Policy: Azure > Turbot > Permissions > Custom Levels
An ordered list of azure role names to use as custom Guardrails permission levels for Azure Subscriptions.
Levels in this policy will appear in the Guardrails console as grantable to Guardrails users as Azure/Role/{role name}. When granted access, Guardrails will grant the associated IAM role to the Azure user in the subscription.
Note that the IAM roles must already exist in the Azure Subscription.
Resource Types
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Policy Specification
Schema Type |
|
---|---|
Default |
|
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/iamPermissions
- tmod:@turbot/azure-iam#/policy/types/permissionsCustomLevelsSubscription
- turbot graphql policy-type --id "tmod:@turbot/azure-iam#/policy/types/permissionsCustomLevelsSubscription"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-iam#/policy/types/permissionsCustomLevelsSubscription"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI