Enrichment Permissions
This page covers who can link a source datastore to a destination, change its settings, unlink, and work inside the enrichment datastore. For the full reference of user roles, see User Roles. For the canonical matrix of every team-permission-gated action, see Team Permissions Overview.
Two Permission Systems
Qualytics has two separate systems. User roles (Member, Manager, Admin) control what a user can do across the whole workspace. Team permissions (Reporter, Viewer, Drafter, Author, Editor) control what a user can do on the specific datastores their teams cover. The two are independent, and most actions check both.
User Roles (Workspace-Level)
| Action | Member | Manager | Admin |
|---|---|---|---|
| Link a destination to a source datastore | |||
| Change the destination | |||
| Edit enrichment settings | |||
| Create a destination from the link dialog | |||
| Unlink a destination | |||
| Delete a destination |
Creating a destination from the link dialog is creating a datastore, so it follows the same rule as any datastore creation: the Manager role, with the Editor team permission on at least one team the new datastore is assigned to.
Team Permissions (Asset-Level)
Team permissions are checked on the source datastore for the link and its settings, and on the destination for everything you do inside it.
| Action | Reporter | Viewer | Drafter | Author | Editor |
|---|---|---|---|---|---|
| See a datastore's destination | |||||
| Link or change the destination | |||||
| Edit enrichment settings | |||||
| Open a destination and its Overview | |||||
| Preview the records of a written container | |||||
| Unlink a destination |
Note
Unlinking is restricted to the Admin role, with no team permission check. The dashes in that row mean team permissions do not apply to the action.
Inside a destination, computed assets and operations follow the ordinary datastore rules. Author can create and edit their own computed assets, while Editor can manage any owner's assets, run operations, or change datastore settings. If checks are needed on a written container, Drafter can author drafts and Author can create active checks. See the Team Permissions Overview.
Team access to an enrichment datastore is granted like any datastore, and the Teams listing shows them in the Enrichment Destinations column. A user with no team access to it does not see it in the tree, even when a source datastore they can see writes to it.
How Both Layers Work Together
To link a destination, change it, or edit the enrichment settings, a user needs both:
- User role: at least Member.
- Team permission: Editor on the source datastore.
To create a destination from the link dialog, a user needs the Manager role, and the new datastore is assigned to teams that user has Editor permission on.
To unlink, a user needs only the Admin role. No team permission is checked.
To see which destination a datastore writes to, a user needs at least Member and Reporter on the source datastore. To preview the records inside a written container, the user needs at least Viewer on the destination.
Admin Bypass
Users with the Admin role bypass all team-level checks. An Admin can link, change, edit, and unlink on any datastore regardless of team membership.
UI Behavior Without Permission
| Scenario | What the user sees |
|---|---|
| Member role, but no Editor team permission on the source | The datastore's Settings menu is not offered. API requests to link or edit settings are refused. |
| Member role, opening the link dialog | Add new is not offered; only Use existing is. |
| Not an Admin, trying to unlink | Unlinking is refused with 403 Forbidden, even if the link dialog can be opened. |
| No team access to the destination | The destination does not appear in the tree, so its containers cannot be opened, even though the source datastore still shows which destination it writes to. |
Full Permissions Reference
For the complete permissions and roles matrix across all Qualytics features, see the Team Permissions page.