Configuring User access to Cloudera AI
This topic describes how to grant users/groups access to an environment so that they can provision and/or list Cloudera AI Workbenches within that environment. The same users will also be granted Single Sign-on (SSO) access to the workbenches. In addition, if a user needs to provision, upgrade, or delete an Cloudera AI Workbench, they also need the account-level EnvironmentAdmin role assigned. For more information, see Understanding account roles and resource roles.
Required Role: PowerUser
There are two Cloudera Data Platform user roles associated with the Cloudera AI service: MLAdmin and
MLUser. A Cloudera Data Platform PowerUser will need to assign these roles to users who require access
to the Cloudera AI service within an environment.
- MLAdmin - This role grants a Cloudera Data Platform user/group the ability to create and delete Cloudera AI Workbenches within a given Cloudera Data Platform environment. MLAdmins will also have Site Administrator level access to all the workbenches provisioned within this environment. That is, they can run workloads, monitor, and manage all user activity on these workbenches.
- MLUser - This role grants a Cloudera Data Platform user/group the ability to list Cloudera AI Workbenches provisioned within a given Cloudera Data Platform environment. MLUsers will also be able to run workloads on all the workbenches provisioned within this environment.
For instructions, see Granting Cloudera Data Platform Users Access to Cloudera AI Service.