Azure DevOps built-in role

Playwright Workspace Reader

Views Playwright workspace resources and test results without changing the workspace, creating or deleting access tokens, or running tests. The published definition contains control-plane read Actions only and no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 19d36063-d00b-4ea5-a1ac-a7c4926a0b78

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the Playwright workspace. Resource-group or subscription assignments are inherited by every workspace below them and broaden both workspace and test-result visibility.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Playwright Workspace Reader directly on the workspace to result consumers and reviewers. Keep access-token authentication disabled for reader-only use and elevate to Contributor only for approved quota, assignee access-token, or test-run operations, not for workspace writes.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →