Skip to content
Stackship documentation Svenska

PoliciesUsers

Permissions

The two actions that govern policies, the roles that hold them, and where they have to be assigned.

Actions

Action Allows
policies/read See the boundary's policies, and ask which compute plans they allow
policies/write Create, change, enforce, disable and delete policies

Both are checked at the boundary. A role assigned on a resource group or on a single resource does not reach them: policies belong to the boundary as a whole.

Roles

Role See Change
Reader, Platform Reader Yes No
Contributor, Owner Yes Yes
Platform Contributor, Platform Owner Yes Yes

The narrower roles, such as Apps Operator or Databases Operator, hold neither.

Compute plan pickers without policies/read

The plan pickers in the portal ask the boundary's policies which plans are allowed, with your own permissions. Without policies/read they cannot tell, and offer every plan. The platform still checks the plan when you create the resource and refuses one the policies do not allow, except for functions — see Allowed compute plans.