RBAC role definitions
Note
Available in Grafana Enterprise and Grafana Cloud.
The following tables list permissions associated with basic and fixed roles. This does not include basic role assignments added by plugins or apps.
Basic role assignments
| Basic role | UID | Associated fixed roles | Description | 
|---|---|---|---|
| Grafana Admin | basic_grafana_admin | ||
| fixed:authentication.config:writerfixed:general.auth.config:writerfixed:ldap:writerfixed:licensing:writerfixed:migrationassistant:migratorfixed:org.users:writerfixed:organization:maintainerfixed:plugins:maintainerfixed:provisioning:writerfixed:roles:writerfixed:settings:readerfixed:settings:writerfixed:stats:readerfixed:support.bundles:writerfixed:usagestats:readerfixed:users:writer | Default Grafana server administrator assignments. | ||
| Admin | basic_admin | All roles assigned to Editor and fixed:reports:writerfixed:datasources:writerfixed:organization:writerfixed:datasources.permissions:writerfixed:teams:writerfixed:dashboards:writerfixed:dashboards.permissions:writerfixed:dashboards.public:writerfixed:folders:writerfixed:folders.permissions:writerfixed:alerting:writerfixed:alerting.provisioning.secrets:readerfixed:alerting.provisioning:writerfixed:datasources.caching:writerfixed:plugins:writerfixed:library.panels:writer | Default Grafana organization administrator assignments. | 
| Editor | basic_editor | All roles assigned to Viewer and fixed:datasources:explorerfixed:dashboards:creatorfixed:folders:creatorfixed:annotations:writerfixed:alerting:writerfixed:library.panels:creatorfixed:library.panels:general.writerfixed:alerting.provisioning.status:writer | Default Editor assignments. | 
| Viewer | basic_viewer | fixed:datasources.id:readerfixed:organization:readerfixed:annotations:readerfixed:annotations.dashboard:writerfixed:alerting:readerfixed:plugins.app:readerfixed:dashboards.insights:readerfixed:datasources.insights:readerfixed:library.panels:general.readerfixed:folders.general:readerfixed:datasources.builtin:reader | Default Viewer assignments. | 
| No Basic Role | n/a | Default No Basic Role | 
Fixed role definitions
The following table has the existing built-in fixed role definitions. Other fixed roles might be added by plugins installed in Grafana. The UUID presented here can be used as an identifier for Terraform provisioning.
Caution
These UUIDs won’t be available if your instance was created before Grafana v10.2.0.
To learn how to use the roles API to determine the role UUIDs, refer to Manage RBAC roles.
| Fixed role | UUID | Permissions | Description | 
|---|---|---|---|
| fixed:alerting:reader | fixed_O2oP1_uBFozI2i93klAkcvEWR30 | All permissions from fixed:alerting.rules:readerfixed:alerting.instances:readerfixed:alerting.notifications:reader | Read-only permissions for all Grafana, Mimir, Loki and Alertmanager alert rules*, alerts, contact points, and notification policies.* | 
| fixed:alerting:writer | fixed_-PAZgSJsDlRD8NUg-PFSeH_BkJY | All permissions from fixed:alerting.rules:writerfixed:alerting.instances:writerfixed:alerting.notifications:writer | Create, update, and delete Grafana, Mimir, Loki and Alertmanager alert rules*, silences, contact points, templates, mute timings, and notification policies.* | 
| fixed:alerting.instances:reader | fixed_ut5fVS-Ulh_ejFoskFhJT_rYg0Y | alert.instances:readfor organization scopealert.instances.external:readfor scopedatasources:* | Read all alerts and silences in the organization produced by Grafana Alerts and Mimir and Loki alerts and silences.* | 
| fixed:alerting.instances:writer | fixed_pKOBJE346uyqMLdgWbk1NsQfEl0 | All permissions from fixed:alerting.instances:readerandalert.instances:createalert.instances:writefor organization scopealert.instances.external:writefor scopedatasources:* | Create, update and expire all silences in the organization produced by Grafana, Mimir, and Loki.* | 
| fixed:alerting.notifications:reader | fixed_hmBn0lX5h1RZXB9Vaot420EEdA0 | alert.notifications:readfor organization scopealert.notifications.external:readfor scopedatasources:* | Read all Grafana and Alertmanager contact points, templates, and notification policies.* | 
| fixed:alerting.notifications:writer | fixed_XplK6HPNxf9AP5IGTdB5Iun4tJc | All permissions from fixed:alerting.notifications:readerandalert.notifications:writefor organization scopealert.notifications.external:readfor scopedatasources:* | Create, update, and delete contact points, templates, mute timings and notification policies for Grafana and external Alertmanager.* | 
| fixed:alerting.provisioning:writer | fixed_y7pFjdEkxpx5ETdcxPvp0AgRuUo | alert.provisioning:readandalert.provisioning:write | Create, update and delete Grafana alert rules, notification policies, contact points, templates, etc via provisioning API. * | 
| fixed:alerting.provisioning.secrets:reader | fixed_9fmzXXZZG-Od0Amy2ofEG8Uk--c | alert.provisioning:readandalert.provisioning.secrets:read | Read-only permissions for Provisioning API and let export resources with decrypted secrets * | 
| fixed:alerting.provisioning.status:writer | fixed_eAxlzfkTuobvKEgXHveFMBZrOj8 | alert.provisioning.provenance:write | Set provenance status to alert rules, notification policies, contact points, etc. Should be used together with regular writer roles. * | 
| fixed:alerting.rules:reader | fixed_fRGKL_vAqUsmUWq5EYKnOha9DcA | alert.rule:read,alert.silences:readfor scopefolders:*alert.rules.external:readfor scopedatasources:*alert.notifications.time-intervals:readalert.notifications.receivers:list | Read all* Grafana, Mimir, and Loki alert rules.* and read rule-specific silences | 
| fixed:alerting.rules:writer | fixed_YJJGwAalUwDZPrXSyFH8GfYBXAc | All permissions from fixed:alerting.rules:readerandalert.rule:createalert.rule:writealert.rule:deletealert.silences:createalert.silences:writefor scopefolders:*alert.rules.external:writefor scopedatasources:* | Create, update, and delete all* Grafana, Mimir, and Loki alert rules.* and manage rule-specific silences | 
| fixed:annotations:reader | fixed_hpZnoizrfAJsrceNcNQqWYV-xNU | annotations:readfor scopesannotations:type:* | Read all annotations and annotation tags. | 
| fixed:annotations:writer | fixed_ZVW-Aa9Tzle6J4s2aUFcq1StKWE | All permissions from fixed:annotations:readerannotations:writeannotations.createannotations:deletefor scopeannotations:type:* | Read, create, update and delete all annotations and annotation tags. | 
| fixed:annotations.dashboard:writer | fixed_8A775xenXeKaJk4Cr7bchP9yXOA | annotations:writeannotations.createannotations:deletefor scopeannotations:type:dashboard | Create, update and delete dashboard annotations and annotation tags. | 
| fixed:authentication.config:writer | fixed_0rYhZ2Qnzs8AdB1nX7gexk3fHDw | settings:readfor scopesettings:auth.saml:*settings:writefor scopesettings:auth.saml:* | Read and update authentication and SAML settings. | 
| fixed:general.auth.config:writer | fixed_QFxIT_FGtBqbIVJIwx1bLgI5z6c | settings:readfor scopesettings:auth:oauth_allow_insecure_email_lookupsettings:writefor scopesettings:auth:oauth_allow_insecure_email_lookup | Read and update the Grafana instance’s general authentication configuration settings. | 
| fixed:dashboards:creator | fixed_ZorKUcEPCM01A1fPakEzGBUyU64 | dashboards:createfolders:read | Create dashboards. | 
| fixed:dashboards:reader | fixed_Sgr67JTOhjQGFlzYRahOe45TdWM | dashboards:read | Read all dashboards. | 
| fixed:dashboards:writer | fixed_OK2YOQGIoI1G031hVzJB6rAJQAs | All permissions from fixed:dashboards:readeranddashboards:writedashboards:deletedashboards:createdashboards.permissions:readdashboards.permissions:write | Read, create, update, and delete all dashboards. | 
| fixed:dashboards.insights:reader | fixed_JlBJ2_gizP8zhgaeGE2rjyZe2Rs | dashboards.insights:read | Read dashboard insights data and see presence indicators. | 
| fixed:dashboards.permissions:reader | fixed_f17oxuXW_58LL8mYJsm4T_mCeIw | dashboards.permissions:read | Read all dashboard permissions. | 
| fixed:dashboards.permissions:writer | fixed_CcznxhWX_Yqn8uWMXMQ-b5iFW9k | All permissions from fixed:dashboards.permissions:readeranddashboards.permissions:write | Read and update all dashboard permissions. | 
| fixed:dashboards.public:writer | fixed_f_GHHRBciaqESXfGz2oCcooqHxs | dashboards.public:write | Create, update, delete or pause a shared dashboard. | 
| fixed:datasources:creator | fixed_XX8jHREgUt-wo1A-rPXIiFlX6Zw | datasources:create | Create data sources. | 
| fixed:datasources:explorer | fixed_qDzW9mzx9yM91T5Bi8dHUM2muTw | datasources:explore | Enable the Explore feature. Data source permissions still apply, you can only query data sources for which you have query permissions. | 
| fixed:datasources:reader | fixed_C2x8IxkiBc1KZVjyYH775T9jNMQ | datasources:readdatasources:query | Read and query data sources. | 
| fixed:datasources:writer | fixed_q8HXq8kjjA5IlHHgBJlKlUyaNik | All permissions from fixed:datasources:readeranddatasources:createdatasources:writedatasources:delete | Read, query, create, delete, or update a data source. | 
| fixed:datasources.builtin:reader | fixed_q8HXq8kjjA5IlHHgBJlKlUyaNik | datasources:readanddatasources:queryscoped todatasources:uid:grafana | An internal role used to grant Viewers access to the builtin example data source in Grafana. | 
| fixed:datasources.caching:reader | fixed_D2ddpGxJYlw0mbsTS1ek9fj0kj4 | datasources.caching:read | Read data source query caching settings. | 
| fixed:datasources.caching:writer | fixed_JtFjHr7jd7hSqUYcktKvRvIOGRE | datasources.caching:readdatasources.caching:write | Enable, disable, or update query caching settings. | 
| fixed:datasources.id:reader | fixed_entg--fHmDqWY2-69N0ocawK0Os | datasources.id:read | Read the ID of a data source based on its name. | 
| fixed:datasources.insights:reader | fixed_EBZ3NwlfecNPp2p0XcZRC1nfEYk | datasources.insights:read | Read data source insights data. | 
| fixed:datasources.permissions:reader | fixed_ErYA-cTN3yn4h4GxaVPcawRhiOY | datasources.permissions:read | Read data source permissions. | 
| fixed:datasources.permissions:writer | fixed_aiQh9YDfLOKjQhYasF9_SFUjQiw | All permissions from fixed:datasources.permissions:readeranddatasources.permissions:write | Create, read, or delete permissions of a data source. | 
| fixed:folders:creator | fixed_gGLRbZGAGB6n9uECqSh_W382RlQ | folders:create | Create folders in the root level. | 
| fixed:folders:reader | fixed_yeW-5QPeo-i5PZUIUXMlAA97GnQ | folders:readdashboards:read | Read all folders and dashboards. | 
| fixed:folders:writer | fixed_wJXLoTzgE7jVuz90dryYoiogL0o | All permissions from fixed:dashboards:writerandfolders:readfolders:writefolders:createfolders:deletefolders.permissions:readfolders.permissions:write | Read, update, and delete all folders and dashboards. Create folders and subfolders. | 
| fixed:folders.general:reader | fixed_rSASbkg8DvpG_gTX5s41d7uxRvI | folders:readscoped tofolders:uid:general | An internal role used to correctly display access to the folder tree for Viewer role. | 
| fixed:folders.permissions:reader | fixed_E06l4cx0JFm47EeLBE4nmv3pnSo | folders.permissions:read | Read all folder permissions. | 
| fixed:folders.permissions:writer | fixed_3GAgpQ_hWG8o7-lwNb86_VB37eI | All permissions from fixed:folders.permissions:readerandfolders.permissions:write | Read and update all folder permissions. | 
| fixed:ldap:reader | fixed_lMcOPwSkxKY-qCK8NMJc5k6izLE | ldap.user:readldap.status:read | Read the LDAP configuration and LDAP status information. | 
| fixed:ldap:writer | fixed_p6AvnU4GCQyIh7-hbwI-bk3GYnU | All permissions from fixed:ldap:readerandldap.user:syncldap.config:reload | Read and update the LDAP configuration, and read LDAP status information. | 
| fixed:library.panels:creator | fixed_6eX6ItfegCIY5zLmPqTDW8ZV7KY | library.panels:createfolders:read | Create library panel at the root level. | 
| fixed:library.panels:general.reader | fixed_ct0DghiBWR_2BiQm3EvNPDVmpio | library.panels:read | Read all library panels at the root level. | 
| fixed:library.panels:general.writer | fixed_DgprkmqfN_1EhZ2v1_d1fYG8LzI | All permissions from fixed:library.panels:general.readerpluslibrary.panels:createlibrary.panels:deletelibrary.panels:write | Create, read, write or delete all library panels and their permissions at the root level. | 
| fixed:library.panels:reader | fixed_tvTr9CnZ6La5vvUO_U_X1LPnhUs | library.panels:read | Read all library panels. | 
| fixed:library.panels:writer | fixed_JTljAr21LWLTXCkgfBC4H0lhBC8 | All permissions from fixed:library.panels:readerpluslibrary.panels:createlibrary.panels:deletelibrary.panels:write | Create, read, write or delete all library panels and their permissions. | 
| fixed:licensing:reader | fixed_OADpuXvNEylO2Kelu3GIuBXEAYE | licensing:readlicensing.reports:read | Read licensing information and licensing reports. | 
| fixed:licensing:writer | fixed_gzbz3rJpQMdaKHt-E4q0PVaKMoE | All permissions from fixed:licensing:readerandlicensing:writelicensing:delete | Read licensing information and licensing reports, update and delete the license token. | 
| fixed:migrationassistant:migrator | fixed_LLk2p7TRuBztOAksTQb1Klc8YTk | migrationassistant:migrate | Execute on-prem to cloud migrations through the Migration Assistant. | 
| fixed:org.users:reader | fixed_oCqNwlVHLOpw7-jAlwp4HzYqwGY | org.users:read | Read users within a single organization. | 
| fixed:org.users:writer | fixed_VERj5nayasjgf_Yh0sWqqCkxWlw | All permissions from fixed:org.users:readerandorg.users:addorg.users:removeorg.users:write | Within a single organization, add a user, invite a new user, read information about a user and their role, remove a user from that organization, or change the role of a user. | 
| fixed:organization:maintainer | fixed_CMm-uuBaPUBf4r8XG3jIvxo55bg | All permissions from fixed:organization:readerandorgs:writeorgs:createorgs:deleteorgs.quotas:write | Create, read, write, or delete an organization. Read or write its quotas. This role needs to be assigned globally. | 
| fixed:organization:reader | fixed_0SZPJlTHdNEe8zO91zv7Zwiwa2w | orgs:readorgs.quotas:read | Read an organization and its quotas. | 
| fixed:organization:writer | fixed_Y4jGqDd8w1yCrPwlik8z5Iu8-3M | All permissions from fixed:organization:readerandorgs:writeorgs.preferences:readorgs.preferences:write | Read an organization, its quotas, or its preferences. Update organization properties, or its preferences. | 
| fixed:plugins:maintainer | fixed_yEOKidBcWgbm74x-nTa3lW5lOyY | plugins:install | Install and uninstall plugins. Needs to be assigned globally. | 
| fixed:plugins:writer | fixed_MRYpGk7kpNNwt2VoVOXFiPnQziE | plugins:write | Enable and disable plugins and edit plugins’ settings. | 
| fixed:plugins.app:reader | fixed_AcZRiNYx7NueYkUqzw1o2OGGUAA | plugins.app:access | Access application plugins (still enforcing the organization role). | 
| fixed:provisioning:writer | fixed_bgk1FCyR6OEDwhgirZlQgu5LlCA | provisioning:reload | Reload provisioning. | 
| fixed:reports:reader | fixed_72_8LU_0ukfm6BdblOw8Z9q-GQ8 | reports:readreports:sendreports.settings:read | Read all reports and shared report settings. | 
| fixed:reports:writer | fixed_jBW3_7g1EWOjGVBYeVRwtFxhUNw | All permissions from fixed:reports:readerandreports:createreports:writereports:deletereports.settings:write | Create, read, update, or delete all reports and shared report settings. | 
| fixed:roles:reader | fixed_GkfG-1NSwEGb4hpK3-E3qHyNltc | roles:readteams.roles:readusers.roles:readusers.permissions:read | Read all access control roles, roles and permissions assigned to users, teams. | 
| fixed:roles:resetter | fixed_WgPpC3qJRmVpVTJavFNwfS5RuzQ | roles:writewith scopepermissions:type:escalate | Reset basic roles to their default. | 
| fixed:roles:writer | fixed_W5aFaw8isAM27x_eWfElBhZ0iOc | All permissions from fixed:roles:readerandroles:writeroles:deleteteams.roles:addteams.roles:removeusers.roles:addusers.roles:remove | Create, read, update, or delete all roles, assign or unassign roles to users, teams. | 
| fixed:serviceaccounts:creator | fixed_Ikw60fckA0MyiiZ73BawSfOULy4 | serviceaccounts:create | Create Grafana service accounts. | 
| fixed:serviceaccounts:reader | fixed_QFjJAZ88iawMLInYOxPA1DB1w6I | serviceaccounts:read | Read Grafana service accounts. | 
| fixed:serviceaccounts:writer | fixed_iBvUNUEZBZ7PUW0vdkN5iojc2sk | serviceaccounts:readserviceaccounts:createserviceaccounts:writeserviceaccounts:deleteserviceaccounts.permissions:readserviceaccounts.permissions:write | Create, update, read and delete all Grafana service accounts and manage service account permissions. | 
| fixed:settings:reader | fixed_0LaUt1x6PP8hsZzEBhqPQZFUd8Q | settings:read | Read Grafana instance settings. | 
| fixed:settings:writer | fixed_joIHDgMrGg790hMhUufVzcU4j44 | All permissions from fixed:settings:readerandsettings:write | Read and update Grafana instance settings. | 
| fixed:stats:reader | fixed_OnRCXxZVINWpcKvTF5A1gecJ7pA | server.stats:read | Read Grafana instance statistics. | 
| fixed:support.bundles:reader | fixed_gcPjI3PTUJwRx-GJZwDhNa7zbos | support.bundles:read | List and download support bundles. | 
| fixed:support.bundles:writer | fixed_dTgCv9Wxrp_WHAhwHYIgeboxKpE | support.bundles:readsupport.bundles:createsupport.bundles:delete | Create, delete, list and download support bundles. | 
| fixed:teams:creator | fixed_nzVQoNSDSn0fg1MDgO6XnZX2RZI | teams:createorg.users:read | Create a team and list organization users (required to manage the created team). | 
| fixed:teams:read | fixed_Z8pB0GQlrqRt8IZBCJQxPWvJPgQ | teams:read | List all teams. | 
| fixed:teams:writer | fixed_xw1T0579h620MOYi4L96GUs7fZY | teams:createteams:deleteteams:readteams:writeteams.permissions:readteams.permissions:write | Create, read, update and delete teams and manage team memberships. | 
| fixed:usagestats:reader | fixed_eAM0azEvnWFCJAjNkUKnGL_1-bU | server.usagestats.report:read | View usage statistics report. | 
| fixed:users:reader | fixed_buZastUG3reWyQpPemcWjGqPAd0 | users:readusers.quotas:readusers.authtoken:read | Read all users and their information, such as team memberships, authentication tokens, and quotas. | 
| fixed:users:writer | fixed_wjzgHHo_Ux25DJuELn_oiAdB_yM | All permissions from fixed:users:readerandusers:writeusers:createusers:deleteusers:enableusers:disableusers.password:writeusers.permissions:writeusers:logoutusers.authtoken:writeusers.quotas:write | Read and update all attributes and settings for all users in Grafana: update user information, read user information, create or enable or disable a user, make a user a Grafana administrator, sign out a user, update a user’s authentication token, or update quotas for all users. | 
Alerting roles
You can use predefined roles to manage user access to alert rules, alert instances, and alert notification settings and create custom roles to limit user access to alert rules in a folder.
Access to Grafana alert rules is an intersection of many permissions:
- Permission to read a folder. For example, the fixed role fixed:folders:readerincludes the actionfolders:readand a folder scopefolders:id:.
- Permission to query all data sources that a given alert rule uses. If a user cannot query a given data source, they cannot see any alert rules that query that data source.
There is only one exclusion at this moment. Role fixed:alerting.provisioning:writer does not require user to have any additional permissions and provides access to all aspects of the alerting configuration via special provisioning API.
For more information about the permissions required to access alert rules, refer to Create a custom role to access alerts in a folder.
Grafana OnCall roles
If you are using Grafana OnCall, you can try out the integration between Grafana OnCall and RBAC. For a detailed list of the available OnCall RBAC roles, refer to the table in Available Grafana OnCall RBAC roles and granted actions.
The following table lists the default RBAC OnCall role assignments to the basic roles:
| Basic role | Associated fixed roles | Description | 
|---|---|---|
| Grafana Admin | plugins:grafana-oncall-app:admin | Default Grafana server administrator assignments. | 
| Admin | plugins:grafana-oncall-app:admin | Default Grafana organization administrator assignments. | 
| Editor | plugins:grafana-oncall-app:editor | Default Editor assignments. | 
| Viewer | plugins:grafana-oncall-app:reader | Default Viewer assignments. | 
Private data source connect roles
The following table lists how private data source connect fixed roles are assigned to the basic roles:
| Basic role | Associated fixed roles | Description | 
|---|---|---|
| Grafana Admin | plugins:grafana-pdc-app.private-networks:write,plugins:grafana-pdc-app.private-networks:read | Default Grafana server administrator assignments. | 
Note
These private data source connect fixed roles must be granted alongside the
fixed:datasources:writerrole for the permissions to take effect.







