Team Permissions
Team permissions control what actions users can perform on datastores and their associated data assets. Each team is assigned a single permission level that applies to all datastores assigned to that team.
Note
Admins are not subject to team permissions and can access all data assets. Team permissions only apply to users with the Manager and Member roles. For platform-level permissions, see the User Roles documentation.
Tip
Admins can preview the platform as a single-team Manager by enabling Team Restriction Mode. This is helpful for demonstrating team permissions or diagnosing access issues reported by Members and Managers.
Permission Hierarchy
Permissions follow a hierarchical model. Higher permissions include all capabilities of lower permissions:
| Level | Permission | Includes |
|---|---|---|
| 5 | Editor | Editor + Author + Drafter + Viewer + Reporter |
| 4 | Author | Author + Drafter + Viewer + Reporter |
| 3 | Drafter | Drafter + Viewer + Reporter |
| 2 | Viewer | Viewer + Reporter |
| 1 | Reporter | Reporter only |
Permission Matrix
Legend:
- The permission grants the ability to perform the action
- The permission does not grant the ability to perform the action
| Action | Reporter | Viewer | Drafter | Author | Editor |
|---|---|---|---|---|---|
| Datastores | |||||
| View Source Datastore | |||||
| Preview Source Datastore | |||||
| Edit Datastore Settings | |||||
| Edit Quality Score Settings | |||||
| Delete Source Datastore | |||||
| Multi-Schema Datastore Creation 2 | |||||
| View Enrichment Datastore | |||||
| Preview Enrichment Datastore | |||||
| Delete Enrichment Datastore | |||||
| Operations | |||||
| View Activity | |||||
| Run & Manage Operations (Sync, Profile, Scan, External Scan, Materialize, Export, Promote) | |||||
| Schedule Operations (Sync, Profile, Scan, Materialize, Export) | |||||
| Create/Delete Computed Asset (as owner) | |||||
| Create/Delete Computed Asset (any owner) | |||||
| Reassign Computed Asset owner | |||||
| Profiles | |||||
| View Profiles | |||||
| Delete Profiles | |||||
| Quality Checks | |||||
| View Checks | |||||
| Create Draft Checks | |||||
| Save / Restore Check to Draft | |||||
| Create / Edit Active Checks | |||||
| Activate / Validate Check | |||||
| Edit Check Metadata | |||||
| Archive / Delete Checks | |||||
| Dry Run Check | |||||
| Anomalies | |||||
| View Anomalies (including Description and Assignees fields) | |||||
| View Anomaly Source Records | |||||
| Change Anomaly Status (Acknowledge / Archive) | |||||
| Edit Anomaly Description | |||||
| Add / Remove Anomaly Assignees | |||||
| Link / Unlink External Ticket on Anomaly 1 | |||||
| Add Comment to Anomaly | |||||
| Tags | |||||
| View Tags | |||||
| Assign Tags to Datastores, Containers, and Fields | |||||
| Assign Tags to Draft Quality Checks | |||||
| Assign Tags to Active Quality Checks | |||||
| Assign Tags to Anomalies | |||||
| Datastore Groups | |||||
| View Datastore Groups | |||||
| Assign Datastore to Group | |||||
| Field Status | |||||
| View Field Status | |||||
| Mask / Unmask Field | |||||
| Exclude Field | |||||
| Restore Field | |||||
| Delete Field | |||||
| Merge Fields | |||||
| View Masked Field Values |
Tag rules span two axes
Managing tag definitions (create, update, delete) is controlled by the Manager user role; any user with the Manager or Admin role can manage tag definitions regardless of team membership. Applying an existing tag to an asset, in contrast, is a team-permission action gated by the rows above. Users with the Manager user role do not bypass the team-permission gate for tag application: they must still hold the required team permission (Editor for datastores, containers, and fields; Drafter for draft quality checks; Author for active quality checks and anomalies) on the asset's datastore. Only Admin users bypass both axes.
Computed Asset ownership
Computed Assets (Computed Tables, Computed Files, Computed Joins, and Computed Fields) follow a hybrid ownership model. Authors can create, edit, and delete computed assets they personally own. Editors can manage any computed asset on the datastore regardless of owner, and only Editors can reassign ownership to another user. For a cross-datastore Computed Join, the user also needs at least Viewer permission on the right-side datastore to use its containers as join inputs.
Individual Permissions
For detailed descriptions of each permission level, see the individual pages:
-
Editor
Full datastore management: enrichment, operations, computed fields, and field status.
-
Author
Quality check management: activate, validate, and manage check lifecycle.
-
Drafter
Check creation: create and save checks as drafts for future activation.
-
Viewer
Read access: view anomalies, source records, and add comments.
-
Reporter
Report access: dashboards, overviews, and analytical insights.
-
In addition to the Author team permission on the anomaly's datastore, linking or unlinking an external ticket also requires the platform-wide Manager user role (or higher). Users with only the Author team permission but a Member user role cannot use the ticket link/unlink actions. ↩
-
Multi-Schema Datastore Creation is gated at the user-role layer, not by team permissions. It requires the Manager user role (or higher) plus the Editor team permission on at least one team assigned to the new datastores. See Multiple-Schema Permissions for the full flow. ↩