1. Docs
  2. Pulumi Cloud
  3. Identity & access management
  4. Role-Based Access Control (RBAC)
  5. RBAC Scopes: Insights accounts

RBAC Scopes: Insights accounts

    This document defines all the available scopes in Pulumi Cloud assignable to specific insights accounts or sets of insights accounts.

    Note that creating, listing, or restoring insights accounts are organization-level operations, and these scopes can be found in the organization settings scopes.

    Insights Accounts

    ValueDescription
    insights_account_access:readView what users and roles can access an insights account.

    Granted by default permission: Account Read
    insights_account_access:updateManage what users and roles can access an insights account.

    Granted by default permission: Account Admin
    insights_account:deleteRemove an existing insights account. This permanently deletes the account and its associated data.

    Granted by default permission: Account Admin
    insights_account:readView insights account configurations and data. This includes access to monitoring settings and analysis results.

    Granted by default permission: Account Read
    insights_account:updateModify insights account settings and configurations. This allows updating monitoring parameters and analysis rules.

    Granted by default permission: Account Write
    insights_account:update_policy_resultsUpdate policy evaluation results for an insights account. This allows refreshing compliance data and analysis.

    Granted by default permission: Account Write

    Insights Scan

    ValueDescription
    insights_account:scanInitiate a new scan of an insights account. This triggers analysis of infrastructure configurations and compliance.

    Granted by default permission: Account Write
    insights_account_scan:cancelStop an ongoing insights account scan. This halts the current analysis process.

    Granted by default permission: Account Write
    insights_account_scan:pauseTemporarily suspend an insights account scan. This pauses the analysis process without losing progress.

    Granted by default permission: Account Write
    insights_account_scan:readView insights account scan results and status. This includes access to analysis findings and progress.

    Granted by default permission: Account Read
    insights_account_scan:resumeResume a paused insights account scan. This continues the analysis process from where it was paused.

    Granted by default permission: Account Write
    insights_account_scan:updateModify insights account scan settings. This allows updating scan parameters and analysis configurations.

    Granted by default permission: Account Write