Skip to content
Stackship documentation Svenska

SentinelUsers

Permissions

The actions that govern Sentinel, the roles that hold them, and why they must be assigned on the boundary.

Actions

Action Allows
sentinel/read See the boundary's findings with their evidence, its runs and overview, and the Sentinel cards on its resources
sentinel/write Change a finding's status, start Analyze with logs, and turn monitoring of a resource on or off
sentinel/admin See platform findings — held at the platform root

Analyze with logs also needs permission to read the resource's logs. The steps in a finding each need their own action on the resource, such as apps/scale; see Steps and who does them.

Important

sentinel/read and sentinel/write are checked at the boundary, and sentinel/admin at the platform root. A role assigned on a resource group or on a single resource gives no access to Sentinel: someone who may only see one app does not see its findings, not even on the app's own Sentinel card.

Roles

Role Read Write Platform findings
Reader, Platform Reader Yes No No
Apps Reader, Databases Reader, Functions Reader, Jobs Reader, Storage Reader, Blueprint Reader Yes No No
Secrets Reader, Secrets Writer Yes No No
Apps Operator, Databases Operator, Functions Operator, Jobs Operator, Storage Operator, Blueprints Operator Yes Yes No
Contributor, Owner Yes Yes No
Platform Contributor, Platform Owner Yes Yes Yes

Caution

Every role that can read findings can read their evidence, including log lines stored on them — also roles that may not read the resource's logs, such as Databases Reader or Secrets Reader. See Evidence.