editor role enables viewing the list of the set-up quick links and info on them in the project menu, as well as creating, modifying, and deleting such links.

This role includes the monium.quickLinks.viewer permissions.

monium.quickLinks.viewermonium.quickLinks.viewer

The monium.quickLinks.viewer role enables viewing the list of the set-up quick links and info on them in the project menu.

monium.serviceLevelObjectives.editormonium.serviceLevelObjectives.editor

The monium.serviceLevelObjectives.editor role enables viewing the set-up service level objectives (SLOs), as well as creating, modifying, and deleting SLOs.

This role includes the monium.serviceLevelObjectives.viewer permissions.

monium.serviceLevelObjectives.viewermonium.serviceLevelObjectives.viewer

The monium.serviceLevelObjectives.viewer role enables viewing the set-up service level objectives (SLOs).

monium.shards.editormonium.shards.editor

The monium.shards.editor enables viewing info on shards, clusters, services and their quotas, as well as creating, modifying, and deleting shards.

This role includes the monium.shards.viewer permissions.

monium.shards.viewermonium.shards.viewer

The monium.shards.viewer role enables viewing info on shards, clusters, services and their quotas.

monium.telemetry.readermonium.telemetry.reader

The monium.telemetry.reader role enables reading all types of Monium telemetry, such as metrics, logs, and distributed tracing.

This role includes the monium.metrics.reader, monium.logs.reader, and monium.traces.reader permissions.

monium.telemetry.writermonium.telemetry.writer

The monium.telemetry.writer role enables writing all types of Monium telemetry, such as metrics, logs, and distributed tracing.

This role includes the monium.metrics.writer, monium.logs.writer, and monium.traces.writer permissions.

monium.traces.readermonium.traces.reader

The monium.traces.reader role enables viewing distributed tracing data.

monium.traces.writermonium.traces.writer

The monium.traces.writer role enables writing distributed tracing data.

Yandex MPP Analytics for PostgreSQL

managed-greenplum.clusters.connectormanaged-greenplum.clusters.connector

The managed-greenplum.clusters.connector role enables Yandex Cloud users to connect to databases in Yandex MPP Analytics for PostgreSQL clusters within Yandex MPP Analytics for PostgreSQL via Yandex Identity and Access Management.

Yandex Security Deck

security-deck.alertSinks.adminsecurity-deck.alertSinks.admin

The security-deck.alertSinks.admin role enables managing alert sinks and alerts, as well as access to them.

Users with this role can:

  • View info on alert sinks, as well as create, use, modify, and delete them.
  • View info on access permissions granted for alert sinks and modify such permissions.
  • View info on alerts, as well as create, modify, and delete them.
  • View info on access permissions granted for alerts and modify such permissions.
  • View additional info on alerts and their sources, the list of affected resources, and tips on resolving issues.
  • View the list of comments to alerts, as well as create, modify, and delete such comments.

This role includes the security-deck.alertSinks.editor permissions.

security-deck.alertSinks.editorsecurity-deck.alertSinks.editor

The security-deck.alertSinks.editor role enables managing alert sinks, alerts, and comments in them.

Users with this role can:

  • View info on alert sinks and access permissions granted for them.
  • Create, use, modify, and delete alert sinks.
  • View info on alerts and access permissions granted for them.
  • View additional info on alerts and their sources, the list of affected resources, and tips on resolving issues.
  • Create, modify, and delete alerts.
  • View the list of comments to alerts, as well as create, modify, and delete such comments.

This role includes the security-deck.alertSinks.viewer and security-deck.alertSinks.user permissions.

security-deck.alertSinks.usersecurity-deck.alertSinks.user

The security-deck.alertSinks.user role enables viewing info on alert sinks and using them.

security-deck.alertSinks.viewersecurity-deck.alertSinks.viewer

The security-deck.alertSinks.viewer role enables viewing info on alerts and alert sinks as well as on access permissions granted for them.

Users with this role can:

  • View info on alert sinks and access permissions granted for them.
  • View info on alerts and access permissions granted for them.
  • View additional info on alerts and their sources, the list of affected resources, and tips on resolving issues.

This role includes the security-deck.alertSinks.auditor permissions.

security-deck.alertSinks.auditorsecurity-deck.alertSinks.auditor

The security-deck.alertSinks.auditor role enables viewing info on alert sinks and access permissions granted for them.

November 2025November 2025

Identity and Access Management updatesIdentity and Access Management updates

  • Added the ability to view a list of a subject's accesses.

New rolesNew roles

Yandex Cloud Interconnect

cic.admincic.admin

The cic.admin role enables managing Cloud Interconnect resources.

Users with this role can:
  • View info on trunk links, as well as create, modify, and delete them.
  • View info on private connections, as well as create, modify, and delete them.
  • View info on public connections, as well as create, modify, and delete them.
  • View info on the points of presence.
  • View info on CIC partners.
  • View info on Cloud Interconnect quotas.
  • View info on the relevant cloud.
  • View information on the relevant folder.

This role includes the cic.editor permissions.

Yandex Cloud Router

cloud-router.admincloud-router.admin

The cloud-router.admin role enables managing Cloud Router resources.

Users with this role can:

  • View info on routing instances, as well as create, modify, and delete them.
  • Add, modify, and remove cloud subnet IP prefixes in routing instances.
  • View info on Cloud Router quotas.
  • View info on the relevant cloud.
  • View information on the relevant folder.

This role includes the cloud-router.editor permissions.

cloud-router.prefixEditorcloud-router.prefixEditor

The cloud-router.prefixEditor role enables managing cloud subnet IP prefixes in routing instances, as well as viewing info on Cloud Router resources.

Users with this role can:

  • View info on the routing instances.
  • Add, modify, and remove cloud subnet IP prefixes in routing instances.
  • View info on Cloud Router quotas.
  • View info on the relevant cloud.
  • View information on the relevant folder.

This role includes the cloud-router.viewer permissions.

Yandex Identity Hub

organization-manager.idpInstances.billingAdminorganization-manager.idpInstances.billingAdmin

The organization-manager.idpInstances.billingAdmin role enables managing a subscription to the paid-for Yandex Identity Hub features.

Users with this role can:

  • Link Yandex Identity Hub to a billing account.
  • View info on a subscription to the paid-for Yandex Identity Hub features.
  • View info on stats regarding the use of the quotes within a subscription to the paid-for Yandex Identity Hub features, as well as edit these quotas.
  • View the list of users who employ the Yandex Identity Hub authentication quota in the current reporting period.

This role includes the organization-manager.idpInstances.billingViewer permissions.

organization-manager.idpInstances.billingViewerorganization-manager.idpInstances.billingViewer

The organization-manager.idpInstances.billingViewer role enables viewing the list of users who employ the Yandex Identity Hub authentication quota in the current reporting period, as well as viewing info on a subscription to the paid-for Yandex Identity Hub features and stats regarding the use of the quotas within this subscription.

October 2025October 2025

Identity and Access Management updatesIdentity and Access Management updates

  • Added the ability to manage the access of services to the user's resources.

New rolesNew roles

Managed databases

mdb.restorermdb.restorer

The mdb.restorer role enables restoring managed database clusters from backups and grants read access to such clusters and their logs.

Users with this role can restore managed database clusters from backups, read from databases, view cluster logs, and view info on clusters, their maintenance tasks, quotas, and resource operations.

This role includes the mdb.viewer, managed-opensearch.restorer, managed-mysql.restorer, managed-postgresql.restorer, managed-spqr.restorer, managed-greenplum.restorer, managed-clickhouse.restorer, managed-redis.restorer, and managed-mongodb.restorer permissions.

Yandex Identity Hub

organization-manager.groups.externalConverterorganization-manager.groups.externalConverter

The organization-manager.groups.externalConverter role enables adding an attribute with an external group ID to Yandex Identity Hub user groups when synchronizing with user groups in Active Directory or another external source.

organization-manager.groups.externalCreatororganization-manager.groups.externalCreator

The organization-manager.groups.externalCreator role enables creating Yandex Identity Hub user groups when synchronizing with user groups in Active Directory or another external source.

organization-manager.userpools.syncAgentorganization-manager.userpools.syncAgent

The organization-manager.userpools.syncAgent role enables synchronizing Yandex Identity Hub users and groups with users and groups in Active Directory or another external source.

Users with this role can:

  • View info on sync sessions between Yandex Identity Hub Sync Agent and Yandex Identity Hub, as well as create and modify such sessions.
  • View info on user pools and sync settings in user pools.
  • View the list of and info on Yandex Identity Hub user groups associated with user pools through synchronization with user groups in Active Directory or another external source.
  • Associate user groups with user pools through synchronization with user groups in Active Directory or another external source.
  • View info on Yandex Identity Hub users, create, modify, activate, deactivate, and delete such users, as well as edit their passwords and other data.

This role includes the organization-manager.userpools.extGroupsManager permissions.

Yandex Managed Service for Apache Kafka®

managed-kafka.restorermanaged-kafka.restorer

The managed-kafka.restorer role enables restoring Apache Kafka® clusters from backups and viewing info on such clusters, their logs, and details on quotas and resource operations for Managed Service for Apache Kafka®.

Users with this role can:

  • View info on Apache Kafka® clusters and access permissions granted for them.
  • Restore Apache Kafka® clusters from backups.
  • View info on maintenance tasks for Apache Kafka® clusters.
  • View Apache Kafka® cluster logs.
  • View info on quotas for Managed Service for Apache Kafka®.
  • View info on resource operations for Managed Service for Apache Kafka®.

This role includes the managed-kafka.viewer permissions.

Yandex Managed Service for ClickHouse®

managed-clickhouse.restorermanaged-clickhouse.restorer

The managed-clickhouse.restorer role enables restoring ClickHouse® clusters from backups and viewing info on such clusters, their logs, and details on quotas and resource operations for Managed Service for ClickHouse®.

Users with this role can:

  • Restore ClickHouse® clusters from backups.
  • View info on ClickHouse® clusters and access permissions granted for them.
  • View info on maintenance tasks for ClickHouse® clusters.
  • View ClickHouse® cluster logs.
  • View info on the results of ClickHouse® cluster performance diagnostics.
  • View info on quotas for Managed Service for ClickHouse®.
  • View info on resource operations for Managed Service for ClickHouse®.

This role includes the managed-clickhouse.viewer permissions.

Yandex Managed Service for MySQL®

managed-mysql.restorermanaged-mysql.restorer

The managed-mysql.restorer role enables restoring MySQL® clusters from backups and viewing info on MySQL® clusters, hosts, databases, and users, viewing cluster logs, as well as viewing info on quotas and resource operations.

Users with this role can:

  • View info on MySQL® cluster backups and restore clusters from backups.
  • View info on MySQL® clusters and access permissions granted for them.
  • View info on maintenance tasks for MySQL® clusters.
  • View info on MySQL® cluster hosts.
  • View info on MySQL® databases.
  • View info on MySQL® users.
  • View info on MySQL® alerts.
  • View MySQL® cluster logs.
  • View info on the results of MySQL® cluster performance diagnostics.
  • View info on quotas for Managed Service for MySQL®.
  • View info on resource operations for Managed Service for MySQL®.

This role includes the managed-mysql.viewer permissions.

Yandex Managed Service for OpenSearch

managed-opensearch.restorermanaged-opensearch.restorer

The managed-opensearch.restorer role enables restoring OpenSearch clusters from backups and viewing info on OpenSearch clusters, their logs, as well as info on quotas and resource operations for Managed Service for OpenSearch.

Users with this role can:

  • View info on OpenSearch clusters and access permissions granted for them.
  • Restore OpenSearch clusters from backups.
  • View info on maintenance tasks for OpenSearch clusters.
  • View OpenSearch cluster logs.
  • View info on quotas for Managed Service for OpenSearch.
  • View info on resource operations for Managed Service for OpenSearch.

This role includes the managed-opensearch.viewer permissions.

Yandex Managed Service for PostgreSQL

managed-postgresql.restorermanaged-postgresql.restorer

The managed-postgresql.restorer role enables restoring PostgreSQL clusters from backups and viewing info on PostgreSQL clusters, hosts, databases, and users, viewing cluster logs, as well as viewing info on quotas and resource operations.

Users with this role can:

  • View info on PostgreSQL cluster backups and restore clusters from backups.
  • View info on PostgreSQL clusters and access permissions granted for them.
  • View info on maintenance tasks for PostgreSQL clusters.
  • View info on PostgreSQL cluster hosts.
  • View info on PostgreSQL databases.
  • View info on PostgreSQL users.
  • View info on PostgreSQL alerts.
  • View PostgreSQL cluster logs.
  • View info on the results of PostgreSQL cluster performance diagnostics.
  • View info on quotas for Managed Service for PostgreSQL.
  • View info on resource operations for Managed Service for PostgreSQL.

This role includes the managed-postgresql.viewer permissions.

Yandex Managed Service for Sharded PostgreSQL

managed-spqr.restorermanaged-spqr.restorer

The managed-spqr.restorer role enables restoring Sharded PostgreSQL clusters from backups and viewing info on Sharded PostgreSQL clusters, hosts, databases, and users, cluster logs, as well as info on quotas and resource operations.

Users with this role can:

  • View info on Sharded PostgreSQL cluster backups and restore clusters from backups.
  • View info on Sharded PostgreSQL clusters and access permissions granted for them.
  • View info on maintenance tasks for Sharded PostgreSQL clusters.
  • View info on Sharded PostgreSQL cluster hosts.
  • View info on databases in Sharded PostgreSQL clusters.
  • View info on users in Sharded PostgreSQL clusters.
  • View Sharded PostgreSQL cluster logs.
  • View info on quotas for Managed Service for Sharded PostgreSQL.
  • View info on resource operations for Managed Service for Sharded PostgreSQL.

This role includes the managed-spqr.viewer permissions.

Yandex Managed Service for Valkey™

managed-redis.restorermanaged-redis.restorer

The managed-redis.restorer role enables restoring Valkey™ clusters from backups, viewing info on Valkey™ hosts, clusters, and their logs, as well as on quotas and resource operations.

Users with this role can:

  • View info on Valkey™ cluster backups and restore clusters from backups.
  • View info on Valkey™ clusters and access permissions granted for them.
  • View info on maintenance tasks for Valkey™ clusters.
  • View info on Valkey™ cluster hosts.
  • View info on Valkey™ cluster shards.
  • View info on Valkey™ users.
  • View info on Valkey™ alerts.
  • View Valkey™ cluster logs.
  • View info on quotas for Yandex Managed Service for Valkey™.
  • View info on resource operations for Yandex Managed Service for Valkey™.

This role includes the managed-redis.viewer permissions.

Yandex MPP Analytics for PostgreSQL

managed-greenplum.restorermanaged-greenplum.restorer

The managed-greenplum.restorer role enables restoring Yandex MPP Analytics for PostgreSQL clusters from backups within Yandex MPP Analytics for PostgreSQL, viewing info on Yandex MPP Analytics for PostgreSQL clusters and hosts, their logs, as well as info on quotas and service resource operations.

Users with this role can:

  • View info on Yandex MPP Analytics for PostgreSQL cluster backups and restore clusters from backups.
  • View info on Yandex MPP Analytics for PostgreSQL clusters and access permissions granted for them.
  • View info on maintenance tasks for Yandex MPP Analytics for PostgreSQL clusters.
  • View info on Yandex MPP Analytics for PostgreSQL cluster hosts.
  • View Yandex MPP Analytics for PostgreSQL cluster logs.
  • View info on the results of Yandex MPP Analytics for PostgreSQL cluster performance diagnostics.
  • View info on quotas for Yandex MPP Analytics for PostgreSQL.
  • View info on resource operations for Yandex MPP Analytics for PostgreSQL.

This role includes the managed-greenplum.viewer permissions.

Yandex StoreDoc

managed-mongodb.restorermanaged-mongodb.restorer

The managed-mongodb.restorer role enables restoring Yandex StoreDoc clusters from backups and viewing info on Yandex StoreDoc clusters, hosts, shards, databases, users, cluster logs, quotas, and resource operations.

Users with this role can:

  • View info on Yandex StoreDoc cluster backups and restore clusters from backups.
  • View info on Yandex StoreDoc clusters and access permissions granted for them.
  • View info on maintenance tasks for Yandex StoreDoc clusters and modify such tasks.
  • View info on Yandex StoreDoc cluster hosts.
  • View info on Yandex StoreDoc cluster shards.
  • View info on Yandex StoreDoc databases.
  • View info on Yandex StoreDoc users.
  • View info on Yandex StoreDoc alerts.
  • View Yandex StoreDoc cluster logs.
  • View info on the results of Yandex StoreDoc cluster performance diagnostics.
  • View info on Yandex StoreDoc quotas.
  • View info on resource operations for Yandex StoreDoc.

This role includes the managed-mongodb.viewer permissions.

Q3 2025Q3 2025

  • Implemented management of OAuth client secrets using the CLI and API. CLI API
  • Added a group of commands for OAuth client management to the CLI and API. CLI API

Q2 2025Q2 2025

  • Enabled creating and using refresh tokens. CLI

Q1 2025Q1 2025

  • Added new scopes for API keys and the ability to assign more than one scope per service. Management console CLI Terraform API
  • Workload identity federations are now available to all users. Management console CLI Terraform API
  • Added creating an ID token for service account, a special short-lived token for authentication in third-party systems. Management console CLI Terraform API

Q4 2024Q4 2024

  • Added sending the CreateIamToken data event when creating an IAM token.
  • Expanded the scope of limited lifetime API keys to work with Yandex Managed Service for YDB in compatibility mode with PostgreSQL, Yandex Cloud Postbox, and Yandex Serverless Containers. Management console CLI Terraform API
  • You can now see the service account's last authentication date and time. You can get the information in the last_authenticated_at field using the yc iam user-account get Yandex Cloud CLI command. CLI

Q3 2024Q3 2024

  • Added Workload Identity Federations that allow you to grant access to external applications without using long-lived access keys. Management console CLI Terraform API
  • You can now create API keys with limited scope and validity period. Management console CLI Terraform API
  • Added the ResolveAgent REST API method. API
  • Added the ability to revoke an IAM token using the Yandex Cloud CLI. CLI
  • Added All users in organization X and All users in federation N system groups.
  • Added the Terraform data source used to get the service agent ID. Terraform

Q2 2024Q2 2024

  • Added the last used date info for service account access keys. You can find this info on the service account page in the management console or in the last_used_at field when using the API to invoke access key management methods. Management console API

Q1 2024Q1 2024

  • Added the Security Token Service component to get temporary access keys compatible with AWS S3 API. This feature is at the Preview stage. CLI API
  • Added OAuth client authentication support by authenticating a service account token.
  • Added the option of using masked token ID for Audit Trails logs.
  • Improved the key rotation mechanism in OpenID Connect.

Was the article helpful?

Previous
Audit Trails events
Next
General questions
© 2026 Direct Cursus Technology L.L.C.