Standard Access Roles To help teams get started quickly, the Science Cloud automatically provisions standard, managed roles in all tenant accounts. These roles are designed to support common operational needs and map to standard cloud provider policies:

Reference Links: To view the specific permissions granted by these policies, refer to the official AWS documentation:

Important Access Guidelines

Custom Access and Self-Management Some projects have specific business requirements that necessitate custom access controls. The Science Cloud fully supports custom role creation through a secure, hybrid approach that minimizes your ongoing dependence on our support desk.

How the Hybrid Approach Works: Instead of requiring a support ticket for every granular permission change, the Science Cloud provisions a secure, baseline access boundary for your team using automated deployment tools.

Once this secure framework is established and linked to your team's authorized identities, your project administrators gain the autonomy to securely create, manage, and delegate specific permissions within your own environment. This allows your team to operate agilely while remaining safely within the Science Cloud's overarching security guardrails.