Azure Databases built-in role

Semantic Reranker User

Runs Semantic Reranker queries against a registered inference account. It reads the inference account in the control plane and invokes the reranker through a DataAction, but cannot create, update, delete, enable, or disable the inference account.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 6c74a7c5-4a87-40f9-bb03-61e49aecbc78

Control-plane actions (1)

Data-plane actions (1)

Excluded actions (2)

Assignable scopes (1)

Practical scope

Assign on the Azure Cosmos DB account whose Semantic Reranker runtime the identity calls. A resource-group assignment is inherited by every eligible account in that group. This role authorizes reranker invocation only; Cosmos DB item reads use separate native data-plane permissions.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Semantic Reranker User to the runtime caller on the individual Azure Cosmos DB account. Add a separate Cosmos DB Built-in Data Reader or narrower native role for source-item reads, and reserve Inference Account Operator or Owner for principals that enable or administer the feature.

Related roles (3)

Editorial sources (5)

Official Microsoft Learn documentation →