Permissions Reference

View as Markdown

Complete reference of all permissions across the NeMo Platform APIs. Each permission controls access to a specific operation within an individual API. Permissions are assigned to users through roles.

For token-level access restrictions, see API Scopes. For the RBAC model, see Authorization Concepts.

PlatformAdmin is omitted — it bypasses permission checks entirely at the policy level.

Entities API

PermissionDescriptionViewerEditorAdmin
entities.(read | create | update | delete)Read, create, update, delete entities

Files API

PermissionDescriptionViewerEditorAdmin
filesets.(read | list)Read, list files
filesets.(create | update | delete)Create, update, delete files

Guardrails API

PermissionDescriptionViewerEditorAdmin
guardrails.checks.execExecute guardrail checks
guardrails.configs.(read | list)Read, list guardrails configs
guardrails.configs.(create | update | delete)Create, update, delete guardrails configs

IAM API

PermissionDescriptionViewerEditorAdmin
iam.(read | list | create | delete)Read, list, create, delete iam
iam.bundle.readDownload OPA authorization bundle (external OPA / advanced ops)

Inference API

PermissionDescriptionViewerEditorAdmin
inference.deployment-configs.(read | list)Read, list inference deployment-configs
inference.deployment-configs.(create | delete)Create, delete inference deployment-configs
inference.deployments.(read | list)Read, list inference deployments
inference.deployments.(create | update | delete)Create, update, delete inference deployments
inference.gateway.model.execExecute model gateway inference
inference.gateway.openai.execExecute OpenAI-compatible gateway inference
inference.gateway.provider.execExecute provider gateway inference
inference.providers.(read | list)Read, list inference providers
inference.providers.(create | update | delete)Create, update, delete inference providers
inference.virtual-models.(read | list)Read, list inference virtual-models
inference.virtual-models.(create | update | delete)Create, update, delete inference virtual-models

Intake API

PermissionDescriptionViewerEditorAdmin
intake.annotations.(read | list)Read, list intake annotations
intake.annotations.(create | delete)Create, delete intake annotations
intake.evaluator-results.(read | list)Read, list intake evaluator-results
intake.evaluator-results.createCreate intake evaluator results
intake.experiment-groups.readRead intake experiment groups
intake.experiment-groups.(create | update | delete)Create, update, delete intake experiment-groups
intake.experiments.readRead intake experiments
intake.experiments.(create | update | delete)Create, update, delete intake experiments
intake.ingest.createIngest traces into intake
intake.spans.(read | list)Read, list intake spans
intake.traces.readRead intake traces

Jobs API

PermissionDescriptionViewerEditorAdmin
jobs.(read | list)Read, list jobs
jobs.(create | update | delete | cancel)Create, update, delete, cancel jobs

Models API

PermissionDescriptionViewerEditorAdmin
models.(read | list)Read, list models
models.(create | update | delete)Create, update, delete models
models.adapters.(read | list)Read, list models adapters
models.adapters.(create | update | delete)Create, update, delete models adapters
models.prompts.readRead model prompts
models.prompts.(create | update | delete)Create, update, delete models prompts
models.prompts.listList model prompts
models.tool-call-plugin.setWhether this user can set tool_call_plugin on Models or Deployment Configs (policy-enforced)
models.trust-remote-code.setWhether this user can set trust_remote_code on Models (policy-enforced)

Platform

PermissionDescriptionViewerEditorAdmin
platform.adminPlatform-wide administrative bypass (policy-enforced)

Projects API

PermissionDescriptionViewerEditorAdmin
projects.(read | list)Read, list projects
projects.(create | update | delete)Create, update, delete projects

Safe Synthesizer API

PermissionDescriptionViewerEditorAdmin
safe-synthesizer.jobs.(read | list | create | delete | cancel)Read, list, create, delete, cancel safe synthesizer jobs

Secrets API

PermissionDescriptionViewerEditorAdmin
secrets.(read | list)Read, list secrets
secrets.(create | update | delete)Create, update, delete secrets
secrets.(access | rotate)Access, rotate secrets

Workspaces API

PermissionDescriptionViewerEditorAdmin
workspaces.(read | list)Read, list workspaces
workspaces.(update | delete)Update, delete workspaces
workspaces.members.(list | create | update | delete)List, create, update, delete workspaces members
workspaces.members.readRead workspace member details