Skip to content
Stackship documentation Svenska

MonitoringUsers

Permissions

The actions that govern metrics, alerts and the Health page, the scope each is checked at, and the roles that hold them.

Actions

Action Allows Checked at
monitoring/read Seeing a resource's metrics and alerts; listing the alerts firing in a boundary The resource, its resource group or its boundary
monitoring/platform/read Opening the Health page and its Nodes tab: node capacity, unhealthy volumes and platform alerts The platform root only
monitoring/platform/alerts/write Raising and clearing a platform alert The platform root only

monitoring/platform/alerts/write is meant for platform components, which hold it through the service role Platform Alert Publisher. Platform Owner and Platform Contributor hold it too, through their */* wildcard.

Important

Whoever holds monitoring/platform/alerts/write at the root can raise a platform alert under any id that is not one of the module's own rules, and can resolve any alert raised that way — including one another platform component raised, such as the backups' alert about a filling database volume. Platform Owners and Platform Contributors can do this through the API.

Roles

Role monitoring/read monitoring/platform/read monitoring/platform/alerts/write
Reader Yes, where assigned No No
Contributor, Owner Yes, where assigned Not from a boundary or below Not from a boundary or below
Every scoped reader and operator role, such as Apps Reader, Databases Operator or Storage Reader, and Database Explorer Yes, where assigned No No
Platform Reader Yes Yes No
Platform Contributor, Platform Owner Yes Yes Yes
Platform Alert Publisher No No Yes

A role assigned on a boundary or below never reaches the root-only actions, whatever it lists: Owner and Contributor list both through */*, but only an assignment at the root would give them — see Root-scoped actions. The roles themselves are described in Built-in roles, and a custom role can list these actions like any other — see Custom roles.

The Health page's other tabs need actions of the platform's core: Map needs kernel/platform/read, held by the three platform roles, and Database needs kernel/platform/diagnose, held by Platform Owner only — see The Health page.

What the portal shows

  • Without monitoring/read on a resource, its Active alerts card and Alerts tab are not shown, and its Metrics card shows an error instead of charts.
  • Health is in the sidebar only for those who hold monitoring/platform/read at the root.

The platform checks every request as well.