In the Pulumi Cloud console, grant each ESC environment to the appropriate team explicitly; there are no wildcards, so every environment needs its own grant, and the default environment permission is the closest thing to one. After granting, re-run preview. In CI, check which identity the pipeline authenticates as and grant that team or service account access to the environment.

Context: GitHub issue pulumi/pulumi#15484 (closed, 16 comments): pulumi preview suddenly fails on every stack with You do not have permission to perform this operation when opening the ESC environment. Maintainer pgavlin confirms the cause is access control: the identity running the command is not granted on the environment, and each environment must be added to teams individually.

## Matched source
Source: Published skill
Original query: "Pulumi preview fails with permission errors on ESC environments"
Key terms: environments, errors, fails, permission, preview, pulumi
