Connect your clouds
Check permissions
Check which Zaysa features your cloud connection can use and how to fix missing access.
About 3 minutes
What it does
Check permissions asks your cloud what this connection may do for features in the permissions catalogue. The check uses permission questions, reads, and dry runs. It makes no change to your cloud. Each click asks again; results are not cached. You can check an account once every 10 seconds.
Open the check
On the Cloud accounts card, click Check permissions (1).
In Cost Optimizer, open the account's ⋮ menu and click Check permissions (1).
On a Kubernetes cluster's page, click Check permissions at the top right (1).
For a cluster, the window asks the cluster itself. A cluster connected through a connector shows Kubernetes visibility as included; team access and CI/CD are checked separately.
Read the window
The line at the top tells you if everything in your setup works. In this AWS example: All 4 included features are ready.
- Included in your setup: what the normal connection setup grants. These should all be Ready.
- Optional: turn on to use: features that need an extra grant, because they change things in your cloud, use another identity, or (like Resource Explorer) are not in the default setup. Missing here is normal until you want that feature.
- Read only or Changes things says what the feature does. The check itself never changes anything.
Click a row to open its details.
| Status | Meaning | What to do |
|---|---|---|
| Ready | The check found the listed permissions available. | Continue with the feature. |
| Missing | The check found a missing permission. | Open the row for the missing action and any fix. |
| Not checked here | This check cannot safely confirm it, or the feature uses another identity. | Read the note and follow its check link if shown. |
| Could not check | The provider or connection did not give a usable answer. | Open the row for the error, then check the connection and try again. |
Fix a missing permission
Open the Missing row to see why the feature needs access, what happens without it, and the exact missing action. If Zaysa shows a command, click Copy (1), run it in your cloud shell, then click Check again.
The command uses this connection's AWS role or user, Google Cloud project and principal, or Azure subscription and app. If a required value or verified role is unknown, Zaysa says what it needs instead of showing a command. Grant permissions for a feature that changes resources only if you want to use that feature.
Run AWS commands in AWS CloudShell, Google Cloud commands in Google Cloud Shell, and Azure commands in Azure Cloud Shell. DigitalOcean cannot report token write scopes without making a change. For a write feature, create a Full Access token and update the connection.
Checks for separate identities
CI/CD and Beam are marked Not checked here because their readiness is checked separately. Follow Open that check → to CI/CD readiness or Beam › Connections › Check readiness. On Google Cloud, Beam uses the deploy service account, and its row still opens Beam readiness.
How each cloud is checked
| Cloud | How Zaysa checks |
|---|---|
| AWS | Simulates the connected role or user policy. If simulation is unavailable, it requests up to one CloudTrail event, makes at most one Cost Explorer read, and tries EC2 StopInstances with DryRun. Other actions remain unverified. |
| Google Cloud | Asks testIamPermissions about the connected project using the connection token. A project number is looked up to get its project ID. |
| Azure | Reads the connected app’s permissions on its subscription. Microsoft Graph app permissions are separate and cannot be inferred from that answer. |
| DigitalOcean | Reads the account, one droplet page, and one actions page. Its API cannot report token write scopes without a write, so those stay unverified. |
| Kubernetes | Asks the cluster SelfSubjectAccessReview API whether the credentials used for this check can perform each listed verb. These are authorization questions, not changes to resources. |
Next steps
For the exact roles behind each feature, open the Permissions reference.