> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mountthor.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Actions

> The actions a custom role can grant

A role version contains an exact set of **actions**. Each action ID identifies
one operation and is written `service:Method`. Action IDs are case-sensitive,
and `mthr iam roles create` rejects an ID that is not in the tables below.

Pass these IDs to `mthr iam roles create --action`. See
[Roles and bindings](/platform/roles-and-bindings) for the full workflow.

## Account

| Action | Grants |
| - | - |
| `directory:GetTenant` | Read tenant details |
| `account:Get` | Read the account record |
| `product:List` | List the products available to the account |
| `terms:GetCurrent` | Read the current terms |
| `terms:Accept` | Accept the current terms |
| `authorization:ListGrants` | Review role assignments and effective access |

## Billing

| Action | Grants |
| - | - |
| `billing:GetBillingAccount` | Read the billing account and its balance |
| `billing:GetBillingCredits` | Read credit balances |
| `billing:ListPriceCatalog` | Read the price catalog |
| `billing:ListInvoices` | List invoices |
| `billing:GetInvoice` | Read one invoice |
| `billing:ExportInvoices` | Export invoices as CSV |
| `billing:GetFundingStatus` | Read prepaid funding status |
| `billing:GetFundingRecovery` | Read the outcome of a funding request |
| `billing:RequestFunding` | Buy prepaid funds |
| `billing:SetAutoRecharge` | Change the auto-recharge settings |
| `billing:CreateBillingPortalSession` | Open the payment portal |
| `billing:CreateSetupIntent` | Start adding a payment method |
| `billing:CompleteSetupIntent` | Finish adding a payment method |

## Kubernetes access

| Action | Grants |
| - | - |
| `access:CreateAccessSession` | Create an access session |
| `access:GetAccessSession` | Read an access session |
| `access:RevokeAccessSession` | Revoke an access session |

## Actions reserved to Owners

Member administration, service-account administration, and access
administration stay with the built-in **Owners** role. A custom role that
requests one of these is rejected. To use them, a person needs an Owners
binding:

* `authorization:CreateRole`, `authorization:DisableRole`,
  `authorization:CreateBinding`, `authorization:DisableBinding`
* `directory:InviteMember`, `directory:ResendInvitation`,
  `directory:CancelInvitation`, `directory:GetInvitation`,
  `directory:GetMember`, `directory:ListMembers`,
  `directory:DeactivateMember`, `directory:BeginOffboarding`
* `directory:CreateServiceAccount`, `directory:ListServiceAccounts`,
  `directory:DeactivateServiceAccount`
* `authentication:CreateServiceAccountCredential`,
  `authentication:ListServiceAccountCredentials`,
  `authentication:RotateServiceAccountCredential`,
  `authentication:RevokeServiceAccountCredential`

Owners can still review and revoke any assignment, including one made by
another owner. See [Members](/platform/members) and
[Service accounts](/platform/service-accounts) for those workflows.

## Inspect a role

```bash theme={null}
mthr iam roles get ROLE_ID
```

The result lists the role's exact actions, its version, and the action catalog
that validated it. A role you create keeps that catalog for its lifetime.
