Connect your clouds

Check permissions

Check which Zaysa features your cloud connection can use and how to fix missing access.

About 3 minutes

What it does

Check permissions asks your cloud what this connection may do for features in the permissions catalogue. The check uses permission questions, reads, and dry runs. It makes no change to your cloud. Each click asks again; results are not cached. You can check an account once every 10 seconds.

Open the check

On the Cloud accounts card, click Check permissions (1).

In Cost Optimizer, open the account's ⋮ menu and click Check permissions (1).

On a Kubernetes cluster's page, click Check permissions at the top right (1).

For a cluster, the window asks the cluster itself. A cluster connected through a connector shows Kubernetes visibility as included; team access and CI/CD are checked separately.

Read the window

The line at the top tells you if everything in your setup works. In this AWS example: All 4 included features are ready.

  • Included in your setup: what the normal connection setup grants. These should all be Ready.
  • Optional: turn on to use: features that need an extra grant, because they change things in your cloud, use another identity, or (like Resource Explorer) are not in the default setup. Missing here is normal until you want that feature.
  • Read only or Changes things says what the feature does. The check itself never changes anything.

Click a row to open its details.

StatusMeaningWhat to do
ReadyThe check found the listed permissions available.Continue with the feature.
MissingThe check found a missing permission.Open the row for the missing action and any fix.
Not checked hereThis check cannot safely confirm it, or the feature uses another identity.Read the note and follow its check link if shown.
Could not checkThe provider or connection did not give a usable answer.Open the row for the error, then check the connection and try again.

Fix a missing permission

Open the Missing row to see why the feature needs access, what happens without it, and the exact missing action. If Zaysa shows a command, click Copy (1), run it in your cloud shell, then click Check again.

The command uses this connection's AWS role or user, Google Cloud project and principal, or Azure subscription and app. If a required value or verified role is unknown, Zaysa says what it needs instead of showing a command. Grant permissions for a feature that changes resources only if you want to use that feature.

Run AWS commands in AWS CloudShell, Google Cloud commands in Google Cloud Shell, and Azure commands in Azure Cloud Shell. DigitalOcean cannot report token write scopes without making a change. For a write feature, create a Full Access token and update the connection.

Checks for separate identities

CI/CD and Beam are marked Not checked here because their readiness is checked separately. Follow Open that check → to CI/CD readiness or Beam › Connections › Check readiness. On Google Cloud, Beam uses the deploy service account, and its row still opens Beam readiness.

How each cloud is checked

CloudHow Zaysa checks
AWSSimulates the connected role or user policy. If simulation is unavailable, it requests up to one CloudTrail event, makes at most one Cost Explorer read, and tries EC2 StopInstances with DryRun. Other actions remain unverified.
Google CloudAsks testIamPermissions about the connected project using the connection token. A project number is looked up to get its project ID.
AzureReads the connected app’s permissions on its subscription. Microsoft Graph app permissions are separate and cannot be inferred from that answer.
DigitalOceanReads the account, one droplet page, and one actions page. Its API cannot report token write scopes without a write, so those stay unverified.
KubernetesAsks the cluster SelfSubjectAccessReview API whether the credentials used for this check can perform each listed verb. These are authorization questions, not changes to resources.

Next steps

For the exact roles behind each feature, open the Permissions reference.