> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.nvidia.com/nemo-platform/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.nvidia.com/nemo-platform/_mcp/server.

# Permissions Reference

Complete reference of all permissions across the NeMo Platform APIs. Each permission controls access to a specific operation within an individual API. Permissions are assigned to users through [roles](/documentation/access-control/authorization/roles-and-permissions).

For token-level access restrictions, see [API Scopes](/documentation/access-control/authorization/api-scopes). For the RBAC model, see [Authorization Concepts](/documentation/access-control/concepts).

PlatformAdmin is omitted — it bypasses permission checks entirely at the policy level.

## Entities API

| Permission                                                 | Description                           | Viewer | Editor | Admin |
| ---------------------------------------------------------- | ------------------------------------- | :----: | :----: | :---: |
| <code>entities.(read \| create \| update \| delete)</code> | Read, create, update, delete entities |        |        |       |

## Files API

| Permission                                         | Description                  | Viewer | Editor | Admin |
| -------------------------------------------------- | ---------------------------- | :----: | :----: | :---: |
| <code>filesets.(read \| list)</code>               | Read, list files             |    ✓   |    ✓   |   ✓   |
| <code>filesets.(create \| update \| delete)</code> | Create, update, delete files |        |    ✓   |   ✓   |

## Guardrails API

| Permission                                                   | Description                               | Viewer | Editor | Admin |
| ------------------------------------------------------------ | ----------------------------------------- | :----: | :----: | :---: |
| `guardrails.checks.exec`                                     | Execute guardrail checks                  |        |    ✓   |   ✓   |
| <code>guardrails.configs.(read \| list)</code>               | Read, list guardrails configs             |    ✓   |    ✓   |   ✓   |
| <code>guardrails.configs.(create \| update \| delete)</code> | Create, update, delete guardrails configs |        |    ✓   |   ✓   |

## IAM API

| Permission                                          | Description                                                     | Viewer | Editor | Admin |
| --------------------------------------------------- | --------------------------------------------------------------- | :----: | :----: | :---: |
| <code>iam.(read \| list \| create \| delete)</code> | Read, list, create, delete iam                                  |        |        |   ✓   |
| `iam.bundle.read`                                   | Download OPA authorization bundle (external OPA / advanced ops) |        |        |       |

## Inference API

| Permission                                                         | Description                                     | Viewer | Editor | Admin |
| ------------------------------------------------------------------ | ----------------------------------------------- | :----: | :----: | :---: |
| <code>inference.deployment-configs.(read \| list)</code>           | Read, list inference deployment-configs         |    ✓   |    ✓   |   ✓   |
| <code>inference.deployment-configs.(create \| delete)</code>       | Create, delete inference deployment-configs     |        |    ✓   |   ✓   |
| <code>inference.deployments.(read \| list)</code>                  | Read, list inference deployments                |    ✓   |    ✓   |   ✓   |
| <code>inference.deployments.(create \| update \| delete)</code>    | Create, update, delete inference deployments    |        |    ✓   |   ✓   |
| `inference.gateway.model.exec`                                     | Execute model gateway inference                 |    ✓   |    ✓   |   ✓   |
| `inference.gateway.openai.exec`                                    | Execute OpenAI-compatible gateway inference     |    ✓   |    ✓   |   ✓   |
| `inference.gateway.provider.exec`                                  | Execute provider gateway inference              |    ✓   |    ✓   |   ✓   |
| <code>inference.providers.(read \| list)</code>                    | Read, list inference providers                  |    ✓   |    ✓   |   ✓   |
| <code>inference.providers.(create \| update \| delete)</code>      | Create, update, delete inference providers      |        |    ✓   |   ✓   |
| <code>inference.virtual-models.(read \| list)</code>               | Read, list inference virtual-models             |    ✓   |    ✓   |   ✓   |
| <code>inference.virtual-models.(create \| update \| delete)</code> | Create, update, delete inference virtual-models |        |    ✓   |   ✓   |

## Intake API

| Permission                                                         | Description                                     | Viewer | Editor | Admin |
| ------------------------------------------------------------------ | ----------------------------------------------- | :----: | :----: | :---: |
| <code>intake.annotations.(read \| list)</code>                     | Read, list intake annotations                   |    ✓   |    ✓   |   ✓   |
| <code>intake.annotations.(create \| delete)</code>                 | Create, delete intake annotations               |        |    ✓   |   ✓   |
| <code>intake.evaluator-results.(read \| list)</code>               | Read, list intake evaluator-results             |    ✓   |    ✓   |   ✓   |
| `intake.evaluator-results.create`                                  | Create intake evaluator results                 |        |    ✓   |   ✓   |
| `intake.experiment-groups.read`                                    | Read intake experiment groups                   |    ✓   |    ✓   |   ✓   |
| <code>intake.experiment-groups.(create \| update \| delete)</code> | Create, update, delete intake experiment-groups |        |    ✓   |   ✓   |
| `intake.experiments.read`                                          | Read intake experiments                         |    ✓   |    ✓   |   ✓   |
| <code>intake.experiments.(create \| update \| delete)</code>       | Create, update, delete intake experiments       |        |    ✓   |   ✓   |
| `intake.ingest.create`                                             | Ingest traces into intake                       |        |    ✓   |   ✓   |
| <code>intake.spans.(read \| list)</code>                           | Read, list intake spans                         |    ✓   |    ✓   |   ✓   |
| `intake.traces.read`                                               | Read intake traces                              |    ✓   |    ✓   |   ✓   |

## Jobs API

| Permission                                               | Description                         | Viewer | Editor | Admin |
| -------------------------------------------------------- | ----------------------------------- | :----: | :----: | :---: |
| <code>jobs.(read \| list)</code>                         | Read, list jobs                     |    ✓   |    ✓   |   ✓   |
| <code>jobs.(create \| update \| delete \| cancel)</code> | Create, update, delete, cancel jobs |        |    ✓   |   ✓   |

## Models API

| Permission                                                | Description                                                                                      | Viewer | Editor | Admin |
| --------------------------------------------------------- | ------------------------------------------------------------------------------------------------ | :----: | :----: | :---: |
| <code>models.(read \| list)</code>                        | Read, list models                                                                                |    ✓   |    ✓   |   ✓   |
| <code>models.(create \| update \| delete)</code>          | Create, update, delete models                                                                    |        |    ✓   |   ✓   |
| <code>models.adapters.(read \| list)</code>               | Read, list models adapters                                                                       |    ✓   |    ✓   |   ✓   |
| <code>models.adapters.(create \| update \| delete)</code> | Create, update, delete models adapters                                                           |        |    ✓   |   ✓   |
| `models.prompts.read`                                     | Read model prompts                                                                               |    ✓   |    ✓   |   ✓   |
| <code>models.prompts.(create \| update \| delete)</code>  | Create, update, delete models prompts                                                            |        |    ✓   |   ✓   |
| `models.prompts.list`                                     | List model prompts                                                                               |        |        |       |
| `models.tool-call-plugin.set`                             | Whether this user can set tool\_call\_plugin on Models or Deployment Configs *(policy-enforced)* |        |        |   ✓   |
| `models.trust-remote-code.set`                            | Whether this user can set trust\_remote\_code on Models *(policy-enforced)*                      |        |        |   ✓   |

## Platform

| Permission       | Description                                             | Viewer | Editor | Admin |
| ---------------- | ------------------------------------------------------- | :----: | :----: | :---: |
| `platform.admin` | Platform-wide administrative bypass *(policy-enforced)* |        |        |       |

## Projects API

| Permission                                         | Description                     | Viewer | Editor | Admin |
| -------------------------------------------------- | ------------------------------- | :----: | :----: | :---: |
| <code>projects.(read \| list)</code>               | Read, list projects             |    ✓   |    ✓   |   ✓   |
| <code>projects.(create \| update \| delete)</code> | Create, update, delete projects |        |    ✓   |   ✓   |

## Safe Synthesizer API

| Permission                                                                      | Description                                              | Viewer | Editor | Admin |
| ------------------------------------------------------------------------------- | -------------------------------------------------------- | :----: | :----: | :---: |
| <code>safe-synthesizer.jobs.(read \| list \| create \| delete \| cancel)</code> | Read, list, create, delete, cancel safe synthesizer jobs |        |        |       |

## Secrets API

| Permission                                        | Description                    | Viewer | Editor | Admin |
| ------------------------------------------------- | ------------------------------ | :----: | :----: | :---: |
| <code>secrets.(read \| list)</code>               | Read, list secrets             |    ✓   |    ✓   |   ✓   |
| <code>secrets.(create \| update \| delete)</code> | Create, update, delete secrets |        |    ✓   |   ✓   |
| <code>secrets.(access \| rotate)</code>           | Access, rotate secrets         |        |        |       |

## Workspaces API

| Permission                                                           | Description                                     | Viewer | Editor | Admin |
| -------------------------------------------------------------------- | ----------------------------------------------- | :----: | :----: | :---: |
| <code>workspaces.(read \| list)</code>                               | Read, list workspaces                           |    ✓   |    ✓   |   ✓   |
| <code>workspaces.(update \| delete)</code>                           | Update, delete workspaces                       |        |    ✓   |   ✓   |
| <code>workspaces.members.(list \| create \| update \| delete)</code> | List, create, update, delete workspaces members |        |        |   ✓   |
| `workspaces.members.read`                                            | Read workspace member details                   |        |        |       |

## Related

* [Roles & Permissions](/documentation/access-control/authorization/roles-and-permissions) — Role descriptions and hierarchy.
* [API Scopes](/documentation/access-control/authorization/api-scopes) — Token-level scope restrictions.
* [Authorization Concepts](/documentation/access-control/concepts) — Workspaces, roles, bindings, and the RBAC model.
* [Security Model](/documentation/access-control/security-model) — Trust boundaries and authorization layers.