[Yandex Cloud documentation](../../index.md) > [Yandex Cloud Functions](../index.md) > Access management

# Access management in Cloud Functions

In this section, you will learn about the following:

* [Resources you can assign a role for](#resources).
* [Roles this service has](#roles-list).

## Access management {#about-access-control}

[Yandex Identity and Access Management](../../iam/index.md) checks all operations in Yandex Cloud. If an entity does not have required permissions, IAM returns an error.


To grant permissions for a resource, [assign](../../iam/operations/roles/grant.md) the relevant resource roles to an entity performing operations. You can assign roles to a [Yandex account](../../iam/concepts/users/accounts.md#passport), [service account](../../iam/concepts/users/service-accounts.md), [local user](../../iam/concepts/users/accounts.md#local), [federated user](../../iam/concepts/federations.md), [user group](../../organization/operations/manage-groups.md), [system group](../../iam/concepts/access-control/system-group.md), or [public group](../../iam/concepts/access-control/public-group.md). For more information, see [How access management works in Yandex Cloud](../../iam/concepts/access-control/index.md).

To assign a role for a resource, you need the `functions.admin` role or one of the following roles for that resource:

* `admin`
* `resource-manager.admin`
* `organization-manager.admin`
* `resource-manager.clouds.owner`
* `organization-manager.organizations.owner`

{% note info %}

The ability to call and manage functions from specific [cloud networks](../../vpc/concepts/network.md#network) or IP addresses, or associate functions with specific cloud networks may be restricted by [access policies](../../iam/concepts/access-control/access-policies.md) at the [folder](../../resource-manager/concepts/resources-hierarchy.md#folder), [cloud](../../resource-manager/concepts/resources-hierarchy.md#cloud), or [organization](../../organization/concepts/organization.md) level. 

{% endnote %}

## Resources you can assign a role for {#resources}

You can assign a role to an [organization](../../organization/concepts/organization.md), [cloud](../../resource-manager/concepts/resources-hierarchy.md#cloud), or [folder](../../resource-manager/concepts/resources-hierarchy.md#folder). The roles assigned to organizations, clouds, and folders also apply to their nested resources.

To assign a role for a [function](../concepts/function.md), use the Yandex Cloud [CLI](../../cli/cli-ref/serverless/cli-ref/function/add-access-binding.md), [API](../api-ref/functions/authentication.md), or [Terraform](../../terraform/resources/function_iam_binding.md).

## Roles this service has {#roles-list}

The list below shows all the roles used for access control in Cloud Functions.

```mermaid
flowchart BT
    functions.editor --> functions.admin
    functions.mdbProxiesUser --> functions.editor
    functions.viewer --> functions.editor
    functions.functionInvoker --> functions.editor
    functions.auditor --> functions.viewer
```

### Service roles {#service-roles}

#### functions.auditor {#functions-auditor}

The `functions.auditor` role enables viewing info on functions, triggers, and connections to managed databases.

Users with this role can:
* View the list of [functions](../concepts/function.md) and info on them.
* View the list of [triggers](../concepts/trigger/index.md) and info on them.
* View the list of database connections and info on them.
* View info on granted [access permissions](../../iam/concepts/access-control/index.md) for Cloud Functions resources.

#### functions.viewer {#functions-viewer}

The `functions.viewer` role enables viewing info on functions, triggers, and connections to managed databases, as well as on Cloud Functions quotas.

Users with this role can:
* View the list of [functions](../concepts/function.md) and info on them.
* View the list of [triggers](../concepts/trigger/index.md) and info on them.
* View the list of database connections and info on them.
* View info on granted [access permissions](../../iam/concepts/access-control/index.md) for Cloud Functions resources.
* View info on Cloud Functions [quotas](../concepts/limits.md#functions-quotas).
* View info on the relevant [cloud](../../resource-manager/concepts/resources-hierarchy.md#cloud).
* View info on the relevant [folder](../../resource-manager/concepts/resources-hierarchy.md#folder).

This role includes the `functions.auditor` permissions.

#### functions.functionInvoker {#functions-functionInvoker}

The `functions.functionInvoker` role enables invoking [functions](../concepts/function.md).

#### functions.editor {#functions-editor}

The `functions.editor` role enables managing functions, triggers, API gateways, and connections to managed databases.

Users with this role can:
* View the list of [functions](../concepts/function.md) and info on them, create functions and their [versions](../concepts/function.md#version), and modify, invoke, and delete functions.
* View the function version [environment variables](../concepts/runtime/environment-variables.md) and code.
* View the list of [triggers](../concepts/trigger/index.md) and info on them, as well as create, stop, run, modify, and delete them.
* View the list of database connections and the info on them, as well as create, modify, and delete database connections and connect to databases through functions.
* Create, modify, and delete [API gateways](../../api-gateway/concepts/index.md).
* View info on granted [access permissions](../../iam/concepts/access-control/index.md) for Cloud Functions resources.
* View info on Cloud Functions [quotas](../concepts/limits.md#functions-quotas).
* View info on the relevant [cloud](../../resource-manager/concepts/resources-hierarchy.md#cloud).
* View info on the relevant [folder](../../resource-manager/concepts/resources-hierarchy.md#folder).

This role includes the `functions.viewer` permissions.

#### functions.mdbProxiesUser {#functions-mdbProxiesUser}

The `functions.mdbProxiesUser` role enables connecting to managed databases through [functions](../concepts/function.md).

#### functions.admin {#functions-admin}

The `functions.admin` role enables managing functions, triggers, API gateways, and connections to managed databases, as well as access to those.

Users with this role can:
* View info on the granted [access permissions](../../iam/concepts/access-control/index.md) to the Cloud Functions resources and modify such access permissions.
* View the list of [functions](../concepts/function.md) and info on them, create functions and their [versions](../concepts/function.md#version), and modify, invoke, and delete functions.
* View the function version [environment variables](../concepts/runtime/environment-variables.md) and code.
* View the list of [triggers](../concepts/trigger/index.md) and info on them, as well as create, stop, run, modify, and delete them.
* View the list of database connections and the info on them, as well as create, modify, and delete database connections and connect to databases through functions.
* Create, modify, and delete [API gateways](../../api-gateway/concepts/index.md).
* View info on Cloud Functions [quotas](../concepts/limits.md#functions-quotas).
* View info on the relevant [cloud](../../resource-manager/concepts/resources-hierarchy.md#cloud).
* View info on the relevant [folder](../../resource-manager/concepts/resources-hierarchy.md#folder).

This role includes the `functions.editor` permissions.

### Primitive roles {#primitive-roles}

Primitive roles allow users to perform actions in all Yandex Cloud [services](../../overview/concepts/services.md).

#### auditor {#auditor}

The `auditor` role grants a permission to read configuration and metadata of any Yandex Cloud resources without any access to data.

For instance, users with this role can:
* View info on a [resource](../../resource-manager/concepts/resources-hierarchy.md).
* View the resource metadata.
* View the list of operations with a resource.

`auditor` is the most secure role that does not grant any access to the [service](../../overview/concepts/services.md) data. This role suits the users who need minimum access to the Yandex Cloud resources.

#### viewer {#viewer}

The `viewer` role grants the permissions to read the info on any Yandex Cloud [resources](../../resource-manager/concepts/resources-hierarchy.md).

This role includes the `auditor` permissions.

Unlike `auditor`, the `viewer` role provides access to [service](../../overview/concepts/services.md) data in read mode.

#### editor {#editor}

The `editor` role provides permissions to manage any Yandex Cloud [resources](../../resource-manager/concepts/resources-hierarchy.md), except for assigning roles to other users, transferring [organization](../../organization/concepts/organization.md) ownership, removing an organization, and deleting Key Management Service [encryption keys](../../kms/concepts/index.md).

For instance, users with this role can create, modify, and delete resources.

This role includes the `viewer` permissions.

#### admin {#admin}

The `admin` role enables assigning any roles, except for `resource-manager.clouds.owner` and `organization-manager.organizations.owner`, and provides permissions to manage any Yandex Cloud [resources](../../resource-manager/concepts/resources-hierarchy.md) (except for transferring [organization](../../organization/concepts/organization.md) ownership and removing an organization).

Prior to assigning the `admin` role for an organization, [cloud](../../resource-manager/concepts/resources-hierarchy.md#cloud), or [billing account](../../billing/concepts/billing-account.md), make sure to check out the information on protecting [privileged accounts](../../security/standard/all.md#privileged-users).

This role includes the `editor` permissions.

Instead of primitive roles, we recommend using service roles with more granular access control, allowing you to implement the [least privilege principle](../../security/standard/all.md#min-privileges).

For more information on primitive roles, see the [Yandex Cloud role reference](../../iam/roles-reference.md#primitive-roles).