To use the generative AI features on Vertex AI, the principals (for example, users, groups, and service accounts) in your project need to be granted the appropriate IAM role. You can also create custom roles to grant a user-defined set of permissions to a principal. This page shows you the applicable IAM roles to grant and the specific permissions needed for each operation so you can create custom roles.
Predefined roles
You can grant the users or groups in your project one of the following predefined roles to give them access to the generative AI features on Vertex AI:
To learn more about Vertex AI IAM roles, see Vertex AI access control with IAM.
Permissions
The following table maps generative AI operations to the permissions required for the operation. If you need fine-grained access control, you can refer to these mappings to create custom roles.
| Operation | Permissions needed |
|---|---|
| Make prompt requests |
|
| Save, view, update, and delete prompts in Vertex AI Studio |
|
| Model tuning |
|
To learn more about Vertex AI IAM permissions, see IAM permissions.
What's next
Enable Data Access audit logs
Enable Data Access audit logs in Vertex AI so that you can monitor usage of your model endpoints.
Control access with IAM
Learn how to use Identity and Access Management (IAM) to manage access to Vertex AI resources.
Introduction to tuning
Learn how to tune a model by providing a training dataset that contains a set of examples of specific downstream tasks.
Responsible AI
Learn about some of the limitations to generative AI and recommended practices for using generative AI.