Foundry built-in roles: User vs Account Owner vs Project Manager vs Owner
Verdict: Build and test only is Foundry User. Create accounts and deploy models without data-plane build is Account Owner. Build, publish agents and assign only Foundry User is Project Manager. Full access is Owner.
| Criterion | Foundry User | Foundry Account Owner | Foundry Project Manager | Foundry Owner |
|---|---|---|---|---|
| Build and develop in a project | Yes | No | Yes | Yes |
| Create accounts and manage models | No | Yes | No | Yes |
| Assign roles | No | Yes | Only the Foundry User role | Yes |
| Publish agents | No | No | Yes | Yes |
| Choose for | New agent developer | Platform manager, no build | Team lead building and delegating | Full administrative control |
Rules
- Foundry User is the least-privilege role: build and develop in a project plus reader access, no project or account creation, model management or role assignment.
- Foundry Account Owner can create accounts and projects and manage models, but its build-and-develop data actions are denied.
- The enterprise mapping grants a developer Foundry User on the project scope plus Reader on the resource scope, scoping data actions to one project.
- Foundry Project Manager builds in projects, publishes agents and can assign only the Foundry User role, without creating accounts or managing models.
Traps
- Despite its name, Azure AI Developer is scoped to Azure ML workspaces and Foundry hubs, not Foundry projects; use Foundry User or Foundry Owner for project access.