> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qumo-deploy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# client.iam

> Identity & access management — bindings and roles at project and tenant scope.

Identity & access management — bindings and roles at project and tenant scope.

Reach it as `client.iam` on a [`QumoClient`](/sdk/reference/client#qumoclient).

### listBindings

```ts theme={null}
listBindings(projectId: string): Promise<IAMBinding[]>
```

Lists the role bindings on a project.

Types: [`IAMBinding`](/sdk/reference/types#iambinding)

### createBinding

```ts theme={null}
createBinding(projectId: string, binding: Omit<IAMBinding, "id">): Promise<IAMBinding>
```

Grants a role on a project to a user or identity.

Types: [`IAMBinding`](/sdk/reference/types#iambinding)

### removeBinding

```ts theme={null}
removeBinding(bindingId: string, tenantId?: string): Promise<void>
```

Deletes a binding. `tenantId` scopes the request for session (cookie)
callers — the route names only the binding, so without a scope the
permission check resolves nothing and the call 403s. The server also
verifies the binding belongs to that tenant — for a project-scoped
binding, via the binding's parent tenant (API-key callers may omit it;
their own tenant applies).

### listTenantBindings

```ts theme={null}
listTenantBindings(tenantId: string): Promise<IAMBinding[]>
```

Lists the role bindings on a workspace.

Types: [`IAMBinding`](/sdk/reference/types#iambinding)

### createTenantBinding

```ts theme={null}
createTenantBinding(tenantId: string, binding: Omit<IAMBinding, "id">): Promise<IAMBinding>
```

Grants a role on a workspace to a user or identity.

Types: [`IAMBinding`](/sdk/reference/types#iambinding)

### listRoles

```ts theme={null}
listRoles(tenantId?: string): Promise<IAMRole[]>
```

Lists the assignable IAM roles. `tenantId` scopes the request: session
(cookie) callers carry no tenant of their own, and an unscoped admin request
resolves to no permissions server-side, so omitting it yields 403.

Types: [`IAMRole`](/sdk/reference/types#iamrole)
