Configure Permissions
Restrict which GCP identities are eligible to run queries against your Yuki-managed BigQuery reservations. By default, none are - you add the users, service accounts, and Google groups that should get access, and Yuki grants them its Run Jobs On Yuki role behind the scenes. Every tool, pipeline, or service account you updated the connection string for must be added here.

How to Configure Permissions
- In the Yuki app, go to Yuki reservations access
- In the Email field, enter the email address of the user, service account, or Google group you want to grant access to
- Set the Type, or leave it as Auto-detect so Yuki infers it from the email address
- Click Grant Access
The Granted access table lists every identity currently permitted to query through Yuki. Click Refresh to reload it, or the trash icon next to an entry to revoke its access.
Next Step
With permissions configured, continue through Update Connection Strings for each tool so its queries route through Yuki.