Azure DevOps built-in role
Chaos Studio Reader
Views Chaos Studio targets, capabilities, experiments, and experiment execution details. The role contains control-plane Actions only and no DataActions, and it cannot start, cancel, create, update, or delete experiments.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 29e2da8a-229c-4157-8ae8-cc72fc506b74
Control-plane actions (6)
Microsoft.Chaos/*/readMicrosoft.Chaos/experiments/executions/getExecutionDetails/actionMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on an individual experiment, target resource, or a bounded resource group according to the resources the reviewer must inspect. Parent-scope assignments expose every inherited Chaos Studio resource.
Common use cases (2)
- Review experiment definitions, target onboarding, capabilities, execution status, and per-action errors for an audit or post-exercise review.
- Give service owners visibility into planned or completed chaos exercises without fault-injection authority.
Prerequisites (2)
- The Chaos Studio experiments or target resources to review must already exist in the selected scope.
- The reviewer must be approved to see experiment parameters and execution details for those resources.
Best practices (3)
- Use Reader for audit and observation instead of Operator or Contributor roles when no execution or configuration change is required.
- Assign at the individual experiment or target where cross-team visibility is unnecessary.
- Do not store payment information, passwords, or other sensitive data in experiment names, steps, branches, or fault parameters.
Security considerations (3)
- Execution details can reveal fault status, errors, target configuration, and other operational context even though the role cannot inject faults.
- A parent-scope assignment exposes Chaos Studio metadata for every inherited experiment and target.
- The role does not grant access to the target resource data plane or permission to execute the target fault itself.
Assignment guidance
Assign Chaos Studio Reader at the experiment, target, or dedicated resource-group scope to reviewers and service owners who only need visibility. Use Operator only for approved run control and use Target or Experiment Contributor only for configuration duties.
Related roles (2)
- Chaos Studio Operator: Adds start and cancel Actions while retaining experiment and execution-detail visibility.
- Chaos Studio Target Contributor: Adds target and capability onboarding without experiment creation or execution control.
Editorial sources (6)
- Azure built-in roles for DevOps - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Permissions and security in Azure Chaos Studio →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.