Skip to content
Stackship documentation Svenska

Access controlUsers

Check access

Find out whether a principal holds an action at a scope, and which role or deny decides it.

Requires: rbac/members/read

The Check access tab answers one question about someone else: does this principal hold this action at this scope, and which role or deny decides it?

Check a principal

  1. In the portal at https://portal.example.com, open Access control (IAM) and go to Check access.
  2. Principal — search for the user or group and pick it.
  3. Action — type the action, for example containerinstance/read. A role's actions are on its Permissions tab; all actions are listed on the Permissions step of creating a custom role.
  4. Scope — optional; empty means the boundary. Type a resource group or resource scope to check lower down.
  5. Choose Check access.

Reading the result

Result Meaning
Access granted A role assigned to the principal at the scope or above grants the action — the role is named
Access denied A deny assignment blocks the action — the deny is named
Not granted None of the principal's own assignments on this page grants it

Important

The portal works this answer out from the assignments listed on the Role assignments and Deny assignments tabs. It does not include roles the principal holds through a group, active just-in-time grants, exclusions on deny assignments, or whether a deny applies to child scopes; it treats every action the same whether it is a data action or not, and it matches wildcards more loosely than the platform does. It does not apply the rule that X/write also grants X/delete, so a delete the principal can do may show as Not granted, and a deny of X/write does not show as blocking X/delete. It compares scopes as plain text, so an assignment on resource group web also appears to cover web2. Read Not granted as "no direct assignment grants it", and check a surprising answer against the assignments of the principal's groups and against its just-in-time requests.

Your own access

The portal also asks the platform, for you, which actions you hold where it shows a page. That is why buttons you cannot use are hidden or disabled rather than failing when you choose them. When something you expect is missing, look up which of the built-in roles carries the action — and where the portal offers it, you can request that role for a few hours.