Skip to content

Teams FAQ

Answers to common questions about teams, permissions, and access control.

General

What is a team?

A team is a group of users that share access to specific datastores at a defined permission level. Teams are the primary mechanism for controlling datastore-level access in Qualytics.

What is the Public team?

The Public team is a default team that every user is automatically part of. It provides access to all datastores assigned to it. The Public team cannot be deleted, and its name, display name, and users cannot be edited.

Can a user belong to multiple teams?

Yes. A user can be a member of multiple teams, each granting access to different datastores at different permission levels. The user's effective access is the combination of all their team memberships.


Name and Display Name

What is the difference between a team's Name and its Display Name?

The Name identifies the team and is the value group sync compares against your directory groups. The Display Name is an optional friendlier label shown in its place across the platform. See How Teams Work.

When should I set a Display Name?

Set one when the Name has to match an identity-provider group and is hard to read on its own, such as WF-DQ-PROD-ANALYSTS-RW. Keep that string as the Name and put the readable label in Display Name. Do not rename the team itself for that, because the match uses the Name only.

I renamed a team to match a directory group, but nobody joins it. Why?

Check which field you changed. Group sync matches the team's Name, never its Display Name. If you edited the Display Name, set the Name to the group name instead and move the friendly label to Display Name. See Edit a Team.

How do I find a team by its Name when the list shows Display Names?

Type the Name in the Search field above the Teams list; it matches both the label on screen and the underlying Name. Hovering over a team's label also shows its Name in the tooltip, and Copy Name in the row's right-click menu copies it. See Sort Teams.


Permissions

What permission levels are available?

Teams can have one of five permission levels: Editor, Author, Drafter, Viewer, or Reporter. See How It Works for detailed permission tables.

Are Admins subject to team permissions?

No. Administrators have full access to all data assets regardless of team membership. Team permissions only apply to users with the Member and Manager roles.

What happens if a user is in two teams with different permissions for the same datastore?

The user gets the highest permission level from their team memberships. For example, if Team A grants Viewer access and Team B grants Editor access to the same datastore, the user will have Editor access.

Why can't a Manager create a datastore?

Creating a datastore needs two things: the Manager role and the Editor team permission on at least one team the new datastore will belong to. If the Manager's teams all sit below Editor, the Add Datastore form has no team to offer and says: "You do not have Editor permissions for any Team and therefore cannot create a datastore." This is common when a Manager is only in the Public team and an Admin has set the Public team's permission to Reporter or Viewer. An Admin can fix it by adding the Manager to a team with Editor, or by raising the permission of a team they already belong to.


Management

Who can create and manage teams?

Only users with the Admin role can create, edit, and delete teams. Users with the Manager role can view the Teams list.

Why was my change to a team refused because of a datastore?

A datastore must belong to at least one team. Removing a datastore from the only team it is assigned to, or deleting that team, is refused until the datastore is assigned to another team. See Edit a Team and Delete a Team.

Can I assign Service Users to teams?

Yes. Service Users can be assigned to teams to scope their access to specific datastores. This is the recommended way to control what automated integrations can access.

Can I automate team assignments?

Yes. Directory Sync is available for both deployment models:

  • Use Directory Sync to manage the full user, Team, and Team membership lifecycle.
  • For self-hosted deployments that authenticate through an OIDC or SAML identity provider, just-in-time group sync is an add-only alternative.

Choose one method as the source of Team membership. If both methods are enabled, sign-in mapping can add a membership that Directory Sync previously removed.