Azure DevOps built-in role

Chaos Studio Target Contributor

Creates, reads, updates, and deletes Chaos Studio target and capability resources but cannot create or run experiments or view their execution details. The role has control-plane Actions only and no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 59a618e3-3c9a-406e-9f03-1a20dd1c55f1

Control-plane actions (12)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure resource being onboarded as a Chaos Studio target or on a tightly bounded resource group containing approved targets. Each target is unique to a resource, and parent-scope assignments cover every inherited target and capability.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Chaos Studio Target Contributor directly on approved target resources to the platform team responsible for onboarding. Grant experiment execution separately and give the experiment managed identity only the fault-specific permissions it needs on each target.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →