As an Administrator, you add the people in your organization who need access to IBM watsonx to the IBM Cloud account and then assign them the appropriate roles for their tasks.
Add nonadministrative users to the IBM Cloud account and assign access groups or roles so that they can work in IBM watsonx. The new users receive an email invitation to join the account. They must accept the invitation
to be added to the account.
Set up access groups to simplify permissions and role assignment.
Add nonadministrative users to your IBM Cloud account
Copy link to section
You invite users to your IBM Cloud account by sending an email invitation. The user accepts the invitation to join the account. You must assign them roles (or access groups) to provide the necessary permissions to work in IBM watsonx. For a
baseline role assignment, you can provide minimum permissions by assigning the following roles in the Manage > Access(IAM) > Users > Invite users > Access policy screen in IBM Cloud:
Table 1. Minimum roles for new IBM watsonx users
Level
Role
Description
Service
All Identity and Access enabled services
Can access all services that use IAM for access management; usually assigned only to administrators in a production environment
Resources
All resources
Scope of resources for which user has access
Resource group access
Viewer
Can view but not modify resource groups
Service access
Reader
Can perform read-only actions within a service
Platform access
Viewer
Can view but not modify service instances
IBM account membership
Copy link to section
To be authorized for IBM watsonx, users must have existing IBMids. If the invited user does not have an IBMid, it is created for them when they join the account.
Assigning roles
Copy link to section
To assign minimum permissions to individual users:
From IBM watsonx, click Administration > Access (IAM) to open the Manage access and users page for your IBM Cloud account.
Click Users > Invite users+.
Enter one or more email addresses that are separated by commas, spaces, or line breaks. The limit is 100 email addresses. The settings apply to all the email addresses.
Click the Access policy tile.
Select All Identity and Access enabled services, then click Next to assign Resource access.
For Resources, choose All resources. Click Next.
For Resource group access, choose Viewer. Click Next
For Roles and action, choose the following minimum permissions:
In the Service access section, select Reader
In the Platform access section, select Viewer.
Review the settings and edit if necessary.
Click Add to save the policy.
Click Invite to send an email invitation to each email address. The policies are assigned to the users when they accept the invitation to join the account.
Watch this video to see how to invite users to your account.
This video provides a visual method to learn the concepts and tasks in this documentation.
Modifying a user's role
Copy link to section
When you change a user's role, their access to services changes. Their ability to complete work in IBM watsonx can be impacted if they do not have the necessary access.
Optional: Add administrative users to your IBM Cloud account
Copy link to section
You can add administrative users with the Administrator role for account management. This role also provides the Manager role for all services in the account.
To add a user as an IBM Cloud account administrator:
About cookies on this siteOur websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.For more information, please review your cookie preferences options. By visiting our website, you agree to our processing of information as described in IBM’sprivacy statement. To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.