Azure Management and governance built-in role
SRE Agent Reader
Provides read-only access to Azure SRE Agent threads, incidents, logs, custom agents, knowledge, connectors, response plans, managed resources, and settings. It does not permit chat, action requests, approvals, configuration changes, or interaction with Azure resources through the agent.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: a4b156ac-253f-4a1a-9851-96d62b71b047
Control-plane actions (3)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.App/agents/read
Data-plane actions (4)
Microsoft.App/agents/threads/readMicrosoft.App/agents/graph/readMicrosoft.App/agents/memory/readMicrosoft.App/agents/incidentManagement/read
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the SRE Agent resource. The role governs a user's view of agent data and is independent from Azure resource roles assigned to the agent's managed identity.
Common use cases (2)
- Give auditors, compliance teams, or stakeholders visibility into agent conversations, incidents, logs, plans, and configuration.
- Review agent activity and operational evidence without interacting with or modifying the agent.
Prerequisites (2)
- An SRE Agent must exist and the principal must be authorized to see its operational data.
- Use Standard User when the principal must chat or run diagnostics.
Best practices (2)
- Assign on individual agent resources and review access because chats and logs can contain sensitive incident data.
- Do not grant agent-managed-identity resource roles to a human merely because the human can view the agent.
Security considerations (2)
- Read access can expose incidents, logs, chat content, knowledge sources, connectors, and infrastructure configuration.
- The role cannot interact with the agent or authorize resource actions, and it does not inherit the managed identity's Azure access.
Assignment guidance
Assign to auditors and stakeholders at the agent resource. Use Standard User for responders who must interact and Administrator only for approval and configuration duties.
Related roles (2)
- SRE Agent Standard User: Adds chat, diagnostics, document upload, and action requests.
- SRE Agent Administrator: Adds approvals, configuration, managed-resource, and destructive administration.
Editorial sources (6)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- User roles and permissions in Azure SRE Agent →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Agent permissions in Azure SRE Agent →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.