Skip to main content
Organization access policies authorize the principals in your organization to take CoreWeave AI Object Storage actions. They aren’t a blanket control over every bucket. A policy in your organization applies to principals from your organization. It doesn’t apply to principals from another organization, and it can’t grant or block unauthenticated access. This page is for administrators who need to grant Object Storage actions to principals in their organization. Written in JSON with the same syntax as bucket access policies, organization access policies apply to both the S3-compatible API and the AI Object Storage API. For an authenticated request to succeed, the requesting principal’s organization access policy must allow it. When the target bucket has a bucket access policy, that policy must also allow it.
Unauthenticated requests skip organization access policies. Access from another organization requires a bucket access policy, and that principal’s own organization access policy must also allow the action. For more information, see Policy evaluation.
Set your organization access policies after you create access tokens and keys, and before bucket operations.

Key considerations

AI Object Storage organization access policies have specific aspects and considerations to understand: Learn how to set an organization access policy or view examples of organization access policies.
Last modified on October 8, 2026