# Nylas IAM access controls

Source: https://developer.nylas.com/docs/changelogs/2026-10-06-nylas-iam/

[Nylas IAM](/docs/v3/auth/nylas-iam/) lets you give services, workers, and AI agents only the Nylas resources and actions they need. Configure access in the [Nylas Dashboard](https://dashboard.nylas.com/) and issue an IAM API key for each caller's access pattern.

## Added

- **Principals and resource bindings.** Bind each principal to one organization, application, workspace, or grant. Grant selection searches the application's grants by ID or email address, including grants without workspace membership.
- **Roles and direct permissions.** Assign Nylas system roles, create custom roles, or add permissions directly to a principal. The Dashboard distinguishes effective permissions from permissions ignored at the selected resource binding.
- **IAM API keys.** Create credentials that inherit a principal's resource binding and permissions. Set an optional expiration, rotate keys, or disable credentials. Use IAM API keys as Bearer tokens or with the Nylas SDKs. See [Create and manage IAM API keys](/docs/v3/auth/nylas-iam/#create-and-manage-iam-api-keys).
- **Audit activity.** Review **Config Changes** for IAM configuration updates and **Access Activity** for allowed and denied requests. Filter activity and follow request links to investigate authorization decisions. See [Review and troubleshoot IAM activity](/docs/v3/auth/nylas-iam/#review-and-troubleshoot-iam-activity).

IAM permissions control the caller's access to Nylas. Provider OAuth scopes still control what the connected account authorizes; IAM can't expand those scopes. See [How Nylas IAM works](/docs/v3/auth/nylas-iam/#how-nylas-iam-works) before choosing a resource binding and permissions.