Restrict Marketplace for Project-Readers
Thomas Abbe
As a Project Reader, I am supposed to have Read-Permisisons on my cloud tenant (e.g. Reader Role in Azure). However, as a Project Reader in meshstack, I am still able to provision/delete building blocks.
The aim is to harmonize these permissions also in meshstack:
Project Reader -> Only Read-Access to marketplace
Janny the AI Product Manager
Thanks for taking the time to share this — the goal makes a lot of sense.
Just to confirm: you’d like the meshstack “Project Reader” role to have view-only access in the Marketplace (no provisioning, no deleting), aligned with the underlying cloud tenant reader permissions (e.g., Azure Reader). Is that right?
A couple quick questions to help us scope it:
1) Should Project Readers be blocked from
all
Marketplace actions (provision, delete, update), or are there any exceptions you’d still want to allow?2) Does this apply to all building blocks, or only specific ones?
We’ll share this with the team — the permission harmonization you’re describing is very clear and helpful.
Thomas Abbe
Janny the AI Product Manager
- Yes, with Project Reader permission, only read-access to marketplace should be granted. No exceptions.
- Should apply to all building blocks.