IAM reference
The permissions of the platform: every IAM action and every built-in role.
Generated from the platform's RBAC catalogue when the RBAC module's image was built — do not edit.
How permissions work
- An action names one operation, such as apps/read. Every API endpoint that needs a permission names exactly one action; its module's API reference says which.
- A role grants a set of actions. A role assignment gives a principal a role at a scope — the platform root, a boundary, a resource group or one resource — and everything below it.
- Roles may use wildcards: * matches one segment, */* matches every action. Granting X/write also grants X/delete.
- Data actions read or write the data inside a resource, such as secret values. They are granted separately from actions, never through */*.
Modules
| Module | Actions | Data actions |
|---|---|---|
| Kernel | 27 | 2 |
| Apps | 4 | 3 |
| Blueprints | 2 | 0 |
| Functions | 4 | 1 |
| Jobs | 3 | 1 |
| Managed Identities | 3 | 1 |
| Secrets | 3 | 2 |
| Databases — Postgres | 7 | 9 |
| Databases — SQL Server | 7 | 10 |
| Databases — Qdrant | 4 | 2 |
| Databases — Valkey | 3 | 2 |
| Workflows | 3 | 2 |
| Container Instances | 7 | 5 |
| Static Web Apps | 4 | 2 |
| Boundaries | 18 | 1 |
| Boundaries (Data Plane) | 0 | 5 |
| Resource Groups | 3 | 0 |
| Sentinel | 3 | 0 |
| Monitoring | 3 | 0 |
| Compliance | 1 | 0 |
| Policies | 2 | 0 |
| S3 Storage | 15 | 0 |
| Registry | 2 | 0 |
| Lifecycle | 6 | 0 |
| Search | 1 | 0 |
| RBAC | 8 | 0 |
Built-in roles — what each role grants.