Azure DevOps built-in role
Chaos Studio Operator
Reads Chaos Studio resources and starts, cancels, and retrieves execution details for existing experiments. The role uses control-plane Actions and has no DataActions; it cannot create experiments or manage targets and capabilities.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 1a40e87e-6645-48e0-b27a-0b115d849a20
Control-plane actions (10)
Microsoft.Chaos/*/readMicrosoft.Chaos/experiments/start/actionMicrosoft.Chaos/experiments/cancel/actionMicrosoft.Chaos/experiments/executions/getExecutionDetails/actionMicrosoft.Chaos/locations/operationResults/readMicrosoft.Chaos/locations/operationStatuses/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual experiment or the resource group containing the approved experiments. A broader assignment is inherited by every Chaos Studio experiment below it, but does not replace the separate target-resource permissions required by each experiment managed identity.
Common use cases (2)
- Run and stop preapproved chaos experiments during a controlled resilience exercise.
- Inspect execution status and per-action errors without changing experiment definitions or target onboarding.
Prerequisites (2)
- An approved experiment must already exist with every target and capability onboarded.
- The experiment managed identity must have the documented permissions on all target resources and the exercise owner must approve the expected blast radius.
Best practices (3)
- Use Operator instead of Experiment Contributor when the principal does not design experiments or onboard targets.
- Restrict assignments to the specific experiments used by the operations team and require a reviewed execution window and recovery plan.
- Verify the experiment identity permissions and target capabilities before starting a run.
Security considerations (3)
- The experiment start Action triggers fault injection and can disrupt services even though the role cannot edit the experiment.
- Cancel authority can stop an active exercise, while execution details can expose operational status and fault errors.
- An assignment at resource-group or subscription scope permits the principal to start every inherited Chaos Studio experiment.
Assignment guidance
Assign Chaos Studio Operator directly on an approved experiment or its dedicated resource group to the team that executes resilience tests. Keep experiment creation and target onboarding with separate principals, and grant target permissions only to the experiment managed identity.
Related roles (2)
- Chaos Studio Experiment Contributor: Adds experiment creation and target or capability management to the Operator execution permissions.
- Chaos Studio Reader: Retains viewing and execution-detail access without the ability to start or cancel experiments.
Editorial sources (6)
- Azure built-in roles for DevOps - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Permissions and security in Azure Chaos Studio →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.