Configure access control
Access is enforced through Grafana role-based access control (RBAC), using the same external alerting permissions that Grafana Alerting uses for data source-managed resources. The plugin defines no permissions of its own, so a user who can already manage external rules and Alertmanager configuration in Grafana can do the same here.
Permissions
How permissions map to pages
Read permission controls whether a page is reachable at all. Write permission controls whether the create and edit actions on that page are offered.
Pages a user can’t read are hidden from the plugin navigation rather than shown and then refused. Someone with only alert.rules.external:read sees a plugin containing rule pages and nothing else.
Two reasons an action can be unavailable
An action can be missing for two quite different reasons, and it’s worth telling them apart before granting anyone more access:
- Insufficient permissions. The user’s role doesn’t include the required permission. Granting the permission fixes it.
- Not supported. The data source itself can’t do it, most commonly a vanilla Prometheus rules source with no writable ruler API. No amount of permission changes this; refer to Configure data sources.
Assign permissions
These permissions are included in the built-in Grafana alerting roles. To grant them individually, create a custom role and assign it to a user, team, or service account.
For the full procedure, refer to Manage RBAC roles.
Note
Custom roles require Grafana Enterprise or Grafana Cloud. On Grafana OSS, use the built-in roles.
Enabling the plugin is separate
Installing and enabling the app requires the Grafana Admin role, which is independent of the permissions above. Enabling it once makes the plugin available to everyone; what each person can then do is decided by the permissions in this table.


