AI access
The AI access page in JetBrains Central Console lets you manage AI access for users, groups, and service accounts in your organization. Use this page to grant or revoke access, manage AI credit limits, monitor AI seats, and track current AI usage.
The AI access page has a dedicated tab for managing AI access for each principal type: Users, Groups, and Service accounts. With a group-scoped role, the Service accounts tab is not available.
When enabling AI for an organization, an admin can grant AI access to everyone. In this case, all users in your organization get AI access automatically, and you can't manage access per user or group on the AI access page. Otherwise, you can grant AI access to individual users and groups here.
Granting AI access alone doesn't allow users or service accounts to use AI-powered features. The following conditions must be met as well:
The user or service account is within their monthly credit limit.
The organization's shared credit pool has AI credits available.
On the Business and Enterprise plans, the user has an AI seat assigned. Service accounts don't require AI seats on any plan.
Direct and group-based AI access
A user can get AI access individually, through one or more groups, or both. If a user is a member of a group, they automatically get access when you grant AI access to that group.
Granting access to a group lets you cover an entire team or department. Members get access automatically, and new members are covered as they join the group.
The Access source column on the Users tab shows how a user is granted access: directly or through a group. If access comes through a group, the column shows the group names. If a user is granted access through several groups, the column lists the first one and shows a +N indicator for the rest. Hover over this indicator to see the other groups.
Groups can be nested. Members of a child group are also members of its parent group, so AI access granted to a parent group also applies to users from its child groups.
AI credits are consumed by individual users, not by the group. You can't set a credit limit for a group, but you can set an individual limit for any member, or assign the group to a custom policy that defines a limit.
If a user has AI access only through a group, you cannot revoke it from that user individually. You must either remove the user from the group or revoke access from the group itself. For details, see Revoke AI access.
AI access management
Grant AI access
Granting AI access gives a user, group, or service account permission to use AI-powered features, but the permission alone is not enough. Make sure the other conditions are met as well.
In the sidebar, under AI governance, select Access.
If you don't see this page, or the controls on this page are inactive, make sure your role has the necessary permissions.
In the upper right corner, click Grant access and select Users, Groups, or Service accounts.
If the Users and Groups items are inactive, it means that AI access is granted to all users in your organization. To manage access per user or group, change AI settings.
On a paid plan, the Users item is also inactive when no AI seats are available in the organization's shared pool of AI seats. The Groups item stays available, because group grants are not limited by the number of available AI seats. For more information, see Direct and group-based AI access.
In the dialog, search for a user, group, or service account, then select one or more of them from the dropdown. If you have the Manage AI access permission only through a group-scoped role, the search returns only the users and groups you can manage.
On a paid plan, when you grant access to users, a banner in the dialog shows the number of unassigned seats. You can't select more users than there are available AI seats.
Click Grant access.
A success message appears in the lower right corner. Principals with AI access are shown in the table in the corresponding tab. Members of a group you granted access appear on the Users tab with the group name in the Access source column. The Credit limit column shows the limit that currently applies to them. For details, see AI credit limits.
On a paid plan, users who are granted AI access directly get an AI seat immediately, and the number of available AI seats decreases. Users with AI access through a group get seats only if they are available. For details, see Direct and group-based AI access.
Revoke AI access
Revoking AI access restricts specific users, groups, or service accounts from accessing AI-powered features.
In the sidebar, under AI governance, select Access.
If you don't see this page, or the controls on this page are inactive, make sure your role has the necessary permissions.
Select the Users, Groups, or Service accounts tab and search for a user, service account, or group either by scrolling through the list or using the search field at the top of the table.
If you have the Manage AI access permission only through a group-scoped role, the Service accounts tab is not available.
In the corresponding row, click
and select Revoke access.
To revoke access from multiple users, groups, or service accounts, select them using the checkboxes in the first column and click Revoke access on the toolbar below the table. On the Users tab, users with AI access only through a group are skipped when you revoke access from several users at once. They keep their AI access and AI seats, if applicable.
The Revoke access item may be inactive if AI access is granted to all users in your organization. To manage access per user or group, change AI settings.
In the dialog, click Revoke access to confirm.
A success message appears in the lower right corner. Users, groups, or service accounts are removed from the table in the corresponding tab and are no longer able to use AI-powered features.
On a paid plan, a user who still has AI access through a group keeps their AI seat. Otherwise, the released seat returns to the shared pool. If there are users with AI access but with no AI seat, a released seat goes to the user who has been waiting the longest.
View the number of users or service accounts that can use AI-powered features
In the sidebar, under AI governance, select Access.
If you don't see this page, your role doesn't have the necessary permissions.
Select the Users or Service accounts tab.
Review the value in the following information cards at the top of the page:
On the Users tab: Users with AI access (Basic plan) or Users with AI seats (paid plans).
On the Service accounts tab: Service accounts with AI access.
This value shows the number of users or service accounts in your organization that can use AI-powered features. If you have the View AI access permission only through a group-scoped role, it includes only the users you can see.