Silences Writer: fixed:alerting.instances:writer | All permissions from fixed:alerting.instances:reader and
alert.instances:create
alert.instances:write for organization scope
alert.instances.external:write for scope datasources:* | Add and update silences in Grafana and external providers. |
Instances and Silences Reader: fixed:alerting.instances:reader | alert.instances:read for organization scope
alert.instances.external:read for scope datasources:* | Read alert instances and silences in Grafana and external providers. |
Notifications Writer: fixed:alerting.notifications:writer | All permissions from fixed:alerting.notifications:reader,
fixed:alerting.receivers:writer,
fixed:alerting.templates:writer,
fixed:alerting.time-intervals:writer,
fixed:alerting.routes:writer,
fixed:alerting.inhibition-rules:writer,
fixed:alerting.notifications.external:writerand
alert.notifications:write for organization scope | Add, update, and delete notification policies and contact points in Grafana and external providers. |
Notifications Reader: fixed:alerting.notifications:reader | All permissions from fixed:alerting.receivers:reader,
fixed:alerting.templates:reader,
fixed:alerting.time-intervals:reader,
fixed:alerting.routes:reader,
fixed:alerting.inhibition-rules:reader,
fixed:alerting.notifications.external:readerand
alert.notifications:read for organization scope | Read notification policies and contact points in Grafana and external providers. |
Rules Writer: fixed:alerting.rules:writer | All permissions from fixed:alerting.rules:reader and
alert.rule:create
alert.rule:write
alert.rule:delete
alert.silences:create
alert.silences:write for scope folders:*
alert.rules.external:write for scope datasources:* | Create, update, and delete all alert rules and manage rule-specific silences. |
Rules Reader: fixed:alerting.rules:reader | alert.rule:read, alert.silences:read for scope folders:*
alert.rules.external:read for scope datasources:*
alert.notifications.time-intervals:read
alert.notifications.receivers:list | Read all alert rules and rule-specific silences in Grafana and external providers. |
Full access: fixed:alerting:writer | All permissions from fixed:alerting.rules:writer
fixed:alerting.instances:writer
fixed:alerting.notifications:writer | Add, update, and delete alert rules, silences, contact points, and notification policies in Grafana and external providers. |
Full read-only access: fixed:alerting:reader | All permissions from fixed:alerting.rules:reader
fixed:alerting.instances:reader
fixed:alerting.notifications:reader | Read alert rules, alert instances, silences, contact points, and notification policies in Grafana and external providers. |
Read via Provisioning API + Export Secrets: fixed:alerting.provisioning.secrets:reader | alert.provisioning:read and alert.provisioning.secrets:read | Read alert rules, alert instances, silences, contact points, and notification policies using the provisioning API and use export with decrypted secrets. |
Access to alert rules provisioning API: fixed:alerting.provisioning:writer | alert.provisioning:read and alert.provisioning:write | Manage all alert rules, notification policies, contact points, templates, in the organization using the provisioning API. |
Set provisioning status: fixed:alerting.provisioning.provenance:writer | alert.provisioning.provenance:write | Set provisioning rules for Alerting resources. Should be used together with other regular roles (Notifications Writer and/or Rules Writer.) |
Contact Point Reader: fixed:alerting.receivers:reader | alert.notifications.receivers:read for scope receivers:* | Read all contact points. |
Contact Point Creator: fixed:alerting.receivers:creator | alert.notifications.receivers:create
alert.notifications.receivers.test:create for scope receivers:uid:- | Create a new contact point. The user is automatically granted full access to the created contact point. |
Contact Point Writer: fixed:alerting.receivers:writer | All permissions from fixed:alerting.receivers:creator
alert.notifications.receivers:read, alert.notifications.receivers:write, alert.notifications.receivers:delete and alert.notifications.receivers.test:create for scope receivers:* | Create a new contact point and manage all existing contact points. |
Templates Reader: fixed:alerting.templates:reader | alert.notifications.templates:read | Read all notification templates. |
Templates Writer: fixed:alerting.templates:writer | alert.notifications.templates:read, alert.notifications.templates:write, alert.notifications.templates:delete, alert.notifications.templates.test:write | Create new and manage existing notification templates. Test templates with custom payloads. |
Time Intervals Reader: fixed:alerting.time-intervals:reader | alert.notifications.time-intervals:read | Read all time intervals. |
Time Intervals Writer: fixed:alerting.time-intervals:writer | alert.notifications.time-intervals:read, alert.notifications.time-intervals:write, alert.notifications.time-intervals:delete | Create new and manage existing time intervals. |
Notification Policies Reader: fixed:alerting.routes:reader | alert.notifications.routes:read | Read all notification policies. |
Notification Policies Writer: fixed:alerting.routes:writer | alert.notifications.routes:read
alert.notifications.routes:write | Create new and manage existing notification policies. |
Inhibition Rules Reader: fixed:alerting.inhibition-rules:reader | alert.notifications.inhibition-rules:read for scope inhibition-rules:* | Read all inhibition rules. |
Inhibition Rules Writer: fixed:alerting.inhibition-rules:writer | All permissions from fixed:alerting.inhibition-rules:reader and
alert.notifications.inhibition-rules:write, alert.notifications.inhibition-rules:delete for scope inhibition-rules:* | Create, update, and delete all inhibition rules. |
Full admin access: fixed:alerting:admin | All permissions from fixed:alerting:writer and
alert.notifications.receivers.permissions:read, alert.notifications.receivers.permissions:write, alert.notifications.receivers:readSecrets, alert.notifications.receivers:updateProtected for scope receivers:* | Full write access in Grafana and all external providers, including their permissions, protected fields and secrets. |
Enrichments Reader: fixed:alerting.enrichments:reader | alert.enrichments:read | Read all alert enrichment configurations. |
Enrichments Writer: fixed:alerting.enrichments:writer | alert.enrichments:read
alert.enrichments:write | Create new and manage existing alert enrichment configurations. |
External Notifications Reader: fixed:alerting.notifications.external:reader | alert.notifications.external:read for scope datasources:* | Read notification policies and contact points in external providers. |
External Notifications Writer: fixed:alerting.notifications.external:writer | All permissions from fixed:alerting.notifications.external:reader and
alert.notifications.external:write for scope datasources:* | Add, update, and delete contact points and notification policies in external providers. |