---
name: transit-gateway-iam
title: Using IAM permissions with IBM Cloud Transit Gateway
description: IBM Cloud&reg; Transit Gateway uses the IBM Cloud Identity and Access Management (IAM) platform access roles to manage access to the service's resources. IAM access roles allow account administrators to assign different levels of permission for using the service. The following tables provide the list of actions that you can take against the IBM Cloud Transit Gateway service and its resources depending on a user assigned roles.
last-updated: 2026-08-04
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/transit-gateway?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Using IAM permissions with IBM Cloud Transit Gateway
{: #iam}

IBM Cloud&reg; Transit Gateway uses the IBM Cloud Identity and Access Management (IAM) platform access roles to manage access to the service's resources. IAM access roles allow account administrators to assign different levels of permission for using the service. The following tables provide the list of actions that you can take against the IBM Cloud Transit Gateway service and its resources depending on a user assigned roles.
{: shortdesc}



## Platform-access roles
{: #platform-roles-iam}

IBM Cloud Transit Gateway supports Administrator, Editor, Operator, and Viewer platform-access roles.

| Role | Description of Actions | Actions |
| --- | --- | --- |
| Administrator | Can perform all actions, including managing gateways and connections, and assign IBM Cloud Transit Gateway IAM access policies to other users. | Create gateways \n Delete gateways \n Edit gateways \n Add or remove gateway connections \n Accept or reject a cross account connection request \n Edit gateway connections \n Update user access policies for the service |
| Editor | Can perform all actions, including managing gateways and connections, but can't assign IBM Cloud Transit Gateway IAM access policies to other users. | Create gateways \n Delete gateways \n Edit gateways \n Add or remove gateway connections \n Accept or reject a cross account connection request \n Edit gateway connections |
| Operator and Viewer | Can only perform actions that don't change the state of resources. | List gateways \n Get gateways \n List a gateway's connections \n View a gateway's connections \n View incoming connection requests |
{: caption="IAM platform-access user roles and actions" caption-side="bottom"}

To add or remove connections to VPCs, or to accept or reject a cross-account connection request, you must also have Administrator or Editor platform-access role permission to the VPC being connected to. For more information, see [VPC: Getting started with IAM](https://cloud.ibm.com/docs/vpc?topic=vpc-iam-getting-started&format=markdown).

To add or remove connections to Direct Links, you must also have Administrator or Editor platform-access role permission to the Direct Link being connected to. For more information, see [Managing access for IBM Cloud Direct Link](https://cloud.ibm.com/docs/dl?topic=dl-iam&format=markdown).
{: note}

## Service name
{: #transit-service-name}

The service name that you designate varies depending on how you access IBM Cloud Transit Gateway. If you are using the IBM Cloud CLI, APIs, or Terraform, then use `transit` for your service name. If you are using the UI, `Transit Gateway` must be the service name.