# Common Scenarios

This section outlines the behavior for scenarios where ABAC policies and custom roles have been configured for a user.

* * *

## Scenario 1: Publish workload in the denied cluster [¶](https://docs.rafay.co/security/abac/troubleshooting/#scenario-1-publish-workload-in-the-denied-cluster "Permanent link")

If a user is assigned a custom role that denies a specific cluster write access and attempts to publish a workload in a cluster, the following error will be encountered.

* * *

## Scenario 2: Deploy an application thru ZTKA [¶](https://docs.rafay.co/security/abac/troubleshooting/#scenario-2-deploy-an-application-thru-ztka "Permanent link")

If a user is assigned a custom role that denies a cluster write access and attempts to deploy an application thru ZTKA, the following error will be encountered.

* * *
