Azure Management and governance built-in role

SRE Agent Reader

Provides read-only access to Azure SRE Agent threads, incidents, logs, custom agents, knowledge, connectors, response plans, managed resources, and settings. It does not permit chat, action requests, approvals, configuration changes, or interaction with Azure resources through the agent.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a4b156ac-253f-4a1a-9851-96d62b71b047

Control-plane actions (3)

Data-plane actions (4)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the SRE Agent resource. The role governs a user's view of agent data and is independent from Azure resource roles assigned to the agent's managed identity.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to auditors and stakeholders at the agent resource. Use Standard User for responders who must interact and Administrator only for approval and configuration duties.

Related roles (2)

Common questions

When should I assign the SRE Agent Reader Azure role?

Assign SRE Agent Reader when you need to: Give auditors, compliance teams, or stakeholders visibility into agent conversations, incidents, logs, plans, and configuration.; and Review agent activity and operational evidence without interacting with or modifying the agent.. Practical scope: Assign on the SRE Agent resource. The role governs a user's view of agent data and is independent from Azure resource roles assigned to the agent's managed identity.

What permissions does the SRE Agent Reader Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.App/agents/read; Microsoft.App/agents/threads/read; Microsoft.App/agents/graph/read; and Microsoft.App/agents/memory/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the SRE Agent Reader Azure role?

Key considerations when assigning SRE Agent Reader: Read access can expose incidents, logs, chat content, knowledge sources, connectors, and infrastructure configuration.; and The role cannot interact with the agent or authorize resource actions, and it does not inherit the managed identity's Azure access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →