Skip to main content
Pulumi logo Pulumi logo
  1. Docs
  2. Administration
  3. Reference
  4. RBAC Scopes
  5. RBAC Scopes: Cloud Accounts

RBAC Scopes: Cloud Accounts

    This document defines all the available scopes in Pulumi Cloud assignable to specific cloud accounts or sets of cloud accounts.

    Note that creating, listing, or restoring cloud accounts are organization-level operations, and these scopes can be found in the organization settings scopes.

    Cloud accounts

    ValueDescription
    insights_account_access:readView what users and roles can access a cloud account.

    Granted by default permission set: Account Read
    insights_account_access:updateManage what users and roles can access a cloud account.

    Granted by default permission set: Account Admin
    insights_account:deleteRemove an existing cloud account. This permanently deletes the account and its associated data.

    Granted by default permission set: Account Admin
    insights_account:readView cloud account configurations and data. This includes access to monitoring settings and analysis results.

    Granted by default permission set: Account Read
    insights_account:updateModify cloud account settings and configurations. This allows updating monitoring parameters and analysis rules.

    Granted by default permission set: Account Write

    Cloud account scans

    ValueDescription
    insights_account:scanInitiate a new scan of a cloud account. This triggers analysis of infrastructure configurations and compliance.

    Granted by default permission set: Account Write
    insights_account_scan:cancelStop an ongoing cloud account scan. This halts the current analysis process.

    Granted by default permission set: Account Write
    insights_account_scan:pauseTemporarily suspend a cloud account scan. This pauses the analysis process without losing progress.

    Granted by default permission set: Account Write
    insights_account_scan:readView cloud account scan results and status. This includes access to analysis findings and progress.

    Granted by default permission set: Account Read
    insights_account_scan:resumeResume a paused cloud account scan. This continues the analysis process from where it paused.

    Granted by default permission set: Account Write
    insights_account_scan:updateModify cloud account scan settings. This allows updating scan parameters and analysis configurations.

    Granted by default permission set: Account Write

      The infrastructure as code platform for any cloud.