Yandex Cloud
Search
Contact UsGet started
  • Blog
  • Pricing
  • Documentation
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • ML & AI
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Customer Stories
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Education and Science
    • Yandex Cloud Partner program
  • Blog
  • Pricing
  • Documentation
© 2025 Direct Cursus Technology L.L.C.
Yandex SpeechSense
  • Getting started
  • Audit Trails events
  • Access management
  • Pricing policy
  • Release notes
  • FAQ

In this article:

  • Which resources you can assign a role for
  • Which roles exist in the service
  • Service roles
  • Primitive roles
  • What roles do I need

Access management in SpeechSense

Written by
Yandex Cloud
Updated at April 22, 2025
  • Which resources you can assign a role for
  • Which roles exist in the service
    • Service roles
    • Primitive roles
  • What roles do I need

User access to Yandex SpeechSense depends on relevant permissions granted within an organization. Organizations are managed using Yandex Cloud Organization.

The operations available to SpeechSense users are determined by their roles. You can assign roles to a Yandex account, service account, federated users, user group, system group, or public group. For more information about access management in Yandex Cloud, see How access management works in Yandex Cloud.

Only users with the admin, resource-manager.clouds.owner, or organization-manager.organizations.owner role for a resource can assign roles for this resource.

Which resources you can assign a role forWhich resources you can assign a role for

In the SpeechSense interface, you can assign a role for a space or project. Roles assigned for a space also apply to all nested projects and resources.

Which roles exist in the serviceWhich roles exist in the service

Service rolesService roles

speech-sense.auditorspeech-sense.auditor

The speech-sense.auditor role enables you to view names, descriptions, and lists of members of a project or a space with all of its projects. The role does not provide access to project data.

speech-sense.viewerspeech-sense.viewer

The speech-sense.viewer role enables you to view project or space characteristics, the list of their members, connections, and dashboards.

The speech-sense.viewer role includes all permissions of the speech-sense.auditor role.

speech-sense.editorspeech-sense.editor

The speech-sense.editor role enables you to edit a project, its description, dashboards, and alerts, create and edit its classifiers, and run analyses. When assigned for a space, the role allows you to edit the space and create projects, connections, and dictionaries within it.

The speech-sense.editor role includes all permissions of the speech-sense.viewer role.

speech-sense.adminspeech-sense.admin

The speech-sense.admin role assigned for a space or project enables you to perform any action in them: view dialogs, edit connections, or run analyses. The role grants permission to assign roles to other users.

The speech-sense.admin role includes all permissions of the speech-sense.editor and speech-sense.data.editor roles.

speech-sense.spaces.creatorspeech-sense.spaces.creator

The speech-sense.spaces.creator role allows you to create spaces in SpeechSense.

speech-sense.data.viewerspeech-sense.data.viewer

The speech-sense.data.viewer role allows you to view a project's name or description, the list of connections, dashboards, and project members. It also enables you to search inside documents, listen to dialogs, and view their text transcripts. When assigned for a space, this role enables you to view all of its projects without editing them.

speech-sense.data.editorspeech-sense.data.editor

The speech-sense.data.editor role enables you to upload dialogs to project or space connections, evaluate these dialogs and comment on them in the system.

The speech-sense.data.editor role includes all permissions of the speech-sense.data.viewer role.

Users with roles like speech-sense.data.* can view and rate the contents of documents but do not have access to aggregate information.

Users with speech-sense.data.* roles can view and rate the contents of documents but have no access to aggregated information.

Primitive rolesPrimitive roles

Primitive roles allow users to perform actions in all Yandex Cloud services.

auditorauditor

The auditor role grants a permission to read configuration and metadata of any Yandex Cloud resources without any access to data.

For instance, users with this role can:

  • View info on a resource.
  • View the resource metadata.
  • View the list of operations with a resource.

auditor is the most secure role that does not grant any access to the service data. This role suits the users who need minimum access to the Yandex Cloud resources.

viewerviewer

The viewer role grants the permissions to read the info on any Yandex Cloud resources.

This role also includes the auditor permissions.

Unlike auditor, the viewer role provides access to service data in read mode.

editoreditor

The editor role provides permissions to manage any Yandex Cloud resources, except for assigning roles to other users, transferring organization ownership, removing an organization, and deleting Key Management Service encryption keys.

For instance, users with this role can create, modify, and delete resources.

This role also includes the viewer permissions.

adminadmin

The admin role enables assigning any roles, except for resource-manager.clouds.owner and organization-manager.organizations.owner, and provides permissions to manage any Yandex Cloud resources (except for transferring organization ownership and removing an organization).

Prior to assigning the admin role for an organization, cloud, or billing account, make sure to check out the information on protecting privileged accounts.

This role also includes the editor permissions.

Instead of primitive roles, we recommend using service roles with more granular access control, allowing you to implement the least privilege principle.

For more information about primitive roles, see the Yandex Cloud role reference.

What roles do I needWhat roles do I need

The table below lists the roles required to perform a particular action. You can always assign a role offering more permissions than the one specified. For example, you can assign the speech-sense.editor role for a space instead of speech-sense.viewer.

Action

Required roles

Viewing data

Viewing a space and all its projects

speech-sense.auditor

Viewing space and project specifications

speech-sense.viewer

Viewing a project, its channels and dialogs

speech-sense.data.viewer

Project management

Creating a project

speech-sense.editor

Editing project settings

speech-sense.editor

Uploading and rating dialogs

speech-sense.data.editor

Writing comments

speech-sense.data.editor

Creating connections

speech-sense.editor

Creating classifiers

speech-sense.editor

Running analysis

speech-sense.editor

Deleting a project

speech-sense.admin

Granting a role in a project

speech-sense.admin

Space management

Editing space settings

speech-sense.editor

Deleting a space

speech-sense.admin

Granting a role in a space

speech-sense.admin

Was the article helpful?

Previous
Audit Trails events
Next
Pricing policy
© 2025 Direct Cursus Technology L.L.C.