Yandex Cloud
Search
Contact UsGet started
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI for business
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
Yandex Security Deck
    • Common Security Deck roles
    • YCDR roles
    • DSPM roles
    • KSPM roles
    • CIEM roles
    • CSPM roles
    • Access Transparency roles
  • Pricing policy
  1. Access management
  2. KSPM roles

Kubernetes® Security Posture Management (KSPM) service roles

Written by
Yandex Cloud
Updated at October 16, 2025

With Kubernetes® Security Posture Management (KSPM) service roles, you can manage user access to the KSPM resources and their settings, as well as to the data contained in the control results and alerts.

kspm.workerkspm.worker

The kspm.worker role allows the user to view info on Managed Service for Kubernetes clusters and install KSPM components in them.

The role is issued to the service account to perform cluster checks and extends to an organization, cloud, or folder. This service account should be specified when creating the workspace.

kspm.auditorkspm.auditor

The kspm.auditor role allows the user to view info on KSPM settings, KSPM operations, and the list of exceptions from the rules.

kspm.viewerkspm.viewer

The kspm.viewer role allows the user to view info on KSPM settings, Managed Service for Kubernetes clusters connected to KSPM, exceptions from the rules, exceptions from the scope of control, KSPM users, and KSPM operations.

This role includes the kspm.auditor permissions.

kspm.editorkspm.editor

The kspm.editor role allows the user to engage, set up, and disconnect KSPM, create, modify, and delete exceptions from the rules and exceptions from the scope of control, view info on Managed Service for Kubernetes clusters connected to KSPM, KSPM users, and KSPM operations.

This role includes the kspm.viewer permissions.

kspm.adminkspm.admin

The kspm.admin role allows the user to engage, set up, and disconnect KSPM, create, modify, and delete exceptions from the rules and exceptions from the scope of control, view info on Managed Service for Kubernetes clusters connected to KSPM, KSPM users, and KSPM operations.

This role includes the kspm.editor permissions.

Was the article helpful?

Previous
DSPM roles
Next
CIEM roles
© 2025 Direct Cursus Technology L.L.C.