Permissions
The platform-core actions — clusters, deployment sources, operations, activity, platform settings — and the built-in roles that hold them.
These actions cover what the platform's core provides itself. Actions of resources — apps, databases, vaults and so on — are listed on each module's own permissions page.
Where actions are checked
Some actions are checked at the platform root (/). Only a role assigned at the root grants
them, so in practice only the platform roles do; a boundary Owner does not hold them, even though
the Owner role's definition includes most of them. The others are checked at the scope the request names:
a boundary, a resource group or a resource.
Actions
| Action | Allows | Checked at |
|---|---|---|
kernel/clusters/read |
See the registered clusters | root |
kernel/clusters/write |
Register, change and delete clusters; issue join tokens; revoke agents | root |
kernel/platform/read |
See the platform's components, their status and the cluster topology | root |
kernel/platform/diagnose |
Inspect a platform component's pods, events and database internals | root |
kernel/deployments/read |
See a boundary's deployment sources, their repositories and credential health | boundary |
kernel/deployments/write |
Connect deployment sources; includes kernel/deployments/delete |
boundary |
kernel/deployments/delete |
Delete deployment sources | boundary |
kernel/deployments/token |
Get a short-lived token to clone a source repository — held by platform services | boundary |
kernel/operations/read |
See operations and dismiss them from your notifications | boundary, resource |
kernel/activity/read |
Read a resource's activity log | resource |
kernel/activity/write |
Write activity records — nearly every role has it, so that changes can be recorded whichever role allowed them | boundary |
kernel/resourceStatus/read |
Receive live status updates for resources | resource |
kernel/emailSettings/manage |
View and change the SMTP settings | root |
kernel/emailTemplates/manage |
Edit, preview, restore and reset e-mail templates | root |
kernel/mcpSettings/manage |
Turn the MCP interface for AI clients on and off, and edit the hosts allowed to register a client | root |
kernel/telemetrySettings/manage |
View and change where the platform exports its own telemetry | root |
kernel/llmGateways/read, …/write, …/delete |
See, register and change, and delete LLM gateways | root |
kernel/llmGateways/resolve |
Resolve an LLM gateway's address and key — held by platform services only | root |
The catalogue also defines kernel/k8sChannel/* and kernel/crates/* actions, which the
platform's modules and resource pages use internally.
Roles
Every built-in role except LLM Gateway Consumer also holds kernel/activity/write, so that the
changes it allows can be recorded; the table leaves it out.
| Role | Kernel actions it holds |
|---|---|
| Platform Owner | All of them |
| Platform Contributor | All except kernel/clusters/write and kernel/platform/diagnose |
| Platform Reader | kernel/platform/read, kernel/operations/read, kernel/activity/read, kernel/resourceStatus/read, kernel/llmGateways/read |
| Owner, Contributor | The boundary-scoped ones: deployment sources, operations, activity, resource status |
| Reader | kernel/operations/read, kernel/activity/read, kernel/resourceStatus/read, kernel/crates/read |
| Apps Reader, Apps Operator, Functions Operator | kernel/deployments/read, kernel/operations/read, kernel/resourceStatus/read |
| Blueprints Operator | kernel/deployments/read, kernel/operations/read, kernel/resourceStatus/read, kernel/crates/read |
| Blueprint Reader | kernel/operations/read, kernel/resourceStatus/read, kernel/crates/read |
| Other scoped roles (Secrets, Databases, Jobs, Storage …) | kernel/operations/read, kernel/resourceStatus/read |
| Deployment Token Broker | kernel/deployments/token |
| LLM Gateway Consumer | kernel/llmGateways/resolve |
Reader, Blueprint Reader and Blueprints Operator also hold the data action kernel/crates/readLogs,
and Blueprints Operator kernel/crates/exec. Platform Reader and Reader do not hold
kernel/clusters/read or kernel/deployments/read.
Roles, scopes and how to assign them are described in Assign a role.