Azure AI + machine learning built-in role
Cognitive Services Custom Vision Labeler
For a supported existing Custom Vision workload, views projects and changes only training images, image regions, tags, and suggested labels. Resource reads are control-plane Actions; the labeling workflow uses Custom Vision DataActions. Custom Vision is supported for existing customers only until its retirement on 2028-09-25; service calls fail after that date.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 88424f51-ebe7-446f-bc41-7fa16989e96c
Control-plane actions (1)
Microsoft.CognitiveServices/*/read
Data-plane actions (6)
Microsoft.CognitiveServices/accounts/CustomVision/*/readMicrosoft.CognitiveServices/accounts/CustomVision/projects/predictions/query/actionMicrosoft.CognitiveServices/accounts/CustomVision/projects/images/*Microsoft.CognitiveServices/accounts/CustomVision/projects/tags/*Microsoft.CognitiveServices/accounts/CustomVision/projects/images/suggested/*Microsoft.CognitiveServices/accounts/CustomVision/projects/tagsandregions/suggestions/action
Excluded actions (1)
Microsoft.CognitiveServices/accounts/CustomVision/projects/export/read
Assignable scopes (1)
/
Practical scope
For an existing workload or migration only, assign on the Custom Vision training resource containing the approved labeling project. Parent-scope assignments are inherited and extend image and tag access across every contained Custom Vision resource.
Common use cases (2)
- Correct or complete labels needed to sustain an existing model while migration is in progress.
- Review annotations and export-ready dataset quality before moving training data to a documented alternative.
Prerequisites (2)
- A supported existing project and migration plan must exist, and its owner or trainer must define the labeling instructions and tag taxonomy.
- The labeler must be authorized to view and handle the training images assigned to the project.
Best practices (4)
- Microsoft directs customers to make a transition plan by 2026-09-25 and complete migration before retirement.
- Do not start a net-new Custom Vision workload; evaluate Azure Machine Learning AutoML, Foundry models, or Azure Content Understanding (preview) as documented alternatives.
- Use the Labeler role for annotation staff instead of Trainer or Contributor.
- Remove access when the labeling engagement ends and review exported or downloaded training data handling separately.
Security considerations (3)
- The role exposes training images and prediction images returned by its documented query operation and can change or delete image annotations and tags.
- It cannot train, publish, or delete the project, limiting model lifecycle authority.
- Migration exports and parent-scope assignments can expose training content beyond the intended project boundary.
Assignment guidance
For a supported existing workload or migration only, assign Custom Vision Labeler on the specific training resource to users or groups that maintain or prepare its labeled data for transition. Do not start a net-new Custom Vision workload; evaluate Azure Machine Learning AutoML, Foundry models, or Azure Content Understanding (preview) as documented alternatives.
Related roles (2)
- Cognitive Services Custom Vision Trainer: Adds project editing, training, publishing, and model export beyond image and tag labeling.
- Cognitive Services Custom Vision Reader: View-only alternative for reviewers who should not change images or tags.
Editorial sources (6)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure role-based access control - Custom Vision - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Migrate from Custom Vision Service - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.