Skip to main content

Manage access to storage

Access to block storage is regulated by the role-based model, which defines access within an account. For more information, see Access Control in Servercore Products. You can view the capabilities of roles within all products in the role reference guide.

member

A user with full access to all Servercore products. Does not have management access for: users, service users, user groups, and federations.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations with storage

In the Account access scope:

  • storage management:

    • ordering storage;
    • modifying storage;
    • canceling storage

In the Project access scope, operations with storage are unavailable

billing

A user with access to billing management and no access to service management.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations with storage
  • billing management:

    • balance top-ups and transferring funds between balances;
    • management of autobills, monthly payments, payment deferrals;
    • management of balance notifications;
    • bank card management;
    • viewing reporting documents;
    • management of the partner program and fund withdrawal;
  • viewing connected services and service statuses

iam.admin

A user with access to user management and no access to services or billing. Cannot manage their own account: change permissions, manage notifications, or delete the user. The first user with the iam.admin role is created by the Account Owner.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations with storage

iam.viewer

A user with access to view everything managed by iam.admin.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

reader

A user with access to view everything managed by member in the same access scope.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations with storage

In the Account access scope:

  • viewing the list of storage devices and information about them

In the Project access scope, operations with storage are unavailable

dedicated.admin

A user with access to storage management.

The dedicated.admin role also provides access to managing:

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations with storage

In the Account access scope:

  • storage management:

    • ordering storage;
    • modifying storage;
    • canceling storage

In the Project access scope, operations with storage are unavailable

dedicated.viewer

A user with access to view everything managed by dedicated.admin in the same access scope.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations with storage

In the Account access scope:

  • viewing the list of storage devices and information about them

In the Project access scope, operations with storage are unavailable