Datastore Tags Permissions
This page covers the roles and permissions required to assign and unassign tags on source datastores. For the full reference of user roles and how they compare, see User Roles. For the canonical matrix of every team-permission-gated action, see Team Permissions Overview.
Permission Matrix
Datastore access is controlled by team permissions. The user also needs the Member role or above; Admin bypasses team restrictions.
| Action | Minimum team permission |
|---|---|
| View tags on an accessible datastore | Reporter |
| Assign or unassign datastore tags | Editor |
| Run Profile or Scan filtered by tag | Editor |
Key Details
- Viewing tags requires access to the datastore; assigning a tag does not grant access.
- Assigning and unassigning tags requires the Editor team permission or above in at least one of the teams the datastore belongs to. This is a team-level permission - the user must be a member of a team that has Editor access to the datastore.
- Running operations filtered by tag (scoping Profile/Scan to tagged containers) requires the Editor team permission or above. This is the same permission required to run any operation - the tag filter is part of the operation configuration, not a separate permission.
- Admin users bypass all team-level permission checks and can manage tags across all datastores regardless of team membership.
Team Context
Permissions for assign/unassign are evaluated against the datastore's team assignments. A user with the Editor team permission must be in at least one team that the datastore belongs to. For more details on how teams work, see the Team Permissions page.
UI Behavior Without Permission
| Scenario | What the User Sees |
|---|---|
| User lacks the Editor team permission | The button next to "Assign tags to this datastore" is hidden - the tag selector cannot be opened. Tags are displayed as read-only. |
| User has no team access to the datastore | The datastore is not listed - the user cannot see it at all. |
Creating, Editing, or Deleting Tags
Creating, editing, and deleting tags are global actions not specific to datastores. These actions require the Manager role or above. Assigning a new tag name through the datastore API can also create that tag without a separate tag-management action. For those permissions, see the Tags documentation.
Full Permissions Reference
For the complete permissions and roles matrix across all Qualytics features, see the Team Permissions page.