Skip to main content
This table lists the permissions required to perform CoreWeave AI Object Storage actions in the Cloud Console. Object Storage Admins already have these permissions by default. This reference is for granting specific permissions to non-admin users. To grant these permissions to users, you must have the Object Storage Admin role. Then, you can create an organization access policy to grant the permissions to the users. When you grant these permissions to a user, they can perform the corresponding actions in the Cloud Console. For more information about organization access policies, see About organization access policies.
Console featureAI Object Storage permission
List (view) bucketscwobject:ListBucketInfo
Create bucketss3:CreateBucket
cwobject:CreateAccessKey
Delete bucketss3:DeleteBucket (policy can include the ability to delete individual buckets or all buckets)
Create access keyscwobject:CreateAccessKeySAML
cwobject:CreateAccessKey
Revoke access keyscwobject:RevokeAccessKeyByAccessKey
List access keyscwobject:ListAccessKeyInfo
Create or edit organization policiescwobject:EnsureAccessPolicy
Delete organization policiescwobject:DeleteAccessPolicy
View organization policiescwobject:ListAccessPolicy
  • All cwobject: permissions are global operations and must specify "resources": ["*"] in the policy statement.
  • Cloud Console groups aren’t allowed in organization access policies. Use UIDs (from the Cloud Console) or SAML users and groups instead.

Next steps

Last modified on May 29, 2026