Azure DevOps built-in role
Chaos Studio Experiment Contributor
Creates, updates, deletes, starts, cancels, and inspects Chaos Studio experiments and can onboard targets and manage capabilities. The published role contains control-plane Actions only and no DataActions; the separate managed identity attached to an experiment performs the fault operations against target resources.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 7c2e40b7-25eb-482a-82cb-78ba06cb46d5
Control-plane actions (5)
Microsoft.Chaos/*Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign only where the principal must manage both experiment resources and Chaos target or capability extension resources. Parent-scope assignments are inherited, while the experiment managed identity still needs separate permissions on every target resource before a fault can run.
Common use cases (2)
- Let a resilience engineering team design, onboard, run, stop, and troubleshoot approved Chaos Studio experiments.
- Manage target capabilities and experiment definitions together when the same trusted team owns both stages of the chaos workflow.
Prerequisites (2)
- Define approved target resources, fault types, blast radius, rollback or recovery checks, and an experiment identity before granting experiment administration.
- Give the experiment managed identity the documented fault-specific permissions on every target and enable the required target capabilities.
Best practices (3)
- Separate experiment design from routine execution by using Chaos Studio Operator for users who only run approved experiments.
- Test with a small blast radius, verify target permissions before execution, and avoid putting passwords or other sensitive data in experiment properties.
- Keep experiment identity permissions on target resources separate from human access to the Chaos Studio experiment.
Security considerations (3)
- Starting an experiment intentionally injects faults and can have a wider operational impact than expected; Microsoft identifies the start Action as the most important operation to restrict.
- The role can both make a resource eligible for fault injection and start the experiment that injects faults, concentrating setup and execution authority.
- A user-assigned experiment identity can be reused by multiple experiments, and automatically created custom-role assignments can persist after an experiment is deleted.
Assignment guidance
Assign Chaos Studio Experiment Contributor to a small resilience team at the narrowest scope containing its approved experiments and target registrations. Give target-resource permissions to the experiment managed identity separately, and use Operator, Reader, or Target Contributor where the full combined workflow is unnecessary.
Related roles (3)
- Chaos Studio Operator: Runs and inspects existing experiments without creating experiments or managing targets and capabilities.
- Chaos Studio Target Contributor: Onboards targets and capabilities without creating, starting, or inspecting experiment execution details.
- Chaos Studio Reader: Provides the documented view-only Chaos Studio workflow without experiment start or target changes.
Editorial sources (6)
- Azure built-in roles for DevOps - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Permissions and security in Azure Chaos Studio →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.