Skip to content

Enrichment Permissions

This page covers who can link a source datastore to a destination, change its settings, unlink, and work inside the enrichment datastore. For the full reference of user roles, see User Roles. For the canonical matrix of every team-permission-gated action, see Team Permissions Overview.

Two Permission Systems

Qualytics has two separate systems. User roles (Member, Manager, Admin) control what a user can do across the whole workspace. Team permissions (Reporter, Viewer, Drafter, Author, Editor) control what a user can do on the specific datastores their teams cover. The two are independent, and most actions check both.

User Roles (Workspace-Level)

Action Member Manager Admin
Link a destination to a source datastore
Change the destination
Edit enrichment settings
Create a destination from the link dialog
Unlink a destination
Delete a destination

Creating a destination from the link dialog is creating a datastore, so it follows the same rule as any datastore creation: the Manager role, with the Editor team permission on at least one team the new datastore is assigned to.

Team Permissions (Asset-Level)

Team permissions are checked on the source datastore for the link and its settings, and on the destination for everything you do inside it.

Action Reporter Viewer Drafter Author Editor
See a datastore's destination
Link or change the destination
Edit enrichment settings
Open a destination and its Overview
Preview the records of a written container
Unlink a destination

Note

Unlinking is restricted to the Admin role, with no team permission check. The dashes in that row mean team permissions do not apply to the action.

Inside a destination, computed assets and operations follow the ordinary datastore rules. Author can create and edit their own computed assets, while Editor can manage any owner's assets, run operations, or change datastore settings. If checks are needed on a written container, Drafter can author drafts and Author can create active checks. See the Team Permissions Overview.

Team access to an enrichment datastore is granted like any datastore, and the Teams listing shows them in the Enrichment Destinations column. A user with no team access to it does not see it in the tree, even when a source datastore they can see writes to it.

How Both Layers Work Together

To link a destination, change it, or edit the enrichment settings, a user needs both:

  1. User role: at least Member.
  2. Team permission: Editor on the source datastore.

To create a destination from the link dialog, a user needs the Manager role, and the new datastore is assigned to teams that user has Editor permission on.

To unlink, a user needs only the Admin role. No team permission is checked.

To see which destination a datastore writes to, a user needs at least Member and Reporter on the source datastore. To preview the records inside a written container, the user needs at least Viewer on the destination.

Admin Bypass

Users with the Admin role bypass all team-level checks. An Admin can link, change, edit, and unlink on any datastore regardless of team membership.

UI Behavior Without Permission

Scenario What the user sees
Member role, but no Editor team permission on the source The datastore's Settings menu is not offered. API requests to link or edit settings are refused.
Member role, opening the link dialog Add new is not offered; only Use existing is.
Not an Admin, trying to unlink Unlinking is refused with 403 Forbidden, even if the link dialog can be opened.
No team access to the destination The destination does not appear in the tree, so its containers cannot be opened, even though the source datastore still shows which destination it writes to.

Full Permissions Reference

For the complete permissions and roles matrix across all Qualytics features, see the Team Permissions page.