HasRole
Principal is directly granted a role (Entra role, GCP role binding, IAM role attachment).
Identity
── HasRole ──▸
Role
Derivation
| nature | explicit |
|---|
Rules that emit HasRole 6
azureexplicit
A principal is assigned the Purview Data Reader role within a Purview account. This assignment is visible via the Purview REST API policyElements endpoint and materializes an explicit HasRole edge (Identity -> Role). The principal can read catalog assets, classifications, and scan results (data-plane access).
azureexplicit
A principal is assigned the Purview Data Curator role within a Purview account. Data Curator allows read and write access to catalog assets, classifications, and glossary terms (data-plane write access).
azureexplicit
A principal is assigned the Purview Collection Admin role within a Purview account. Collection Admin allows managing collections and assigning Purview RBAC roles to other principals within the account (data-plane administrative capability).
azureexplicit
A principal is assigned the Purview Data Source Administrator role. Data Source Admin manages scan credentials, data sources, and integration runtimes (data-plane operational capability, includes write permissions).
azureexplicit
An identity with ARM Contributor or Owner permission on a Microsoft.Purview/accounts resource is automatically granted the Purview Root Collection Admin role within the account at creation. This is an ARM control-plane to Purview data-plane escalation: ARM admin authority over the account resource carries over to data-plane administrative capability. Per Microsoft documentation, the account creator is assigned Root Collection Admin in Purview, enabling role assignment and privilege escalation within the Purview scope.
azureexplicit