Permissions
The actions that govern resource groups and the roles that hold them.
Actions
| Action | Allows |
|---|---|
resourcegroups/read |
See the resource group in the list, open it and list the resources in it. |
resourcegroups/write |
Create resource groups. |
resourcegroups/delete |
Delete resource groups, and everything in them. |
The actions are checked on the resource group, so a role assigned on the boundary covers every group in it, and a role assigned on one group covers only that group. The list of resource groups shows the groups you can read and leaves the others out.
Roles
| Role | Read | Create | Delete |
|---|---|---|---|
| Reader | Yes | No | No |
| Contributor, Owner | Yes | Yes | Yes |
| Platform Reader | Yes | No | No |
| Platform Contributor, Platform Owner | Yes | Yes | Yes |
| Roles for one kind of resource, such as Apps Reader or Secrets Reader | Yes | No | No |
The roles for one kind of resource include resourcegroups/read so that their holders can find the
resource groups their assignment covers.