Permissions
The actions that govern Sentinel, the roles that hold them, and why they must be assigned on the boundary.
Actions
| Action | Allows |
|---|---|
sentinel/read |
See the boundary's findings with their evidence, its runs and overview, and the Sentinel cards on its resources |
sentinel/write |
Change a finding's status, start Analyze with logs, and turn monitoring of a resource on or off |
sentinel/admin |
See platform findings — held at the platform root |
Analyze with logs also needs permission to read the resource's logs. The steps in a finding
each need their own action on the resource, such as apps/scale; see
Steps and who does them.
Important
sentinel/readandsentinel/writeare checked at the boundary, andsentinel/adminat the platform root. A role assigned on a resource group or on a single resource gives no access to Sentinel: someone who may only see one app does not see its findings, not even on the app's own Sentinel card.
Roles
| Role | Read | Write | Platform findings |
|---|---|---|---|
| Reader, Platform Reader | Yes | No | No |
| Apps Reader, Databases Reader, Functions Reader, Jobs Reader, Storage Reader, Blueprint Reader | Yes | No | No |
| Secrets Reader, Secrets Writer | Yes | No | No |
| Apps Operator, Databases Operator, Functions Operator, Jobs Operator, Storage Operator, Blueprints Operator | Yes | Yes | No |
| Contributor, Owner | Yes | Yes | No |
| Platform Contributor, Platform Owner | Yes | Yes | Yes |
Caution
Every role that can read findings can read their evidence, including log lines stored on them — also roles that may not read the resource's logs, such as Databases Reader or Secrets Reader. See Evidence.