Skip to content
Stackship documentation Svenska

Access controlUsers

IAM reference

The permissions of the platform: every IAM action and every built-in role.

Generated from the platform's RBAC catalogue when the RBAC module's image was built — do not edit.

How permissions work

  • An action names one operation, such as apps/read. Every API endpoint that needs a permission names exactly one action; its module's API reference says which.
  • A role grants a set of actions. A role assignment gives a principal a role at a scope — the platform root, a boundary, a resource group or one resource — and everything below it.
  • Roles may use wildcards: * matches one segment, */* matches every action. Granting X/write also grants X/delete.
  • Data actions read or write the data inside a resource, such as secret values. They are granted separately from actions, never through */*.

Modules

Module Actions Data actions
Kernel 27 2
Apps 4 3
Blueprints 2 0
Functions 4 1
Jobs 3 1
Managed Identities 3 1
Secrets 3 2
Databases — Postgres 7 9
Databases — SQL Server 7 10
Databases — Qdrant 4 2
Databases — Valkey 3 2
Workflows 3 2
Container Instances 7 5
Static Web Apps 4 2
Boundaries 18 1
Boundaries (Data Plane) 0 5
Resource Groups 3 0
Sentinel 3 0
Monitoring 3 0
Compliance 1 0
Policies 2 0
S3 Storage 15 0
Registry 2 0
Lifecycle 6 0
Search 1 0
RBAC 8 0

Built-in roles — what each role grants.