strazactl roles create
Create a role
On this page
strazactl roles create <name> [flags]
Options
--app string the MCP server that owns this role, by name. The role is named after that server, reaches it alone and is removed with it
--description string role description
--kind string role kind, required unless --app: application is matched by policy sets and reaches an MCP server's tools only with --app, business bundles application roles for a job, approver decides approval requests and is the only kind a policy may name in approve.roles besides straza-admin, straza carries capabilities in Straza itself, the control plane. Approver and straza roles never hold tools
--tools strings the tools this role reaches on the owning server, comma-separated and named one at a time, or * for every tool, which only a global admin may give. Required with --app
Options inherited from parent commands
--server string strazad base URL (overrides $STRAZA_SERVER and the server you logged into)
See also
- strazactl roles: Manage roles