# Project Roles

> Reference the project roles required to run CLI commands for each UGS module.

Project roles grant access to project-level data, which includes APIs that only apply to individual projects you choose. So to use some of the UGS CLI commands, you need to have the correct project roles linked to your project ID and Service Account.
You can link the project roles to your Service Account and project ID under the `Services Accounts` section in the Unity Dashboard. For more information, see [Creating a Service Account].
The tables below shows the project roles required to execute commands for each module.

## Environment module

| Project role               | Description                                          |
| -------------------------- | ---------------------------------------------------- |
| `Unity Environments Admin` | Grants full access to all environments in a project. |

## Access module

| Project role                     | Description                                             |
| -------------------------------- | ------------------------------------------------------- |
| `Unity Environments Admin`       | Grants full access to all environments in a project.    |
| `Player Resource Policy Editor`  | Grants write access to player-based resource policies.  |
| `Player Resource Policy Reader`  | Grants read access to player-based resource policies.   |
| `Project Resource Policy Editor` | Grants write access to project-based resource policies. |
| `Project Resource Policy Reader` | Grants read access to project-based resource policies.  |

## Cloud Code module

| Project role                  | Description                                                                |
| ----------------------------- | -------------------------------------------------------------------------- |
| `Unity Environments Admin`    | Grants full access to all environments in a project.                       |
| `Cloud Code Editor`           | Grants permissions necessary for viewing and editing cloud code resources. |
| `Cloud Code Viewer`           | Grants permissions necessary for viewing cloud code resources.             |
| `Cloud Code Script Publisher` | Grants permissions necessary for publishing cloud code scripts.            |

## Lobby module

| Project role               | Description                                          |
| -------------------------- | ---------------------------------------------------- |
| `Unity Environments Admin` | Grants full access to all environments in a project. |
| `Remote Config Admin`      | Grants access to the Remote Config admin API.        |

## Player module

| Project role            | Description                                                |
| ----------------------- | ---------------------------------------------------------- |
| `Authentication Admin`  | Grants access to all Admin APIs for player authentication. |
| `Authentication Editor` | Grants access to all Admin APIs for player authentication. |

## Matchmaker module

| Project role                | Description                                          |
| --------------------------- | ---------------------------------------------------- |
| `Matchmaker Config Manager` | Grants write access to Matchmaker configuration.     |
| `Matchmaker Config Viewer`  | Grants read access to Matchmaker configuration.      |
| `Unity Environment Viewer`  | Grants read access to all environments in a project. |

## Deploy Command

The services that support the deploy command are listed on the [Deploy] page. You need the roles for each service you deploy. The table below covers Cloud Code, Remote Config and Lobby; see the module tables on this page for Access, Leaderboards and Matchmaker, and [Creating a Service Account] for other services.

| Project role                  | Description                                                     |
| ----------------------------- | --------------------------------------------------------------- |
| `Unity Environments Admin`    | Grants full access to all environments in a project.            |
| `Remote Config Admin`         | Grants access to the Remote Config admin API.                   |
| `Cloud Code Script Editor`    | Grants permissions necessary for editing cloud code scripts.    |
| `Cloud Code Script Publisher` | Grants permissions necessary for publishing cloud code scripts. |
| `Cloud Code Script Viewer`    | Grants permissions necessary for viewing cloud code scripts.    |

## Fetch Command

The services that support the fetch command are listed on the [Fetch] page. You need the roles for each service you fetch. The table below covers Remote Config and Lobby; see the module tables on this page for Access, Leaderboards and Matchmaker, and [Creating a Service Account] for other services.

| Project role               | Description                                          |
| -------------------------- | ---------------------------------------------------- |
| `Unity Environments Admin` | Grants full access to all environments in a project. |
| `Remote Config Admin`      | Grants access to the Remote Config admin API.        |

## Leaderboard module

| Project role               | Description                                          |
| -------------------------- | ---------------------------------------------------- |
| `Unity Environments Admin` | Grants full access to all environments in a project. |
| `Leaderboards Admin`       | Grants access to the Leaderboard admin API.          |

[Creating a Service Account]: https://services.docs.unity.com/docs/service-account-auth

[Deploy]: ./../base-commands/deploy

[Fetch]: ./../base-commands/fetch
