Azure DevOps built-in role

Playwright Workspace Owner

Performs all published Playwright workspace resource, quota, access-token, and test-run operations. The role uses control-plane Actions only and has no DataActions; the published machine definition does not include Microsoft.Authorization/roleAssignments/write.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 45265627-32f7-4da4-9ab0-b1cb0e9ec70b

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the Playwright workspace unless the same trusted platform owner manages every inherited workspace. A parent-scope assignment broadens workspace lifecycle, token, quota, and test-run authority.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Playwright Workspace Owner directly on one workspace only to the platform owner responsible for its lifecycle. Use Contributor for workspace reads, quota operations, the assignee's access-token operations, and test execution without workspace write; use Reader for results, and a separate access-administration role when Azure role assignments must be created.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →