Access control and IAM
These roles manage identities, groups, access policies, and personal access tokens.CKS clusters
These roles manage CoreWeave Kubernetes Service clusters and VPC resources.Inference
These roles manage inference gateways, deployments, and capacity claims.Sandbox
These roles manage CoreWeave Sandbox profiles, runners, and sandbox execution.Bare metal
These roles manage the CoreWeave Bare Metal Service (limited availability), including BMC serial console access to nodes. Contact support to request access.Object storage
This role administers CoreWeave AI Object Storage control plane resources. Access to bucket data (buckets and objects) through the S3-compatible API is governed separately by organization and bucket access policies, not by this role.Observability and telemetry
These roles cover observability data and Telemetry Relay configuration.Billing
This role grants read-only access to billing data.Notifications and integrations
These roles manage alert subscriptions and the destinations that receive them.Support
This role grants read-only access to support records.
Administrators can manage resources in the Cloud Console, the API, and with infrastructure-as-code (IaC) tools like Terraform.
Legacy group role assignments
Before IAM Access Policies, user permissions were determined by the legacy group a user belonged to. The following table shows how each legacy group maps to the new IAM roles:
Roles added for newer platform features may not be automatically included in legacy admin policies. If you expect access to a feature but can’t reach it, check your organization’s access policies and add the relevant role if it’s missing.
You can review and modify these role assignments or create new groups with different role combinations using IAM Access Policy management.
Next steps
- Learn about IAM Access Policies.
- Create an IAM Access Policy.