| Access Token Viewer | Read-only visibility into personal access tokens (list and view). |
| Access Token Admin | Full management of personal access tokens: create and delete tokens for the current user as permitted by org policy. |
| IAM Viewer | Read-only visibility across IAM configuration (for example, view organization user permitted actions, SAML configuration, AUP provisioning, API tokens, groups and memberships). |
| IAM Admin | Administrative control over IAM: invite/revoke users, create/delete/update groups and memberships, and configure identity integrations (for example, SAML SSO, AUP provisioning, API tokens). |
| CKS Viewer | Read-only visibility into Kubernetes resources: list and view clusters and VPC resources. |
| CKS Admin | Administrative control over Kubernetes resources: create, update, and delete clusters and VPC resources. |
| Inference Viewer | Read-only visibility into inference resources: list and view gateways, deployments, and capacity claims. |
| Inference Admin | Administrative control over inference resources: create, update, and delete gateways, deployments, and capacity claims. Includes Inference Viewer permissions. |
| Object Storage Admin | Full administration for AI Object Storage: create/delete buckets, manage organization access policies, and create/revoke/list access keys. Includes listing buckets and ensuring/setting bucket access policies. |
| Billing Viewer | Read-only access to billing data, including viewing the billing dashboard, current balance, and listing/downloading invoices. |
| Observability Viewer | Read-only access to observability data (for example, cluster metrics/dashboards) for troubleshooting and performance monitoring. |
| Notifications Viewer | Read-only access to alert history, notification delivery statuses, and the alert configuration page. |
| Notifications Admin | Manage which alerts the organization receives and where they are delivered: subscribe and unsubscribe alerts per destination on the alert configuration page. Includes Notifications Viewer permissions. |
| Integrations Viewer | Read-only visibility into notification destinations and credentials, including the Integrations page and the destinations list on the alert configuration page. |
| Integrations Admin | Full management of notification destinations and credentials: create, update, and delete Slack and webhook integrations. Includes Integrations Viewer permissions. |
| Support Viewer | Read-only access to support tickets/records in the integrated support system (Freshdesk). |
| Access Request Approver | Approves or denies privileged access requests. Can view the list of pending Service Account Management access requests. |