@@ -307,7 +307,8 @@ func ReloadBuiltinRoles(opts *RoleOptions) {
307
307
Identifier : RoleAuditor (),
308
308
DisplayName : "Auditor" ,
309
309
Site : Permissions (map [string ][]policy.Action {
310
- ResourceAuditLog .Type : {policy .ActionRead },
310
+ ResourceAssignOrgRole .Type : {policy .ActionRead },
311
+ ResourceAuditLog .Type : {policy .ActionRead },
311
312
// Allow auditors to see the resources that audit logs reflect.
312
313
ResourceTemplate .Type : {policy .ActionRead , policy .ActionViewInsights },
313
314
ResourceUser .Type : {policy .ActionRead },
@@ -327,7 +328,8 @@ func ReloadBuiltinRoles(opts *RoleOptions) {
327
328
Identifier : RoleTemplateAdmin (),
328
329
DisplayName : "Template Admin" ,
329
330
Site : Permissions (map [string ][]policy.Action {
330
- ResourceTemplate .Type : ResourceTemplate .AvailableActions (),
331
+ ResourceAssignOrgRole .Type : {policy .ActionRead },
332
+ ResourceTemplate .Type : ResourceTemplate .AvailableActions (),
331
333
// CRUD all files, even those they did not upload.
332
334
ResourceFile .Type : {policy .ActionCreate , policy .ActionRead },
333
335
ResourceWorkspace .Type : {policy .ActionRead },
0 commit comments