Skip to main content
A role is the unit of access you assign in a policy rule. Each role grants a fixed set of actions. Most services have a Viewer role for read-only access and an Admin role for full management. Assign the least privileged role that lets a principal do their job. The following roles are grouped by functional area to help you pick the right one. The description states what the role grants. The “When to assign” column suggests who typically needs it.

Access control and IAM

These roles manage identities, groups, access policies, and personal access tokens.

CKS clusters

These roles manage CoreWeave Kubernetes Service clusters and VPC resources.

Inference

These roles manage inference gateways, deployments, and capacity claims.

Sandbox

These roles manage CoreWeave Sandbox profiles, runners, and sandbox execution.

Bare metal

These roles manage the CoreWeave Bare Metal Service (limited availability), including BMC serial console access to nodes. Contact support to request access.

Object storage

This role administers CoreWeave AI Object Storage control plane resources. Access to bucket data (buckets and objects) through the S3-compatible API is governed separately by organization and bucket access policies, not by this role.

Observability and telemetry

These roles cover observability data and Telemetry Relay configuration.

Billing

This role grants read-only access to billing data.

Notifications and integrations

These roles manage alert subscriptions and the destinations that receive them.

Support

This role grants read-only access to support records. Administrators can manage resources in the Cloud Console, the API, and with infrastructure-as-code (IaC) tools like Terraform.

Legacy group role assignments

Before IAM Access Policies, user permissions were determined by the legacy group a user belonged to. The following table shows how each legacy group maps to the new IAM roles: Roles added for newer platform features may not be automatically included in legacy admin policies. If you expect access to a feature but can’t reach it, check your organization’s access policies and add the relevant role if it’s missing. You can review and modify these role assignments or create new groups with different role combinations using IAM Access Policy management.

Next steps

Last modified on July 31, 2026