Skip to content

Datastore Grouping Permissions

Datastore Grouping uses two independent layers of access control in Qualytics: User Roles (organization-level) and Team Permissions (resource-level). A user may need to satisfy both layers to perform certain actions. For the full reference of user roles and how they compare, see User Roles. For the canonical matrix of every team-permission-gated action, see Team Permissions Overview.

Two Permission Systems

Qualytics has two separate permission systems. User Roles (Member, Manager, Admin) control actions across the workspace. Team Permissions (Reporter, Viewer, Drafter, Author, Editor) control actions on datastores available through team membership. Viewer and Editor are team permissions, not user roles.

User Roles (Organization-Level)

User Roles determine what type of actions a user can perform across the workspace. Group management actions (create, edit, delete) are controlled at this level.

Action Member Manager Admin
View groups
Create a group
Edit a group
Delete a group
Add/remove datastore from group

Manage Groups Button

The Manage groups button in the tree view header is only visible to users with the Manager role or above. Members can still see groups and the datastores they have access to, but cannot access the group management panel.

Team Permissions (Resource-Level)

Team Permissions determine what a user can do on a specific datastore. Adding or removing a datastore from a group requires Editor permission on that datastore's team.

Action Reporter Viewer Drafter Author Editor
View groups in tree
Add datastore to group
Remove datastore from group

How Both Layers Work Together

To add or remove a datastore from a group, a user must satisfy both layers:

  1. User Role: Must be at least Member (organization-level)
  2. Team Permission: Must have Editor permission on the specific datastore (resource-level)

To create, edit, or delete a group, a user only needs:

  1. User Role: Must be Manager or Admin (organization-level). No team permission is required since groups are workspace-wide resources.

Admin Bypass

Users with the Admin role bypass all team-level permission checks. An Admin can add or remove any datastore from any group regardless of team membership.

UI Behavior Without Permission

Scenario What the User Sees
User is below Manager role The Manage groups button is hidden - the user cannot access the group management panel.
User is below Editor team permission The Assign to group button on datastore hover is hidden - the user cannot add or remove the datastore from a group.

Important Notes

  • Groups do not grant access: Groups are workspace-wide, but users only see the datastores their team access allows. Putting a datastore in a shared group does not make it visible to other users.
  • Datastore permissions are independent: Adding a datastore to a group does not change who can access or modify that datastore. Existing team permissions remain unchanged.
  • Favorite status is independent: Adding a datastore to a group does not affect its favorite status, and vice versa.

Full Permissions Reference

For the complete permissions and roles matrix across all Qualytics features, see the Team Permissions page.