Permissions
The two actions that govern policies, the roles that hold them, and where they have to be assigned.
Actions
| Action | Allows |
|---|---|
policies/read |
See the boundary's policies, and ask which compute plans they allow |
policies/write |
Create, change, enforce, disable and delete policies |
Both are checked at the boundary. A role assigned on a resource group or on a single resource does not reach them: policies belong to the boundary as a whole.
Roles
| Role | See | Change |
|---|---|---|
| Reader, Platform Reader | Yes | No |
| Contributor, Owner | Yes | Yes |
| Platform Contributor, Platform Owner | Yes | Yes |
The narrower roles, such as Apps Operator or Databases Operator, hold neither.
Compute plan pickers without policies/read
The plan pickers in the portal ask the boundary's policies which plans are allowed, with your own
permissions. Without policies/read they cannot tell, and offer every plan. The platform still
checks the plan when you create the resource and refuses one the policies do not allow, except
for functions — see
Allowed compute plans.