forked from grafana.jool/grafana-jool
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
19 KiB
19 KiB
+++ title = "Fine-grained access control references" description = "Refer to fine-grained access control references" keywords = ["grafana", "fine-grained-access-control", "roles", "fixed-roles", "built-in-role-assignments", "permissions", "enterprise"] weight = 130 +++
Fine-grained access control references
The reference information that follows complements conceptual information about [Roles]({{< relref "./roles.md" >}}).
Fine-grained access fixed roles
| Fixed roles | Permissions | Descriptions |
|---|---|---|
fixed:roles:reader |
roles:readroles:listusers.roles:listusers.permissions:listroles.builtin:list |
Read all access control roles, roles and permissions assigned to users and built-in role assignments. |
fixed:roles:writer |
All permissions from fixed:roles:reader and roles:writeroles:deleteusers.roles:addusers.roles:removeroles.builtin:addroles.builtin:remove |
Create, read, update, or delete all roles, assign or unassign roles to users and built-in role assignments. |
fixed:reports:reader |
reports:readreports:sendreports.settings:read |
Read all reports and shared report settings. |
fixed:reports:writer |
All permissions from fixed:reports:reader and reports.admin:writereports:deletereports.settings:write |
Create, read, update, or delete all reports and shared report settings. |
fixed:users:reader |
users:readusers.quotas:listusers.authtoken:listusers.teams:read |
Read all users and their information, such as team memberships, authentication tokens, and quotas. |
fixed:users:writer |
All permissions from fixed:users:reader and users:writeusers:createusers:deleteusers:enableusers:disableusers.password:updateusers.permissions:updateusers:logoutusers.authtoken:updateusers.quotas:update |
Read and update all attributes and settings for all users in Grafana: update user information, read user information, create or enable or disable a user, make a user a Grafana administrator, sign out a user, update a user’s authentication token, or update quotas for all users. |
fixed:org.users:reader |
org.users:read |
Read users within a single organization. |
fixed:org.users:writer |
All permissions from fixed:org.users:reader and org.users:addorg.users:removeorg.users.role:update |
Within a single organization, add a user, invite a user, read information about a user and their role, remove a user from that organization, or change the role of a user. |
fixed:ldap:reader |
ldap.user:readldap.status:read |
Read the LDAP configuration and LDAP status information. |
fixed:ldap:writer |
All permissions from fixed:ldap:reader and ldap.user:syncldap.config:reload |
Read and update the LDAP configuration, and read LDAP status information. |
fixed:stats:reader |
server.stats:read |
Read Grafana instance statistics. |
fixed:settings:reader |
settings:read |
Read Grafana instance settings. |
fixed:settings:writer |
All permissions from fixed:settings:reader andsettings:write |
Read and update Grafana instance settings. |
fixed:datasources:explorer |
datasources:explore |
Enable the Explore feature. Data source permissions still apply, you can only query data sources for which you have query permissions. |
fixed:datasources:reader |
datasources:readdatasources:query |
Read and query data sources. |
fixed:datasources:writer |
All permissions from fixed:datasources:reader and datasources:createdatasources:writedatasources:delete |
Read, query, create, delete, or update a data source. |
fixed:datasources:id:reader |
datasources.id:read |
Read the ID of a data source based on its name. |
fixed:datasources.permissions:reader |
datasources.permissions:read |
Read data source permissions. |
fixed:datasources.permissions:writer |
All permissions from fixed:datasources.permissions:reader and datasources.permissions:createdatasources.permissions:deletedatasources.permissions:toggle |
Create, read, or delete permissions of a data source. |
fixed:licensing:reader |
licensing:readlicensing.reports:read |
Read licensing information and licensing reports. |
fixed:licensing:writer |
All permissions from fixed:licensing:viewer and licensing:updatelicensing:delete |
Read licensing information and licensing reports, update and delete the license token. |
fixed:provisioning:writer |
provisioning:reload |
Reload provisioning. |
fixed:organization:reader |
orgs:readorgs.quotas:read |
Read an organization and its quotas. |
fixed:organization:writer |
All permissions from fixed:organization:reader and orgs:writeorgs.preferences:readorgs.preferences:write |
Read an organization, its quotas, or its preferences. Update organization properties, or its preferences. |
fixed:organization:maintainer |
All permissions from fixed:organization:reader and orgs:writeorgs:createorgs:deleteorgs.quotas:write |
Create, read, write, or delete an organization. Read or write its quotas. This role needs to be assigned globally. |
Default built-in role assignments
| Built-in role | Associated role | Description |
|---|---|---|
| Grafana Admin | fixed:roles:readerfixed:roles:writerfixed:users:readerfixed:users:writerfixed:org.users:readerfixed:org.users:writerfixed:ldap:readerfixed:ldap:writerfixed:stats:readerfixed:settings:readerfixed:settings:writerfixed:provisioning:writerfixed:organization:readerfixed:organization:maintainerfixed:licensing:readerfixed:licensing:writer |
Default [Grafana server administrator]({{< relref "../../permissions/_index.md#grafana-server-admin-role" >}}) assignments. |
| Admin | fixed:reports:readerfixed:reports:writerfixed:datasources:readerfixed:datasources:writerfixed:organization:writerfixed:datasources.permissions:readerfixed:datasources.permissions:writer |
Default [Grafana organization administrator]({{< relref "../../permissions/organization_roles.md" >}}) assignments. |
| Editor | fixed:datasources:explorer |
Default [Editor]({{< relref "../../permissions/organization_roles.md" >}}) assignments. |
| Viewer | fixed:datasources:id:readerfixed:organization:reader |
Default [Viewer]({{< relref "../../permissions/organization_roles.md" >}}) assignments. |