Built-in roles at a glance
The roles that ship with the platform, what each grants, and what each leaves out.
Built-in roles cannot be changed or deleted. They are available in every boundary, next to the boundary's custom roles. This page summarises them; a role's exact action lists are on its Permissions tab — open Access control (IAM), then Roles, then the role — and in the IAM reference in the RBAC docs, which lists every built-in role with the actions and data actions it grants.
Boundary roles
Assigned at a boundary, a resource group or a resource.
| Role | Grants | Leaves out |
|---|---|---|
| Owner | Every action and data action, including assigning roles, deny assignments, custom roles and approving just-in-time requests | Creating and deleting boundaries, attaching boundaries to clusters, changing cluster registrations; the PostgreSQL Data Explorer data actions; reading workflow runs' step inputs and outputs |
| Contributor | The same as Owner, minus what is listed on the right | Everything Owner leaves out, and: assigning roles and managing access (rbac/members/write), adding and removing members (boundaries/members/manage), sending invitations (boundaries/invitations/create), and restoring or deleting snapshots of PostgreSQL, SQL Server and container instances |
| Reader | Reading every resource, its members, invitations, network rules, activity and operations; reading logs of apps, static web apps, functions, jobs and container instances; opening login-protected container instance endpoints | Any change; terminals, file access, secret values and database content |
Because Contributor has no rbac/members/write, a Contributor cannot create custom roles or deny
assignments, and cannot approve just-in-time requests.
Owner held through a group grants rbac/members/write, so it is enough to create and delete deny
assignments, but not to assign roles, create custom roles or decide just-in-time requests — those
need Owner assigned directly. See Who can assign roles.
Platform roles
Assigned only at the root scope /, and only by a Platform Owner. They cannot be requested as
just-in-time access.
| Role | Grants | Leaves out |
|---|---|---|
| Platform Owner | Every action and data action, in every boundary and at the root | The PostgreSQL Data Explorer data actions; reading workflow runs' step inputs and outputs |
| Platform Contributor | The same as Platform Owner, minus what is listed on the right | Deleting boundaries, moving boundaries between tenants, assigning roles and managing members and invitations, cross-tenant membership, boundary trusts, changing cluster registrations, managing platform backups, platform diagnostics |
| Platform Reader | Reading resources in every boundary, including platform health, the Lifecycle Manager, the user directory and the registry's and S3's audit logs | Any change, and every data action — no logs, secret values or content; and the reads listed below |
Platform Reader's */read covers only two-part actions such as apps/read, and only some longer
reads are added to it. It cannot read:
- a boundary's members, invitations and workloads (
boundaries/members/read,boundaries/invitations/read,boundaries/workloads/read); - deployment sources (
kernel/deployments/read); - cluster registrations (
kernel/clusters/read); - container instances' live status (
kernel/crates/read); - the Kubernetes channel reads (
kernel/k8sChannel/readand the otherkernel/k8sChannel/*reads).
Actions that are only checked at the root are listed in Root-scoped actions.
Database Explorer
Database Explorer grants the Data Explorer on PostgreSQL and SQL Server: reading and writing rows, running queries, including queries that change data, and reading and changing schemas. It does not include dropping or truncating objects.
No other built-in role holds the PostgreSQL Data Explorer actions — Owner and Platform Owner included — so it must be assigned explicitly to anyone who is to use the Data Explorer on PostgreSQL. The SQL Server Data Explorer actions, on the other hand, are also held by Owner, Contributor, Platform Owner and Platform Contributor.
Scoped roles
Narrow roles for one area, meant for a boundary, a resource group or a single resource. Each also carries the reads the portal needs to show the resource: the boundary, its resource groups, operations, status, monitoring, Sentinel findings and search.
| Role | Grants |
|---|---|
| Apps Reader | Viewing apps, container instances and static web apps, their pods and deployment sources |
| Apps Operator | Creating, changing, scaling and deleting apps, container instances and static web apps; app logs and app file browsing; static web app deploys and logs |
| Functions Reader | Viewing functions and reading their logs |
| Functions Operator | Creating, changing, scaling and deleting functions; reading their logs |
| Jobs Reader | Viewing jobs and reading their logs |
| Jobs Operator | Creating, changing and deleting jobs; reading their logs |
| Databases Reader | Viewing PostgreSQL, SQL Server, Qdrant and Valkey |
| Databases Operator | Creating, changing and deleting those databases, and scaling PostgreSQL, SQL Server and Qdrant; snapshots of PostgreSQL and SQL Server, including restoring and deleting them; reading and changing their passwords and connection strings; SQL Server licences |
| Storage Reader | Viewing S3 storage accounts, buckets, access keys and objects |
| Storage Operator | Managing S3 storage accounts, buckets, access keys and objects; issuing short-lived S3 sessions |
| Secrets Reader | Seeing vaults and reading secret values |
| Secrets Writer | Managing vaults and reading and writing secret values |
| Blueprint Reader | Viewing the template catalogue and the container instances deployed from it; their logs; opening their login-protected endpoints |
| Blueprints Operator | Writing and deleting blueprint templates; managing the container instances deployed from them, including their logs, terminals and files; creating, changing and deleting vaults |
Blueprints Operator's action list names secretvault/writeSecrets, but among its control-plane
actions, while writing secret values is checked as a data action — so the role does not let its
holder write secret values. The Secrets roles are described in more detail in
Secrets permissions.
Service roles
Held by platform components rather than people.
| Role | Grants |
|---|---|
| Deployment Token Broker | Short-lived source-repository tokens for cloning |
| Platform Alert Publisher | Raising and clearing platform alerts |
| LLM Gateway Consumer | Resolving registered LLM gateways, including their API key. Root scope only |