Project permissions
This page explains which permissions let you view, create, or change a project and its rules, and what you see in AIO when you don't have them.
AIO controls access project by project. Your permissions decide which projects appear in your project list, whose traces you can explore, and whether you can add or change rules. Knowing what each permission allows helps you understand why a button or tab is missing, and what to ask your administrator for.
Permissions at a glance
Three kinds of access apply to projects and their rules. The following table shows what each one allows.
Access | What it allows |
| See the project in the project list, open it, query its telemetry, and view its rules. |
| Change the project's settings, and create, edit, enable, disable, or delete its rules. |
Resource admin | Reach every project in the tenant. Only resource admins can create or delete projects. |
You get view:aioProject and modify:aioProject through resource groups. A user who isn't a resource admin can reach exactly the projects in the resource groups that grant them a permission. If a project belongs to several groups, you have a permission on it when any of those groups grants it. For how projects are grouped, see Resource groups.
Important
A project that belongs to no resource group is reachable only by resource admins. A new project starts out in no group, so other users can't see it until it's added to a resource group.
AIO checks your permissions on every request. When your grants or a group's projects change, the change applies the next time you load a page.
How it works
Each screen shows or hides controls based on your permissions. The following sections walk through what you see on each screen.
See your projects
The Projects page lists only the projects you can view. A resource admin sees every project in the tenant. Everyone else sees the projects in groups that grant them view:aioProject.
If you can't view any project, the list is empty rather than showing an error, and the page shows the No projects yet empty state. Telemetry panels show their normal empty state too.
Create a project
Only resource admins see Create new project, in the toolbar and in the empty state. Everyone else doesn't see it. If you open the create page directly without being a resource admin, AIO returns you to the Projects page.
For the steps, see Create a project.
Change or delete a project
To change a project's settings, you need modify:aioProject on that project, or you need to be a resource admin. Only resource admins can delete a project.
View rules
The Rules tab on a project appears only when you can view that project. To open the Rules page, you need to be a resource admin or able to view at least one project. Otherwise, AIO returns you to the Projects page. If you open a project's rules without view access to that project, AIO returns you to the project's page.
The rule list holds only rules whose project you can view. In the Status column, the enable switch appears only for rules in projects you can modify. Other rows show the status as "on" or "off" text.
Create a rule
+ New rule appears in the toolbar and in the empty state only if you can modify the current project. With no project chosen, it appears if you can modify any project, or you're a resource admin. If you open the new-rule page directly without modify access to any project, AIO returns you to the Rules page.
On the Configure rule page, the project picker lists every project you can view, not only the ones you can modify. To save the rule, you need modify:aioProject on the project you pick.
For the steps, see Create a rule.
Edit, enable, or delete a rule
To open a rule, you need view access to its project. To change it, you need modify:aioProject on its project. Without modify access, the Edit rule page is read-only:
- Back to rules appears instead of Discard.
- Save changes is hidden.
- The Danger zone section, with Disable or Enable and Delete rule…, is hidden.
- The Severity, Sampling, and parameter fields still appear, but you can't save changes to them.
Troubleshooting
- Requests fail when the permission check is unavailable. If AIO can't check your permissions, it denies the request with an HTTP 503 error instead of granting broader access. Try again later.
- A rule list or rule doesn't load. The page shows an error such as "Rules did not load — the server returned 403." Select Retry after your administrator grants you access to the project.

Have a suggestion?