The following table lists all RightScale resources and actions that can be used in a policy template language permissions block. The table also lists the least-privileged RightScale role that provides the given privilege. Note that more powerful roles will generally grant privileges from less valuable roles. For example, actor will grant all observer privileges and admin will grant everything the actor and observer roles grant.

Resource Action Privilege Role
rs_cm.account_groups rs_cm.index cm:legacy:publisher publisher
rs_cm.account_groups rs_cm.show cm:legacy:publisher publisher
rs_cm.accounts rs_cm.show cm:legacy:observer observer
rs_cm.alert_specs rs_cm.create cm:legacy:designer designer
rs_cm.alert_specs rs_cm.destroy cm:legacy:designer designer
rs_cm.alert_specs rs_cm.index cm:legacy:observer observer
rs_cm.alert_specs rs_cm.show cm:legacy:observer observer
rs_cm.alert_specs rs_cm.update cm:legacy:designer designer
rs_cm.alerts rs_cm.destroy cm:legacy:actor actor
rs_cm.alerts rs_cm.disable cm:legacy:actor actor
rs_cm.alerts rs_cm.enable cm:legacy:actor actor
rs_cm.alerts rs_cm.index cm:legacy:observer observer
rs_cm.alerts rs_cm.quench cm:legacy:actor actor
rs_cm.alerts rs_cm.show cm:legacy:observer observer
rs_cm.audit_entries rs_cm.append cm:legacy:actor actor
rs_cm.audit_entries rs_cm.create cm:legacy:actor actor
rs_cm.audit_entries rs_cm.detail cm:legacy:observer observer
rs_cm.audit_entries rs_cm.index cm:legacy:observer observer
rs_cm.audit_entries rs_cm.show cm:legacy:observer observer
rs_cm.audit_entries rs_cm.update cm:legacy:actor actor
rs_cm.backups rs_cm.cleanup cm:legacy:actor actor
rs_cm.backups rs_cm.create cm:legacy:actor actor
rs_cm.backups rs_cm.destroy cm:legacy:actor actor
rs_cm.backups rs_cm.index cm:legacy:observer observer
rs_cm.backups rs_cm.restore cm:legacy:actor actor
rs_cm.backups rs_cm.show cm:legacy:observer observer
rs_cm.backups rs_cm.update cm:legacy:actor actor
rs_cm.child_accounts rs_cm.create cm:legacy:enterprise_manager enterprise_manager
rs_cm.child_accounts rs_cm.index cm:legacy:enterprise_manager enterprise_manager
rs_cm.child_accounts rs_cm.update cm:legacy:enterprise_manager enterprise_manager
rs_cm.cloud_accounts rs_cm.create cm:legacy:admin admin
rs_cm.cloud_accounts rs_cm.destroy cm:legacy:admin admin
rs_cm.cloud_accounts rs_cm.index cm:legacy:observer observer
rs_cm.cloud_accounts rs_cm.show cm:legacy:observer observer
rs_cm.cloud_accounts rs_cm.update cm:legacy:admin admin
rs_cm.clouds rs_cm.index cm:legacy:observer observer
rs_cm.clouds rs_cm.show cm:legacy:observer observer
rs_cm.cookbook_attachments rs_cm.create cm:legacy:designer designer
rs_cm.cookbook_attachments rs_cm.destroy cm:legacy:designer designer
rs_cm.cookbook_attachments rs_cm.index cm:legacy:observer observer
rs_cm.cookbook_attachments rs_cm.multi_attach cm:legacy:designer designer
rs_cm.cookbook_attachments rs_cm.multi_detach cm:legacy:designer designer
rs_cm.cookbook_attachments rs_cm.show cm:legacy:observer observer
rs_cm.cookbooks rs_cm.destroy cm:legacy:designer designer
rs_cm.cookbooks rs_cm.follow cm:legacy:designer designer
rs_cm.cookbooks rs_cm.freeze cm:legacy:designer designer
rs_cm.cookbooks rs_cm.index cm:legacy:observer observer
rs_cm.cookbooks rs_cm.obsolete cm:legacy:designer designer
rs_cm.cookbooks rs_cm.show cm:legacy:observer observer
rs_cm.credentials rs_cm.create cm:legacy:actor actor
rs_cm.credentials rs_cm.destroy cm:legacy:actor actor
rs_cm.credentials rs_cm.index cm:legacy:observer observer
rs_cm.credentials rs_cm.show cm:legacy:observer observer
rs_cm.credentials rs_cm.update cm:legacy:actor actor
rs_cm.credentials rs_cm.show_sensitive cm:legacy:credential_viewer OR cm:legacy:admin credential_viewer
rs_cm.credentials rs_cm.index_sensitive cm:legacy:credential_viewer OR cm:legacy:admin credential_viewer
rs_cm.datacenters rs_cm.index cm:legacy:observer observer
rs_cm.datacenters rs_cm.show cm:legacy:observer observer
rs_cm.deployments rs_cm.clone cm:legacy:actor actor
rs_cm.deployments rs_cm.create cm:legacy:actor actor
rs_cm.deployments rs_cm.destroy cm:legacy:actor actor
rs_cm.deployments rs_cm.index cm:legacy:observer observer
rs_cm.deployments rs_cm.lock cm:legacy:actor actor
rs_cm.deployments rs_cm.show cm:legacy:observer observer
rs_cm.deployments rs_cm.unlock cm:legacy:actor actor
rs_cm.deployments rs_cm.update cm:legacy:actor actor
rs_cm.deployments rs_cm.servers cm:legacy:observer observer
rs_cm.identity_providers rs_cm.index cm:legacy:admin admin
rs_cm.identity_providers rs_cm.show cm:legacy:admin admin
rs_cm.images rs_cm.index cm:legacy:observer observer
rs_cm.images rs_cm.show cm:legacy:observer observer
rs_cm.inputs rs_cm.index cm:legacy:observer observer
rs_cm.inputs rs_cm.multi_update cm:legacy:actor actor
rs_cm.instance_types rs_cm.index cm:legacy:observer observer
rs_cm.instance_types rs_cm.show cm:legacy:observer observer
rs_cm.instances rs_cm.create cm:legacy:actor actor
rs_cm.instances rs_cm.index cm:legacy:observer observer
rs_cm.instances rs_cm.launch cm:legacy:actor actor
rs_cm.instances rs_cm.lock cm:legacy:actor actor
rs_cm.instances rs_cm.multi_run_executable cm:legacy:actor actor
rs_cm.instances rs_cm.multi_terminate cm:legacy:actor actor
rs_cm.instances rs_cm.reboot cm:legacy:actor actor
rs_cm.instances rs_cm.run_executable cm:legacy:actor actor
rs_cm.instances rs_cm.show cm:legacy:observer observer
rs_cm.instances rs_cm.start cm:legacy:actor actor
rs_cm.instances rs_cm.stop cm:legacy:actor actor
rs_cm.instances rs_cm.terminate cm:legacy:actor actor
rs_cm.instances rs_cm.unlock cm:legacy:actor actor
rs_cm.instances rs_cm.update cm:legacy:actor actor
rs_cm.ip_address_bindings rs_cm.create cm:legacy:actor actor
rs_cm.ip_address_bindings rs_cm.destroy cm:legacy:actor actor
rs_cm.ip_address_bindings rs_cm.index cm:legacy:observer observer
rs_cm.ip_address_bindings rs_cm.show cm:legacy:observer observer
rs_cm.ip_addresses rs_cm.create cm:legacy:actor actor
rs_cm.ip_addresses rs_cm.destroy cm:legacy:actor actor
rs_cm.ip_addresses rs_cm.index cm:legacy:observer observer
rs_cm.ip_addresses rs_cm.show cm:legacy:observer observer
rs_cm.ip_addresses rs_cm.update cm:legacy:actor actor
rs_cm.monitoring_metrics rs_cm.data cm:legacy:observer observer
rs_cm.monitoring_metrics rs_cm.index cm:legacy:observer observer
rs_cm.monitoring_metrics rs_cm.show cm:legacy:observer observer
rs_cm.multi_cloud_image_matchers rs_cm.create cm:legacy:designer designer
rs_cm.multi_cloud_image_matchers rs_cm.destroy cm:legacy:designer designer
rs_cm.multi_cloud_image_matchers rs_cm.index cm:legacy:observer observer
rs_cm.multi_cloud_image_matchers rs_cm.rematch cm:legacy:designer designer
rs_cm.multi_cloud_image_matchers rs_cm.show cm:legacy:observer observer
rs_cm.multi_cloud_image_settings rs_cm.create cm:legacy:designer designer
rs_cm.multi_cloud_image_settings rs_cm.destroy cm:legacy:designer designer
rs_cm.multi_cloud_image_settings rs_cm.index cm:legacy:observer observer
rs_cm.multi_cloud_image_settings rs_cm.show cm:legacy:observer observer
rs_cm.multi_cloud_image_settings rs_cm.update cm:legacy:designer designer
rs_cm.multi_cloud_images rs_cm.clone cm:legacy:designer designer
rs_cm.multi_cloud_images rs_cm.commit cm:legacy:designer designer
rs_cm.multi_cloud_images rs_cm.create cm:legacy:designer designer
rs_cm.multi_cloud_images rs_cm.destroy cm:legacy:designer designer
rs_cm.multi_cloud_images rs_cm.index cm:legacy:observer observer
rs_cm.multi_cloud_images rs_cm.show cm:legacy:observer observer
rs_cm.multi_cloud_images rs_cm.update cm:legacy:designer designer
rs_cm.network_gateways rs_cm.create cm:legacy:security_manager security_manager
rs_cm.network_gateways rs_cm.destroy cm:legacy:security_manager security_manager
rs_cm.network_gateways rs_cm.index cm:legacy:observer observer
rs_cm.network_gateways rs_cm.show cm:legacy:observer observer
rs_cm.network_gateways rs_cm.update cm:legacy:security_manager security_manager
rs_cm.network_option_group_attachments rs_cm.create cm:legacy:security_manager security_manager
rs_cm.network_option_group_attachments rs_cm.destroy cm:legacy:security_manager security_manager
rs_cm.network_option_group_attachments rs_cm.index cm:legacy:observer observer
rs_cm.network_option_group_attachments rs_cm.show cm:legacy:observer observer
rs_cm.network_option_group_attachments rs_cm.update cm:legacy:security_manager security_manager
rs_cm.network_option_groups rs_cm.create cm:legacy:security_manager security_manager
rs_cm.network_option_groups rs_cm.destroy cm:legacy:security_manager security_manager
rs_cm.network_option_groups rs_cm.index cm:legacy:observer observer
rs_cm.network_option_groups rs_cm.show cm:legacy:observer observer
rs_cm.network_option_groups rs_cm.update cm:legacy:security_manager security_manager
rs_cm.networks rs_cm.create cm:legacy:security_manager security_manager
rs_cm.networks rs_cm.destroy cm:legacy:security_manager security_manager
rs_cm.networks rs_cm.index cm:legacy:observer observer
rs_cm.networks rs_cm.show cm:legacy:observer observer
rs_cm.networks rs_cm.update cm:legacy:security_manager security_manager
rs_cm.permissions rs_cm.create cm:legacy:admin admin
rs_cm.permissions rs_cm.destroy cm:legacy:admin admin
rs_cm.permissions rs_cm.index cm:legacy:admin admin
rs_cm.permissions rs_cm.show cm:legacy:admin admin
rs_cm.placement_groups rs_cm.create cm:legacy:actor actor
rs_cm.placement_groups rs_cm.destroy cm:legacy:actor actor
rs_cm.placement_groups rs_cm.index cm:legacy:observer observer
rs_cm.placement_groups rs_cm.show cm:legacy:observer observer
rs_cm.preferences rs_cm.destroy cm:legacy:observer observer
rs_cm.preferences rs_cm.index cm:legacy:observer observer
rs_cm.preferences rs_cm.show cm:legacy:observer observer
rs_cm.preferences rs_cm.update cm:legacy:observer observer
rs_cm.publication_lineages rs_cm.show cm:legacy:publisher publisher
rs_cm.publications rs_cm.import cm:legacy:designer designer
rs_cm.publications rs_cm.index cm:legacy:observer observer
rs_cm.publications rs_cm.show cm:legacy:observer observer
rs_cm.recurring_volume_attachments rs_cm.create cm:legacy:actor actor
rs_cm.recurring_volume_attachments rs_cm.destroy cm:legacy:actor actor
rs_cm.recurring_volume_attachments rs_cm.index cm:legacy:observer observer
rs_cm.recurring_volume_attachments rs_cm.show cm:legacy:observer observer
rs_cm.repositories rs_cm.cookbook_import cm:legacy:designer designer
rs_cm.repositories rs_cm.cookbook_import_preview cm:legacy:designer designer
rs_cm.repositories rs_cm.create cm:legacy:designer designer
rs_cm.repositories rs_cm.destroy cm:legacy:designer designer
rs_cm.repositories rs_cm.index cm:legacy:observer observer
rs_cm.repositories rs_cm.refetch cm:legacy:designer designer
rs_cm.repositories rs_cm.resolve cm:legacy:observer observer
rs_cm.repositories rs_cm.show cm:legacy:observer observer
rs_cm.repositories rs_cm.update cm:legacy:designer designer
rs_cm.repository_assets rs_cm.index cm:legacy:observer observer
rs_cm.repository_assets rs_cm.show cm:legacy:observer observer
rs_cm.resource_groups rs_cm.create cm:legacy:actor actor
rs_cm.resource_groups rs_cm.destroy cm:legacy:actor actor
rs_cm.resource_groups rs_cm.index cm:legacy:observer observer
rs_cm.resource_groups rs_cm.show cm:legacy:observer observer
rs_cm.resource_groups rs_cm.update cm:legacy:actor actor
rs_cm.right_script_attachments rs_cm.create cm:legacy:designer designer
rs_cm.right_script_attachments rs_cm.destroy cm:legacy:designer designer
rs_cm.right_script_attachments rs_cm.index cm:legacy:observer observer
rs_cm.right_script_attachments rs_cm.show cm:legacy:observer observer
rs_cm.right_script_attachments rs_cm.update cm:legacy:designer designer
rs_cm.right_scripts rs_cm.commit cm:legacy:designer designer
rs_cm.right_scripts rs_cm.create cm:legacy:designer designer
rs_cm.right_scripts rs_cm.destroy cm:legacy:designer designer
rs_cm.right_scripts rs_cm.index cm:legacy:observer observer
rs_cm.right_scripts rs_cm.show cm:legacy:observer observer
rs_cm.right_scripts rs_cm.show_source cm:legacy:observer observer
rs_cm.right_scripts rs_cm.update cm:legacy:designer designer
rs_cm.right_scripts rs_cm.update_source cm:legacy:designer designer
rs_cm.route_tables rs_cm.create cm:legacy:security_manager security_manager
rs_cm.route_tables rs_cm.destroy cm:legacy:security_manager security_manager
rs_cm.route_tables rs_cm.index cm:legacy:observer observer
rs_cm.route_tables rs_cm.show cm:legacy:observer observer
rs_cm.route_tables rs_cm.update cm:legacy:security_manager security_manager
rs_cm.routes rs_cm.create cm:legacy:security_manager security_manager
rs_cm.routes rs_cm.destroy cm:legacy:security_manager security_manager
rs_cm.routes rs_cm.index cm:legacy:observer observer
rs_cm.routes rs_cm.show cm:legacy:observer observer
rs_cm.routes rs_cm.update cm:legacy:security_manager security_manager
rs_cm.runnable_bindings rs_cm.create cm:legacy:designer designer
rs_cm.runnable_bindings rs_cm.destroy cm:legacy:designer designer
rs_cm.runnable_bindings rs_cm.index cm:legacy:observer observer
rs_cm.runnable_bindings rs_cm.multi_update cm:legacy:designer designer
rs_cm.runnable_bindings rs_cm.show cm:legacy:observer observer
rs_cm.security_group_rules rs_cm.create cm:legacy:security_manager security_manager
rs_cm.security_group_rules rs_cm.destroy cm:legacy:security_manager security_manager
rs_cm.security_group_rules rs_cm.index cm:legacy:observer observer
rs_cm.security_group_rules rs_cm.show cm:legacy:observer observer
rs_cm.security_group_rules rs_cm.update cm:legacy:security_manager security_manager
rs_cm.security_groups rs_cm.create cm:legacy:security_manager security_manager
rs_cm.security_groups rs_cm.destroy cm:legacy:security_manager security_manager
rs_cm.security_groups rs_cm.index cm:legacy:observer observer
rs_cm.security_groups rs_cm.show cm:legacy:observer observer
rs_cm.server_arrays rs_cm.clone cm:legacy:actor actor
rs_cm.server_arrays rs_cm.create cm:legacy:actor actor
rs_cm.server_arrays rs_cm.destroy cm:legacy:actor actor
rs_cm.server_arrays rs_cm.disable_runnable_bindings cm:legacy:actor actor
rs_cm.server_arrays rs_cm.enable_runnable_bindings cm:legacy:actor actor
rs_cm.server_arrays rs_cm.index cm:legacy:observer observer
rs_cm.server_arrays rs_cm.monitor cm:legacy:actor actor
rs_cm.server_arrays rs_cm.scale_down cm:legacy:actor actor
rs_cm.server_arrays rs_cm.scale_up cm:legacy:actor actor
rs_cm.server_arrays rs_cm.show cm:legacy:observer observer
rs_cm.server_arrays rs_cm.update cm:legacy:actor actor
rs_cm.server_arrays rs_cm.current_instances cm:legacy:observer observer
rs_cm.server_arrays rs_cm.launch cm:legacy:actor actor
rs_cm.server_arrays rs_cm.multi_terminate cm:legacy:actor actor
rs_cm.server_arrays rs_cm.multi_run_executable cm:legacy:actor actor
rs_cm.server_template_multi_cloud_images rs_cm.create cm:legacy:designer designer
rs_cm.server_template_multi_cloud_images rs_cm.destroy cm:legacy:designer designer
rs_cm.server_template_multi_cloud_images rs_cm.index cm:legacy:observer observer
rs_cm.server_template_multi_cloud_images rs_cm.make_default cm:legacy:designer designer
rs_cm.server_template_multi_cloud_images rs_cm.show cm:legacy:observer observer
rs_cm.server_templates rs_cm.clone cm:legacy:designer designer
rs_cm.server_templates rs_cm.commit cm:legacy:designer designer
rs_cm.server_templates rs_cm.create cm:legacy:designer designer
rs_cm.server_templates rs_cm.destroy cm:legacy:designer designer
rs_cm.server_templates rs_cm.detect_changes_in_head cm:legacy:observer observer
rs_cm.server_templates rs_cm.index cm:legacy:observer observer
rs_cm.server_templates rs_cm.publish cm:legacy:publisher publisher
rs_cm.server_templates rs_cm.resolve cm:legacy:observer observer
rs_cm.server_templates rs_cm.show cm:legacy:observer observer
rs_cm.server_templates rs_cm.swap_repository cm:legacy:designer designer
rs_cm.server_templates rs_cm.update cm:legacy:designer designer
rs_cm.servers rs_cm.clone cm:legacy:actor actor
rs_cm.servers rs_cm.create cm:legacy:actor actor
rs_cm.servers rs_cm.destroy cm:legacy:actor actor
rs_cm.servers rs_cm.disable_runnable_bindings cm:legacy:actor actor
rs_cm.servers rs_cm.enable_runnable_bindings cm:legacy:actor actor
rs_cm.servers rs_cm.index cm:legacy:observer observer
rs_cm.servers rs_cm.show cm:legacy:observer observer
rs_cm.servers rs_cm.unwrap cm:legacy:actor actor
rs_cm.servers rs_cm.update cm:legacy:actor actor
rs_cm.servers rs_cm.wrap_instance cm:legacy:actor actor
rs_cm.servers rs_cm.launch cm:legacy:actor actor
rs_cm.servers rs_cm.terminate cm:legacy:actor actor
rs_cm.sessions rs_cm.index cm:legacy:observer observer
rs_cm.ssh_keys rs_cm.create cm:legacy:actor actor
rs_cm.ssh_keys rs_cm.destroy cm:legacy:actor actor
rs_cm.ssh_keys rs_cm.index cm:legacy:observer observer
rs_cm.ssh_keys rs_cm.show cm:legacy:observer observer
rs_cm.ssh_keys rs_cm.show_sensitive cm:legacy:credential_viewer OR cm:legacy:admin credential_viewer
rs_cm.ssh_keys rs_cm.index_sensitive cm:legacy:credential_viewer OR cm:legacy:admin credential_viewer
rs_cm.subnets rs_cm.create cm:legacy:security_manager security_manager
rs_cm.subnets rs_cm.destroy cm:legacy:security_manager security_manager
rs_cm.subnets rs_cm.index cm:legacy:observer observer
rs_cm.subnets rs_cm.show cm:legacy:observer observer
rs_cm.subnets rs_cm.update cm:legacy:security_manager security_manager
rs_cm.tags rs_cm.by_resource cm:legacy:observer observer
rs_cm.tags rs_cm.by_tag cm:legacy:observer observer
rs_cm.tags rs_cm.multi_add cm:legacy:actor actor
rs_cm.tags rs_cm.multi_delete cm:legacy:actor actor
rs_cm.tasks rs_cm.show cm:legacy:observer observer
rs_cm.user_datas rs_cm.show cm:legacy:observer observer
rs_cm.users rs_cm.create cm:legacy:admin OR cm:legacy:enterprise_manager admin
rs_cm.users rs_cm.index cm:legacy:observer observer
rs_cm.users rs_cm.show cm:legacy:observer observer
rs_cm.users rs_cm.update cm:legacy:observer observer
rs_cm.volume_attachments rs_cm.create cm:legacy:actor actor
rs_cm.volume_attachments rs_cm.destroy cm:legacy:actor actor
rs_cm.volume_attachments rs_cm.index cm:legacy:observer observer
rs_cm.volume_attachments rs_cm.show cm:legacy:observer observer
rs_cm.volume_snapshots rs_cm.copy cm:legacy:actor actor
rs_cm.volume_snapshots rs_cm.create cm:legacy:actor actor
rs_cm.volume_snapshots rs_cm.destroy cm:legacy:actor actor
rs_cm.volume_snapshots rs_cm.index cm:legacy:observer observer
rs_cm.volume_snapshots rs_cm.show cm:legacy:observer observer
rs_cm.volume_types rs_cm.index cm:legacy:observer observer
rs_cm.volume_types rs_cm.show cm:legacy:observer observer
rs_cm.volumes rs_cm.create cm:legacy:actor actor
rs_cm.volumes rs_cm.destroy cm:legacy:actor actor
rs_cm.volumes rs_cm.index cm:legacy:observer observer
rs_cm.volumes rs_cm.show cm:legacy:observer observer
rs_cm.volumes rs_cm.update cm:legacy:actor actor
rs_optima.allocation_table rs_optima.show optima:billing_center:show billing_center_viewer (org scope only)
rs_optima.allocation_table rs_optima.upsert optima:billing_center:update billing_center_admin (org scope only)
rs_optima.aws_reserved_instances rs_optima.index ca:legacy:user ca_user (org scope only)
rs_optima.recommendation_rules rs_optima.index optima:recommendation:index billing_center_viewer (org scope only)
rs_optima.recommendation_rules rs_optima.show optima:recommendation:show billing_center_viewer (org scope only)
rs_optima.recommendations rs_optima.index optima:recommendation:index billing_center_viewer (org scope only)
rs_optima.recommendations rs_optima.show optima:recommendation:show billing_center_viewer (org scope only)
rs_optima.recommendations rs_optima.resolve optima:recommendation:update billing_center_admin (org scope only)
rs_optima.recommendations rs_optima.unresolve optima:recommendation:update billing_center_admin (org scope only)