# IAM and identity on Quake AI

Source: https://docs.quake.ai/docs/account/concepts/iam
Markdown: https://docs.quake.ai/docs/account/concepts/iam.md

---

# IAM and identity on Quake AI

**IAM** on AWS, **Cloud IAM** on Google Cloud, and **Microsoft Entra ID** on Azure centralize users, roles, and API access for an entire cloud estate. On Quake AI identity flows through **Rumble.com sign-in**, **[organizations and projects](/docs/account/concepts)**, Keystone **roles**, and separate credential types for automation.

There is no single console named IAM. Map habits to the objects below.

## Mapping IAM habits

| IAM habit | On Quake AI |
|---|---|
| Root / billing account | Rumble.com identity + [organization](/docs/account/concepts) |
| Account / subscription partition | [Project](/docs/account/concepts) (quota and resource boundary) |
| IAM user for automation | [Application credential](/docs/tools/generate-app-credentials) scoped to a project |
| Short-lived API token | [API token](/docs/tools/api-tokens) (Keystone) |
| IAM role attached to resource | Project **role assignment** (member, reader, etc.) |
| S3 access key | [S3 credentials](/docs/tools/s3-credentials) |
| Instance SSH access | [Key pair](/docs/compute/concepts/key-pairs) |

Fine-grained policy documents per resource ARN are not the model. OpenStack uses project-scoped roles and service APIs enforce ownership on resources inside the project.

## What to read next

- [Account model](/docs/account/concepts): organizations, projects, tiers, and team roles
- [Credentials and tools](/docs/tools/concepts): which credential each tool consumes
- [Shared responsibility](/docs/security/shared-responsibility): identity and access boundaries
