Audit Token Permissions When CI Fails
Permission errors in CI are confusing. Automatically check if your token scopes are the culprit.
Trigger
Issue Updated Trigger
Triggered when an issue is updated. For example labels are changed, issue status is changed, etc.
Action
Get Current Access Token
Tool to retrieve the authenticated api access token details. use when you need to confirm the validity and scopes of the current api token.
Why this helps
Build fails with permission errors but you can't quickly tell if it's a token scope issue - forces manual investigation and guessing
- Token scopes audited automatically on permission failures
- Root cause identified in seconds not minutes
- Permission issues resolved faster
- Prevents wasted debugging time
Setup
Build it in a few focused steps.
- 1Connect Linear and Buildkite integrations to Notis
- 2Create automation: When an issue is updated with a mention of permission error or access denied, audit the Buildkite API token scopes and report what access it has
- 3Select Issue Updated as the trigger
- 4Configure your notification channel
- 5Test by creating an issue mentioning permission errors and confirm token scopes are audited
Questions about this workflow
What scopes does the token check look for?
It validates all token scopes including builds, organizations, artifacts, agents, and more
Can this fix permission issues automatically?
This automation audits permissions. Fixing them by regenerating tokens or adjusting scopes is a separate step.
How detailed is the scope report?
You can ask Notis for summary-level or detailed scope breakdowns depending on your needs
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Linear to Buildkite. A trigger fires from one place; an action lands in another.
Linear triggers
Buildkite actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Get Current Access Token
Tool to retrieve the authenticated api access token details. use when you need to confirm the validity and scopes of the current api token.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Get Meta
Tool to retrieve metadata about the buildkite api. use when you need to fetch webhook ip addresses for firewall or security configurations.
Comment Received Trigger
Triggered when a comment is received.
List Pipeline Agents
Tool to list connected agents for an organization. use after confirming the organization slug. supports optional filtering and pagination.
Issue Created Trigger
Triggered when a new issue is created.
Issue Updated Trigger
Triggered when an issue is updated. For example labels are changed, issue status is changed, etc.
Private Team Comment Created
Fires when a new comment is posted on an issue in a private Linear team (polled with the connected user's token).
Private Team Issue Created
Fires when a new issue appears in a private Linear team (polled with the connected user's token).
Private Team Issue Properties Updated
Fires when properties on an issue change in a private Linear team (polled with the connected user's token).
Connect any two apps with Notis in the middle.
Linear and Buildkite, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Buildkite.