Skip to content
Notis

Audit Token Permissions When CI Fails

Permission errors in CI are confusing. Automatically check if your token scopes are the culprit.

Trigger

Issue Updated Trigger

Triggered when an issue is updated. For example labels are changed, issue status is changed, etc.

Action

Get Current Access Token

Tool to retrieve the authenticated api access token details. use when you need to confirm the validity and scopes of the current api token.

Why this helps

Build fails with permission errors but you can't quickly tell if it's a token scope issue - forces manual investigation and guessing

  • Token scopes audited automatically on permission failures
  • Root cause identified in seconds not minutes
  • Permission issues resolved faster
  • Prevents wasted debugging time

Setup

Build it in a few focused steps.

  • 1Connect Linear and Buildkite integrations to Notis
  • 2Create automation: When an issue is updated with a mention of permission error or access denied, audit the Buildkite API token scopes and report what access it has
  • 3Select Issue Updated as the trigger
  • 4Configure your notification channel
  • 5Test by creating an issue mentioning permission errors and confirm token scopes are audited

Questions about this workflow

What scopes does the token check look for?

It validates all token scopes including builds, organizations, artifacts, agents, and more

Can this fix permission issues automatically?

This automation audits permissions. Fixing them by regenerating tokens or adjusting scopes is a separate step.

How detailed is the scope report?

You can ask Notis for summary-level or detailed scope breakdowns depending on your needs

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Linear to Buildkite. A trigger fires from one place; an action lands in another.

Linear triggers

Buildkite actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Get Current Access Token

Tool to retrieve the authenticated api access token details. use when you need to confirm the validity and scopes of the current api token.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get Meta

Tool to retrieve metadata about the buildkite api. use when you need to fetch webhook ip addresses for firewall or security configurations.

ActionInstant

Comment Received Trigger

Triggered when a comment is received.

TriggerInstant

List Pipeline Agents

Tool to list connected agents for an organization. use after confirming the organization slug. supports optional filtering and pagination.

ActionInstant

Issue Created Trigger

Triggered when a new issue is created.

TriggerInstant

Issue Updated Trigger

Triggered when an issue is updated. For example labels are changed, issue status is changed, etc.

TriggerInstant

Private Team Comment Created

Fires when a new comment is posted on an issue in a private Linear team (polled with the connected user's token).

TriggerPolling

Private Team Issue Created

Fires when a new issue appears in a private Linear team (polled with the connected user's token).

TriggerPolling

Private Team Issue Properties Updated

Fires when properties on an issue change in a private Linear team (polled with the connected user's token).

TriggerPolling

Connect any two apps with Notis in the middle.

Linear and Buildkite, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Buildkite.