INS 8.4 Understand permission names
The permission set is exactly 4 actions across 19 resources, 76 in total. Verified from the Create New Role checkbox list.
Actions: create, delete, update, view.
Resources: acoustic_metrics, billing, call_overview, call_sentiment_timeline, call_transcript, key_moments, permissions, phases, plan_pricing, plans, quality_categories, request_metadata, role_permissions, roles, rsa_keys, system_settings, telcos, tenants, users.
Permissions follow an action_resource naming pattern.
The four actions: create, delete, update, view.
The resources: acoustic_metrics, billing, call_overview, call_sentiment_timeline, call_transcript, key_moments, permissions, phases, plan_pricing, plans, quality_categories, request_metadata, role_permissions, roles, rsa_keys, system_settings, telcos, tenants, users.
So view_call_transcript grants reading a transcript, and update_roles grants changing a role definition.
Four resources are effectively administrative. permissions, role_permissions, roles and users let a holder change who can do what, including their own access. rsa_keys, system_settings and tenants reach platform configuration. Keep all of them out of every role except your administrators.
Grant view before create, update or delete. A role that can update a resource it cannot view is a role that changes things blind.