Permissions Reference#
Complete reference of all permissions across the NeMo Platform APIs. Each permission controls access to a specific operation within an individual API. Permissions are assigned to users through roles.
For token-level access restrictions, see API Scopes. For the RBAC model, see Authorization Concepts.
Note
PlatformAdmin is omitted — it bypasses permission checks entirely at the policy level.
Audit API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list audit configs |
✓ |
✓ |
✓ |
|
Create, update, delete audit configs |
✓ |
✓ |
|
|
Read audit service info |
✓ |
✓ |
✓ |
|
Read, list audit jobs |
✓ |
✓ |
✓ |
|
Create, update, delete, cancel audit jobs |
✓ |
✓ |
|
|
Read, list audit plugins |
✓ |
✓ |
✓ |
|
Read, list audit targets |
✓ |
✓ |
✓ |
|
Create, update, delete audit targets |
✓ |
✓ |
Customization API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list customization jobs |
✓ |
✓ |
✓ |
|
Create, update, delete, cancel customization jobs |
✓ |
✓ |
Data Designer API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list data designer jobs |
✓ |
✓ |
✓ |
|
Create, delete, cancel data designer jobs |
✓ |
✓ |
|
|
Execute data designer previews |
✓ |
✓ |
Entities API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, create, update, delete entities |
Evaluation API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list evaluation benchmarks |
✓ |
✓ |
✓ |
|
Create, delete evaluation benchmarks |
✓ |
✓ |
|
|
Read, list evaluation jobs |
✓ |
✓ |
✓ |
|
Create, delete, cancel evaluation jobs |
✓ |
✓ |
|
|
Execute live evaluations |
✓ |
✓ |
|
|
Read, list evaluation metrics |
✓ |
✓ |
✓ |
|
Create, delete evaluation metrics |
✓ |
✓ |
Files API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list files |
✓ |
✓ |
✓ |
|
Create, update, delete files |
✓ |
✓ |
Guardrails API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Execute guardrail chat completions |
✓ |
✓ |
|
|
Execute guardrail checks |
✓ |
✓ |
|
|
Execute guardrail completions |
✓ |
✓ |
|
|
Read, list guardrails configs |
✓ |
✓ |
✓ |
|
Create, update, delete guardrails configs |
✓ |
✓ |
IAM API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list, create, delete iam |
✓ |
Inference API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list inference deployment-configs |
✓ |
✓ |
✓ |
|
Create, delete inference deployment-configs |
✓ |
✓ |
|
|
Read, list inference deployments |
✓ |
✓ |
✓ |
|
Create, update, delete inference deployments |
✓ |
✓ |
|
|
Execute model gateway inference |
✓ |
✓ |
✓ |
|
Execute OpenAI-compatible gateway inference |
✓ |
✓ |
✓ |
|
Execute provider gateway inference |
✓ |
✓ |
✓ |
|
Read, list inference providers |
✓ |
✓ |
✓ |
|
Create, update, delete inference providers |
✓ |
✓ |
Jobs API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list jobs |
✓ |
✓ |
✓ |
|
Create, update, delete, cancel jobs |
✓ |
✓ |
Models API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list models |
✓ |
✓ |
✓ |
|
Create, update, delete models |
✓ |
✓ |
|
|
Read, list models adapters (policy-enforced) |
✓ |
✓ |
✓ |
|
Create, update, delete models adapters |
✓ |
✓ |
|
|
Whether this user can set trust_remote_code on Models (policy-enforced) |
✓ |
Platform#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Platform-wide administrative bypass (policy-enforced) |
Projects API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list projects |
✓ |
✓ |
✓ |
|
Create, update, delete projects |
✓ |
✓ |
Safe Synthesizer API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list safe synthesizer jobs |
✓ |
✓ |
✓ |
|
Create, delete, cancel safe synthesizer jobs |
✓ |
✓ |
Secrets API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list secrets |
✓ |
✓ |
✓ |
|
Create, update, delete secrets |
✓ |
✓ |
|
|
Access, rotate secrets |
Workspaces API#
Permission |
Description |
Viewer |
Editor |
Admin |
|---|---|---|---|---|
|
Read, list workspaces |
✓ |
✓ |
✓ |
|
Update, delete workspaces |
✓ |
✓ |
|
|
Read, list, create, update, delete workspaces members |
✓ |