Access control with IAM

This page describes how to use Identity and Access Management (IAM) to manage access to Colab Enterprise resources. To manage access for other Gemini Enterprise Agent Platform resources, see Agent Platform access control with IAM.

Control access to notebooks with IAM

You can manage access to Colab Enterprise notebooks (IPYNB files) at the project level or per notebook.

  • To grant access to notebooks at the project level, assign one or more roles to a principal (user, group, or service account).
  • To grant access to a specific notebook, assign one or more roles to a principal on the notebook. To learn more, see Manage access to a notebook.

Running code that interacts with other Google Cloud services

Granting access to a notebook is limited to the specific permissions related to interacting with the notebook. For example, you can grant the ability to create a notebook, write code in it, or delete the notebook.

To run code that interacts with other Google Cloud services, you must use one of the following methods:

  • Run code in a runtime with end-user credentials enabled. This means your notebook has the same access to Google Cloud services as your notebook user.

  • Run code that authenticates and authorizes your notebook to interact with Google Cloud services.

To learn more, see Run code that interacts with Google Cloud.

Types of IAM roles

There are different types of IAM roles that can be used in Colab Enterprise:

  • Predefined roles let you grant a set of related permissions to your Colab Enterprise resources at the project level.

  • Basic roles (Owner, Editor, and Viewer) provide access control to your Colab Enterprise resources at the project level, and are common to all Google Cloud services.

  • Custom roles enable you to choose a specific set of permissions, create your own role with those permissions, and grant the role to users in your organization.

To add, update, or remove these roles in your Colab Enterprise project, see the documentation on managing access to projects, folders, and organizations.

Predefined roles for Colab Enterprise

Colab Enterprise is a part of Agent Platform, and Colab Enterprise resources are managed through the Agent Platform API. Therefore, you can grant principals access to Colab Enterprise resources through Agent Platform roles.

The following table includes all Agent Platform predefined roles.

Role Permissions

(roles/aiplatform.admin)

Grants full access to all resources in Agent Platform.

aiplatform.*

  • aiplatform.agentAnomalyDetectionScopes.create
  • aiplatform.agentAnomalyDetectionScopes.delete
  • aiplatform.agentAnomalyDetectionScopes.get
  • aiplatform.agentAnomalyDetectionScopes.list
  • aiplatform.agentExamples.create
  • aiplatform.agentExamples.delete
  • aiplatform.agentExamples.get
  • aiplatform.agentExamples.list
  • aiplatform.agentExamples.update
  • aiplatform.agents.create
  • aiplatform.agents.delete
  • aiplatform.agents.get
  • aiplatform.agents.list
  • aiplatform.agents.update
  • aiplatform.analyzedInvocations.get
  • aiplatform.analyzedInvocations.list
  • aiplatform.analyzedSessions.aggregate
  • aiplatform.analyzedSessions.get
  • aiplatform.analyzedSessions.list
  • aiplatform.annotationSpecs.create
  • aiplatform.annotationSpecs.delete
  • aiplatform.annotationSpecs.get
  • aiplatform.annotationSpecs.list
  • aiplatform.annotationSpecs.update
  • aiplatform.annotations.create
  • aiplatform.annotations.delete
  • aiplatform.annotations.get
  • aiplatform.annotations.list
  • aiplatform.annotations.update
  • aiplatform.apps.create
  • aiplatform.apps.delete
  • aiplatform.apps.get
  • aiplatform.apps.list
  • aiplatform.apps.update
  • aiplatform.artifacts.create
  • aiplatform.artifacts.delete
  • aiplatform.artifacts.get
  • aiplatform.artifacts.list
  • aiplatform.artifacts.update
  • aiplatform.batchPredictionJobs.cancel
  • aiplatform.batchPredictionJobs.create
  • aiplatform.batchPredictionJobs.delete
  • aiplatform.batchPredictionJobs.get
  • aiplatform.batchPredictionJobs.list
  • aiplatform.cacheConfigs.get
  • aiplatform.cacheConfigs.update
  • aiplatform.cachedContents.create
  • aiplatform.cachedContents.delete
  • aiplatform.cachedContents.get
  • aiplatform.cachedContents.list
  • aiplatform.cachedContents.update
  • aiplatform.consents.get
  • aiplatform.consents.update
  • aiplatform.contexts.addContextArtifactsAndExecutions
  • aiplatform.contexts.addContextChildren
  • aiplatform.contexts.create
  • aiplatform.contexts.delete
  • aiplatform.contexts.get
  • aiplatform.contexts.list
  • aiplatform.contexts.queryContextLineageSubgraph
  • aiplatform.contexts.update