Azure DevOps built-in role

Chaos Studio Experiment Contributor

Creates, updates, deletes, starts, cancels, and inspects Chaos Studio experiments and can onboard targets and manage capabilities. The published role contains control-plane Actions only and no DataActions; the separate managed identity attached to an experiment performs the fault operations against target resources.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 7c2e40b7-25eb-482a-82cb-78ba06cb46d5

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign only where the principal must manage both experiment resources and Chaos target or capability extension resources. Parent-scope assignments are inherited, while the experiment managed identity still needs separate permissions on every target resource before a fault can run.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Chaos Studio Experiment Contributor to a small resilience team at the narrowest scope containing its approved experiments and target registrations. Give target-resource permissions to the experiment managed identity separately, and use Operator, Reader, or Target Contributor where the full combined workflow is unnecessary.

Related roles (3)

Editorial sources (6)

Official Microsoft Learn documentation →