Datastore Grouping Permissions
Datastore Grouping uses two independent layers of access control in Qualytics: User Roles (organization-level) and Team Permissions (resource-level). A user may need to satisfy both layers to perform certain actions. For the full reference of user roles and how they compare, see User Roles. For the canonical matrix of every team-permission-gated action, see Team Permissions Overview.
Two Permission Systems
Qualytics has two separate permission systems. User Roles (Member, Manager, Admin) control actions across the workspace. Team Permissions (Reporter, Viewer, Drafter, Author, Editor) control actions on datastores available through team membership. Viewer and Editor are team permissions, not user roles.
User Roles (Organization-Level)
User Roles determine what type of actions a user can perform across the workspace. Group management actions (create, edit, delete) are controlled at this level.
| Action | Member | Manager | Admin |
|---|---|---|---|
| View groups | |||
| Create a group | |||
| Edit a group | |||
| Delete a group | |||
| Add/remove datastore from group |
Manage Groups Button
The Manage groups button in the tree view header is only visible to users with the Manager role or above. Members can still see groups and the datastores they have access to, but cannot access the group management panel.
Team Permissions (Resource-Level)
Team Permissions determine what a user can do on a specific datastore. Adding or removing a datastore from a group requires Editor permission on that datastore's team.
| Action | Reporter | Viewer | Drafter | Author | Editor |
|---|---|---|---|---|---|
| View groups in tree | |||||
| Add datastore to group | |||||
| Remove datastore from group |
How Both Layers Work Together
To add or remove a datastore from a group, a user must satisfy both layers:
- User Role: Must be at least Member (organization-level)
- Team Permission: Must have Editor permission on the specific datastore (resource-level)
To create, edit, or delete a group, a user only needs:
- User Role: Must be Manager or Admin (organization-level). No team permission is required since groups are workspace-wide resources.
Admin Bypass
Users with the Admin role bypass all team-level permission checks. An Admin can add or remove any datastore from any group regardless of team membership.
UI Behavior Without Permission
| Scenario | What the User Sees |
|---|---|
| User is below Manager role | The Manage groups button is hidden - the user cannot access the group management panel. |
| User is below Editor team permission | The Assign to group button on datastore hover is hidden - the user cannot add or remove the datastore from a group. |
Important Notes
- Groups do not grant access: Groups are workspace-wide, but users only see the datastores their team access allows. Putting a datastore in a shared group does not make it visible to other users.
- Datastore permissions are independent: Adding a datastore to a group does not change who can access or modify that datastore. Existing team permissions remain unchanged.
- Favorite status is independent: Adding a datastore to a group does not affect its favorite status, and vice versa.
Full Permissions Reference
For the complete permissions and roles matrix across all Qualytics features, see the Team Permissions page.