---
name: workload-protection-iam
title: Assigning access to Workload Protection
description: Access to Workload Protection is controlled by IBM Cloud&reg; Identity and Access Management (IAM). Every user that accesses the Workload Protection service in your account must be assigned an access policy with an IAM role. The policy determines which actions a user can perform within the context of Workload Protection.
last-updated: 2026-07-01
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/workload-protection?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Assigning access to Workload Protection
{: #iam}

Access to Workload Protection is controlled by IBM Cloud&reg; Identity and Access Management (IAM). Every user that accesses the Workload Protection service in your account must be assigned an access policy with an IAM role. The policy determines which actions a user can perform within the context of Workload Protection.
{: shortdesc}

Users in an account must be assigned a platform role to manage instances and to launch Workload Protection from IBM Cloud. In addition, users must have a service role that defines the permissions to work with Workload Protection.
{: important}

To organize a set of users and service IDs into a single entity that makes it easy for you to manage IAM permissions, [use access groups](https://cloud.ibm.com/docs/iam?topic=iam-groups&interface=ui&format=markdown). You can assign a single policy to the group instead of assigning the same access multiple times for each individual user or service ID. For more information, go to [How IAM access works](https://cloud.ibm.com/docs/account?topic=account-account_setup&format=markdown#how_access). 


## Managing access by using access groups
{: #iam_groups}

To manage access groups, you must be the account owner, administrator, or editor on all Identity and Access-enabled services in the account, or the assigned administrator or editor for the IAM Access Groups Service.
{: note}

Use the following actions to manage IAM access groups in the IBM Cloud:

* [Creating an access group](https://cloud.ibm.com/docs/iam?topic=iam-groups&interface=ui&format=markdown#create_ag).
* [Assigning access to a group](https://cloud.ibm.com/docs/iam?topic=iam-groups&interface=ui&format=markdown#access_ag).

## Managing access by assigning policies directly to users
{: #iam_users}

To manage access or assign new access to users by using IAM policies, you must be the account owner, administrator on all services in the account, or an administrator for the particular service or service instance.

Use the following actions to manage IAM policies in the IBM Cloud:

* To grant permissions to a user, see [Assigning access to resources](https://cloud.ibm.com/docs/iam?topic=iam-assign-access-resources&interface=ui&format=markdown#access-resources-console).
* To revoke permissions, see [Removing access](https://cloud.ibm.com/docs/iam?topic=iam-assign-access-resources&interface=ui&format=markdown#removing-access-console).
* To review a user's permissions, see [Reviewing assigned access](https://cloud.ibm.com/docs/iam?topic=iam-assign-access-resources&interface=ui&format=markdown#review-your-access-console).

## IBM Cloud platform roles
{: #iam_platform}

Users must be granted a platform role to allow them to view and manage the Workload Protection service in your account. You can grant permissions to work with all the instances in the IBM Cloud account or you can restrict access to individual instances.

The following table identifies the platform role that you can grant a user in the IBM Cloud to run the specified platform actions:

| Platform actions                                                        | Administrator                                     | Editor | Operator | Viewer  |
|-------------------------------------------------------------------------|:-------------------------------------------------:|:-------:|:--------:|:------:|
| `Grant other account members access to work with the service`           | ![Checkmark icon](/images/checkmark-icon.svg) |         |          |        |
| `Provision a service instance`                                          | ![Checkmark icon](/images/checkmark-icon.svg) |![Checkmark icon](/images/checkmark-icon.svg)         |          |        |
| `Delete a service instance`                                             | ![Checkmark icon](/images/checkmark-icon.svg) |![Checkmark icon](/images/checkmark-icon.svg)         |          |        |
| `Create a service ID`                                                   | ![Checkmark icon](/images/checkmark-icon.svg) |![Checkmark icon](/images/checkmark-icon.svg)         |          |        |
| `View details of a service instance`                                    | ![Checkmark icon](/images/checkmark-icon.svg)  | ![Checkmark icon](/images/checkmark-icon.svg)    | ![Checkmark icon](/images/checkmark-icon.svg)      | ![Checkmark icon](/images/checkmark-icon.svg)    |
| `View service instances in the Observability Monitoring dashboard`      | ![Checkmark icon](/images/checkmark-icon.svg)  | ![Checkmark icon](/images/checkmark-icon.svg)    | ![Checkmark icon](/images/checkmark-icon.svg)      | ![Checkmark icon](/images/checkmark-icon.svg)    |
{: caption="IAM user roles and actions" caption-side="top"}


## IBM Cloud service roles
{: #iam_svcroles}

The following table identifies the service role that you can grant a user in the IBM Cloud to run the specified actions:

| Actions                                       | Manager                                           | Writer                         | Reader |
|-----------------------------------------------|---------------------------------------------------|--------------------------------|--------|
| `Manage access keys`                             | ![Checkmark icon](/images/checkmark-icon.svg) |   |   |
| `Manage Secure API Tokens`                       | ![Checkmark icon](/images/checkmark-icon.svg) |   |   |
| `Create, configure, and delete teams`            | ![Checkmark icon](/images/checkmark-icon.svg) |   |   |
| `Configure and remove notifications channels`    | ![Checkmark icon](/images/checkmark-icon.svg) |   |   |
| `Configure and remove agents`                    | ![Checkmark icon](/images/checkmark-icon.svg) |   |   |
| `Create, delete, and edit content in the UI`     | ![Checkmark icon](/images/checkmark-icon.svg)  | ![Checkmark icon](/images/checkmark-icon.svg) | |
| `Manage runtime policies`                        | ![Checkmark icon](/images/checkmark-icon.svg)  | ![Checkmark icon](/images/checkmark-icon.svg) | |
| `Manage image scanning policies`                 | ![Checkmark icon](/images/checkmark-icon.svg) | ![Checkmark icon](/images/checkmark-icon.svg) | |
| `Manage Activity Audit`                          | ![Checkmark icon](/images/checkmark-icon.svg) | ![Checkmark icon](/images/checkmark-icon.svg) | |
| `Send container images to the scanning queue`    | ![Checkmark icon](/images/checkmark-icon.svg)  | ![Checkmark icon](/images/checkmark-icon.svg) | |
| `Create, update and remove alerts`               | ![Checkmark icon](/images/checkmark-icon.svg)  | ![Checkmark icon](/images/checkmark-icon.svg) | |
| `View reports and image scanning results`        | ![Checkmark icon](/images/checkmark-icon.svg)  | ![Checkmark icon](/images/checkmark-icon.svg) | |
| `View platforms, frameworks, rules and policies` | ![Checkmark icon](/images/checkmark-icon.svg)      | ![Checkmark icon](/images/checkmark-icon.svg)                    | ![Checkmark icon](/images/checkmark-icon.svg)    |
| `View events`                                   | ![Checkmark icon](/images/checkmark-icon.svg)      | ![Checkmark icon](/images/checkmark-icon.svg)                    | ![Checkmark icon](/images/checkmark-icon.svg)    |
{: caption="Service roles and actions" caption-side="top"}

## IAM actions
{: #iam_actions}

The following table identifies the IAM actions that are assigned to the platform and service roles for the Workload Protection service:

| Role type         | Role              | IAM actions |
|-------------------|-------------------|--------------|
| Platform          | `administrator`   | `sysdig-secure.launch.admin` </br>`sysdig-secure.launch.user` </br>`sysdig-secure.launch.viewer` |
| Service           | `manager`         | `sysdig-secure.launch.admin` </br>`sysdig-secure.launch.user` </br>`sysdig-secure.launch.viewer` |
| Service           | `writer`          | `sysdig-secure.launch.user` </br>`sysdig-secure.launch.viewer` |
| Service           | `reader`          | `sysdig-secure.launch.viewer` |
{: caption="IAM actions assigned to platform and service roles" caption-side="top"}

## How do I know which access policies are set for me?
{: #iam_accesspolicy}

You can see which access policies are set for you in the [IBM Cloud console](https://cloud.ibm.com/){: external}.

1. Go to [Access IAM users](https://cloud.ibm.com/iam/users){: external}.
2. Click your name in the user table.
3. Click the **Access policies** tab to see your access policies.
4. Click the **Access groups** tab to see the access groups where you are a member. Check the policies for each group.