Skip to content

User Roles

In Qualytics, every user is assigned a role that determines their platform-level permissions. Roles control what features and actions a user can perform globally, independent of team membership.

There are three user roles: Admin, Manager, and Member. Admins have the ability to edit any user's role from the user listing.

Info

User roles control platform-level permissions. For datastore-level access, see the Team Permissions documentation.

Role Hierarchy

Roles follow a hierarchical model: higher roles include all capabilities of lower roles:

Level Role Includes
3 Admin Admin + Manager + Member
2 Manager Manager + Member
1 Member Member only

Permission Matrix

Action Member Manager Admin
Users & Teams
Manage users (create, edit, deactivate)
Manage teams (create, edit, delete)
View users and teams
Create service users
Datastores
Create source datastores 3
Delete source datastores
List datastores (team-scoped)
Create enrichment datastores 3
Delete enrichment datastores
Connections
Read connections
Create connections
Update / Delete connections
Tags & Notifications
View tags
Manage tags (create, update, delete)
View notification rules
Manage notification rules
Library
View library
Manage library
Tokens
Generate personal tokens
Generate service tokens
Generate SCIM administration tokens
Flows
Create / Edit / Execute / Delete flows 2
Integrations
Add integrations
Sync an integration across all its datastores
Sync an integration for one datastore (with Editor team permission)
Anomalies
Link / Unlink external tickets on anomalies 1
Datastore Groups
Create / Edit / Delete groups
Filter and Sort
Filter Explore by datastores in your teams
Filter Explore by all workspace datastores
Filter Explore by any workspace tag
Filter Presets
Create a filter preset
Apply a filter preset
Edit or delete a filter preset you created
Edit or delete a filter preset created by another user
Field Status
Manage field status (with Editor team permission)
View masking audit log
Settings UI
Connections tab
Tokens tab
Access tab
Integrations tab
Defaults tab
Audit tab
Status tab
Platform
View health status
View platform activity log (Audit)
View AgentQ audit history
Restart Dataplane
Capture Dataplane diagnostics
Manage global settings
Subject to team permissions

Individual Roles

For detailed descriptions of each role, see the individual pages:

  • Admin


    Full platform access. Manage users, teams, datastores, connections, and all settings.

    Admin

  • Manager


    Global asset management. Create datastores and connections, manage tags and notifications.

    Manager

  • Member


    Standard access. Inherits permissions from team membership, manages own tokens.

    Member


  1. In addition to the Manager user role, linking or unlinking an external ticket also requires the Author team permission (or higher) on the anomaly's datastore. Admins bypass the team-permission check; Managers do not. ↩

  2. In addition to the Manager user role, creating, editing, publishing, activating, executing, aborting, or deleting a Flow requires the Editor team permission on every datastore the Flow references. Admins bypass the team-permission check; Managers do not. ↩

  3. In addition to the Manager user role, creating a datastore requires the Editor team permission on at least one of the teams the new datastore is assigned to (the Public team when none is chosen). A Manager whose teams all sit below Editor cannot create datastores. Admins bypass the team-permission check; Managers do not. ↩↩