# Permissions

The recommended approach is to assign the **Reader** role to the Service Principal on every subscription that should be monitored. At a minimum, a custom role must allow the application to list accessible subscriptions and read Service Health events, including `Microsoft.ResourceHealth/events/read`.

Sensitive details from some security advisories may be hidden from identities without elevated permissions. The plugin queries the event list but does not call the additional `fetchEventDetails` operation required to retrieve sensitive content.