Azure DevOps built-in role

Chaos Studio Reader

Views Chaos Studio targets, capabilities, experiments, and experiment execution details. The role contains control-plane Actions only and no DataActions, and it cannot start, cancel, create, update, or delete experiments.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 29e2da8a-229c-4157-8ae8-cc72fc506b74

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on an individual experiment, target resource, or a bounded resource group according to the resources the reviewer must inspect. Parent-scope assignments expose every inherited Chaos Studio resource.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Chaos Studio Reader at the experiment, target, or dedicated resource-group scope to reviewers and service owners who only need visibility. Use Operator only for approved run control and use Target or Experiment Contributor only for configuration duties.

Related roles (2)

Common questions

When should I assign the Chaos Studio Reader Azure role?

Assign Chaos Studio Reader when you need to: Review experiment definitions, target onboarding, capabilities, execution status, and per-action errors for an audit or post-exercise review.; and Give service owners visibility into planned or completed chaos exercises without fault-injection authority.. Practical scope: Assign on an individual experiment, target resource, or a bounded resource group according to the resources the reviewer must inspect. Parent-scope assignments expose every inherited Chaos Studio resource.

What permissions does the Chaos Studio Reader Azure role grant?

The role definition grants 6 combined control-plane and data-plane actions. Representative operations include: Microsoft.Chaos/*/read; Microsoft.Chaos/experiments/executions/getExecutionDetails/action; Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.Resources/deployments/*; and Microsoft.Resources/subscriptions/resourceGroups/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Chaos Studio Reader Azure role?

Key considerations when assigning Chaos Studio Reader: Execution details can reveal fault status, errors, target configuration, and other operational context even though the role cannot inject faults.; A parent-scope assignment exposes Chaos Studio metadata for every inherited experiment and target.; and The role does not grant access to the target resource data plane or permission to execute the target fault itself.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →