# AI access

The AI access page in JetBrains Central Console lets you manage AI access for [users](users.html), [groups](groups.html), and [service accounts](service-accounts.html) in your organization. Use this page to grant or revoke access, manage [AI credits](ai-governance.html#ai-credits), and monitor current AI usage. To learn more about the main concepts of AI governance in JetBrains Central Console, see [AI governance](ai-governance.html).

> **Note:**
> Viewing the page requires the [View AI access](roles.html#permissions_view_ai_access) permission. Managing AI access requires the [Manage AI access](roles.html#permissions_manage_ai_access) or [Manage organization](roles.html#permissions_manage_org) permission.
>
> If you have the [View AI access](roles.html#permissions_view_ai_access) or [Manage AI access](roles.html#permissions_manage_ai_access) permission through a [group-scoped role](roles.html#role-scopes), you can view or manage only that group's members, including its subgroups.

The AI access page has a dedicated tab for managing AI access for each [principal](ai-governance.html#principal) type: Users, Groups, and Service accounts. With a [group-scoped role](roles.html#role-scopes), the Service accounts tab is not available.

When [enabling AI](ai-settings.html#enable-ai) for an organization, an admin can grant AI access to everyone. In this case, all users in your organization get AI access automatically, and you can't manage access per user or group on the AI access page. Otherwise, you can grant AI access to individual users and groups here.

> **Note:**
> Service accounts never get AI access automatically. You must always explicitly [grant AI access](#grant-ai-access) to a service account.

## Direct and group-based AI access

A user can get AI access individually, through one or more groups, or both. If a user is a member of a [group](groups.html), they automatically get access when you grant AI access to that group.

> **Tip:**
> Granting access to a group lets you cover an entire team or department. Members get access automatically, and new members are covered as they join the group.

The Access source column on the Users tab shows how a user is granted access: directly or through a group. If access comes through a group, the column shows the group names. If a user is granted access through several groups, the column lists the first one and shows a +N indicator for the rest. Hover over this indicator to see the other groups.

AI credits are consumed by individual users, not by the group. You can't set a credit limit for a group. Members of a group with AI access get the [default credit limit](ai-settings.html#default-ai-credit-limit), which you can [adjust per user](manage-ai-credits.html#set-ai-credit-limits).

Groups can be nested. Members of a child group are also members of its parent group, so AI access granted to a parent group also applies to users from its child groups.

If a user has AI access only through a group, you cannot revoke it from that user individually. You must either remove the user from the group or revoke access from the group itself.  For details, see [Revoke AI access](#revoke-ai-access).

## AI access management

Procedure: Grant AI access

Granting AI access gives a user, group, or service account permission to use AI-powered features. To actually use them, users or service accounts must be within their monthly [credit limit](manage-ai-credits.html#set-ai-credit-limits), and the organization's shared credit pool must have AI credits available.

1. In the sidebar, under AI governance, select Access.

If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary [permissions](roles.html#permissions).

2. In the upper right corner, click Grant access and select Users, Groups, or Service accounts.

If the Users and Groups items are inactive, it means that AI access is granted to all users in your organization. To manage access per user or group, change [AI settings](ai-settings.html) (requires the [Manage AI settings](roles.html#permissions_manage_ai_settings) permission).

If you have the [Manage AI access](roles.html#permissions_manage_ai_access) permission only through a [group-scoped role](roles.html#role-scopes),  the Service accounts item is not available.

3. In the dialog, search for a user, group, or service account, then select one or more of them from the dropdown.  If you have the [Manage AI access](roles.html#permissions_manage_ai_access) permission only through a [group-scoped role](roles.html#role-scopes),  the search returns only the users and groups you can manage.

4. Click Grant access.

A success message appears in the lower right corner. Principals with AI access are shown in the table in the corresponding tab. Members of a group you granted access appear on the Users tab with a badge for that group. The default credit limit set on the AI settings page applies to users and service accounts with AI access and can be [adjusted](manage-ai-credits.html#set-ai-credit-limits).

Procedure: Revoke AI access

Revoking AI access restricts specific users, groups, or service accounts from accessing AI-powered features.

> **Note:**
> You can revoke only directly granted access.  If a user has AI access only through a group, you cannot revoke it from that user individually. You must either remove the user from the group or revoke access from the group itself.

1. In the sidebar, under AI governance, select Access.

If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary [permissions](roles.html#permissions).

2. Select the Users, Groups, or Service accounts tab and search for a user, service account, or group either by scrolling through the list or using the search field at the top of the table.

If you have the [Manage AI access](roles.html#permissions_manage_ai_access) permission only through a [group-scoped role](roles.html#role-scopes),  the Service accounts tab is not available.

3. In the corresponding row, click ![Ellipsis icon](images/union.svg) and select Revoke access.

To revoke access from multiple users, groups, or service accounts, select them using the checkboxes in the first column and click Revoke access on the toolbar below the table. On the Users tab, users with AI access only through a group are skipped when you revoke access from several users at once.

The Revoke access item may be inactive if AI access is granted to all users in your organization. To manage access per user or group, change [AI settings](ai-settings.html) (requires the [Manage AI settings](roles.html#permissions_manage_ai_settings) permission).

4. In the dialog, click Revoke access to confirm.

A success message appears in the lower right corner. Users, groups, or service accounts are removed from the table in the corresponding tab and are no longer able to use AI-powered features.

Procedure: View the number of users or service accounts with AI access

1. In the sidebar, under AI governance, select Access.

If you don't see this page, your role doesn't have the necessary [permissions](roles.html#permissions).

2. Select the Users or Service accounts tab.

3. Review the value in the Users with AI access or Service accounts with AI access information card at the top of the page.

This value shows the number of users or service accounts in your organization that have AI access. If you have the [View AI access](roles.html#permissions_view_ai_access) permission only through a [group-scoped role](roles.html#role-scopes), it includes only the users you can see.

