Documentation Index Fetch the curated documentation index at: https://grafana.com/llms.txt
Fetch the complete documentation index at: https://grafana.com/llms-full.txt Use this file to discover all available pages before exploring further.
STOP! If you are an AI agent or LLM, read this before continuing.
This is the HTML version of a Grafana documentation page. Always request
the Markdown version instead - HTML wastes context. Get this page as
Markdown: https://grafana.com/docs/grafana/v12.4/administration/roles-and-permissions/access-control/plugin-role-definitions.md (append .md) or send Accept: text/markdown
to https://grafana.com/docs/grafana/v12.4/administration/roles-and-permissions/access-control/plugin-role-definitions/. For the curated documentation index, use https://grafana.com/llms.txt.
For the complete documentation index, use https://grafana.com/llms-full.txt.
Menu
Important: This documentation is about an older version. It's relevant only to the release noted, many of the features and functions have been updated or replaced. Please view the current version.
This page lists the RBAC roles available for Grafana Cloud app plugins. Plugin roles control access to specific plugin features and can be assigned to users, teams, or basic roles.
For general information about how RBAC works with app plugins, refer to
RBAC for app plugins.
Note
Third-party plugins can define their own RBAC roles. This page documents roles for Grafana Cloud app plugins only. Refer to the documentation for third-party plugins to learn about their available roles.
Default plugin permissions by basic role
When you assign a user a basic organization role (Viewer, Editor, or Admin), they automatically receive default plugin permissions. The following table summarizes the default access level for each Grafana Cloud plugin.
Plugin
Viewer
Editor
Admin
Adaptive Logs
Read exemptions
Read exemptions
Admin access
Adaptive Metrics
Read recommendations, exemptions
Read recommendations, exemptions
Admin access
Adaptive Traces
Read recommendations
Read recommendations
Admin access
Application Observability
View access
View access
Admin access
Assistant
Chat access, user rules/quickstarts
+ MCP servers, investigations
+ Tenant-wide settings
Cloud Provider
Read access
Read access
Provider-specific write access
Cost Attributions
Read attributions
Read attributions
Read attributions
Cost Management and Billing
—
—
Full access
Fleet Management (Collector)
Read access
Read access
Full access
Frontend Observability
Read apps, source maps
+ Write apps, source maps
+ Delete apps
Grafana Auth
—
—
Write access policies
IRM
Read all
+ Write alert groups, schedules, maintenance, user settings
+ Write integrations, escalation chains, etc.
k6
Read settings
+ Write settings
Admin access
Knowledge Graph
Read assertions
+ Write configuration and rules
+ Full write access
Kubernetes Monitoring
Read all
Read all
Admin access
Labels
Read labels
+ Create, edit, delete labels
+ Full write access
Machine Learning
Read forecasting, outliers, sift
+ Write forecasting, outliers, sift
+ Full write access
OnCall
Read all
+ Write alert groups, schedules, maintenance, user settings
The permissions above are automatically granted based on the user’s organization role. You can assign additional plugin-specific roles (listed below) to grant more granular access.
Write and manage access policies for Grafana Cloud
Incident plugin
Plugin ID: grafana-incident-app
Plugin role
Description
plugins:grafana-incident-app:incident-access
Access to Grafana Incident
IRM plugin
Plugin ID: grafana-irm-app
Core roles
Plugin role
Description
plugins:grafana-irm-app:admin
Read/write access to everything in IRM
plugins:grafana-irm-app:editor
Similar to Admin, minus abilities to: create Integrations, create Escalation Chains, create Outgoing Webhooks, update ChatOps settings, update other user’s settings, and update general IRM settings
plugins:grafana-irm-app:reader
Read-only access to everything in IRM
plugins:grafana-irm-app:oncaller
Read access to everything in IRM, plus edit access to Alert Groups, Schedules, and own settings
plugins:grafana-irm-app:notifications-receiver
Receive alert notifications, plus edit own IRM settings
plugins:grafana-irm-app:incident-access
Access to Grafana IRM incidents
Alert groups
Plugin role
Description
plugins:grafana-irm-app:alert-groups-reader
Read-only access to Alert Groups
plugins:grafana-irm-app:alert-groups-editor
Read access to Alert Groups + ability to act on Alert Groups (acknowledge, resolve, etc)
Similar to Admin, minus abilities to: create Integrations, create Escalation Chains, create Outgoing Webhooks, update ChatOps settings, update other user’s settings, and update general OnCall settings
plugins:grafana-oncall-app:reader
Read-only access to everything in OnCall
plugins:grafana-oncall-app:oncaller
Read access to everything in OnCall, plus edit access to Alert Groups, Schedules, and own settings
plugins:grafana-oncall-app:notifications-receiver
Receive OnCall alert notifications, plus edit own OnCall settings
Alert groups
Plugin role
Description
plugins:grafana-oncall-app:alert-groups-reader
Read-only access to OnCall Alert Groups
plugins:grafana-oncall-app:alert-groups-editor
Read access to OnCall Alert Groups + ability to act on Alert Groups (acknowledge, resolve, etc)