Privileges and Roles Reference
In the Cloud Portal, you can create and assign roles, each of which consists of one or more privileges. A privilege is a level of access to a type of object.
Below, you can review the available privileges, including the supported levels for each.
For more information on privileges and roles, see Overview of Authorization .
Privileges
Flows
The flows privilege governs access to flow objects.
Access Level | Name | Description |
---|---|---|
0 | None | Assigned role cannot see or use flows, including the pages where flows are available. |
1 | Viewer | Assigned user can access Flows page and Flow View page for flows that the user owns or has been shared. User can also run jobs on the user's own flows. User cannot make changes to any flows. |
2 | Editor | All of the above, plus: Assigned user can edit, share, and run jobs on flows to which the user has access. Note By default, editors can also schedule flows. This option can be disabled by an administrator. Tip Flow editors can edit any custom SQL used to import datasets into the flow. |
3 | Author | All of the above, plus: Assigned user can create new flows, schedule flows, and delete flows. |
Tip
If you have enabled deployment management, a deployment user should be assigned author-level access. Lesser flow roles may prevent the deployment user from properly importing and managing flows. Go to the Roles Page.
Connections
The connections privilege governs access to connection objects.
Access Level | Name | Description |
---|---|---|
0 | None | Assigned role cannot see or use connections, including the pages where connections are available. |
1 | Viewer | Assigned user can access Connections page for connections that the user owns or has been shared. User can share connections. User cannot make changes to any connections. |
2 | Editor | All of the above, plus: Assigned user can edit and share connections to which the user has access. |
3 | Author | All of the above, plus: Assigned user can create new connections and delete connections. |
Plans
The plans privilege manages access to plan objects.
Access Level | Name | Description |
---|---|---|
0 | None | Assigned role cannot see or use plans, including the pages where plans are available. |
1 | Viewer | Assigned user can access Plans page and Plan View page for plans that the user owns or has been shared. User can also run jobs on the user's own plans. User can cancel plan runs. |
2 | Editor | All of the above, plus: Assigned user can edit, share, and run jobs on plans to which the user has access. Note By default, editors can also schedule plans. This option can be disabled by an administrator. |
3 | Author | All of the above, plus: Assigned user can create new plans, schedule plans, and delete plans. |
Datasets
The Datasets functions privilege manage access to imported datasets and reference datasets and their UI pages in the application.
Access Level | Name | Description |
---|---|---|
0 | None | Assigned user cannot perform any operations on datasets. |
1 | Viewer | Assigned user only can view datasets. User cannot edit datasets. |
2 | Editor | Assigned user can view, edit, and share datasets. |
3 | Author | All of the above, plus: Assigned user can create new, view, edit, share, and delete datasets. |
Workflows
The Workflows privilege manages access to Designer Experience and Designer Desktop workflows.
Access Level | Name | Description |
---|---|---|
0 | None | Assigned user cannot perform any operations on datasets. |
1 | Editor | Assigned user can view, edit, and share datasets. |
2 | Author | All of the above, plus: Assigned user can create new, view, edit, share, and delete datasets. |
Standard Platform Roles
The following roles are provided with the product.
Note
The following roles cannot be removed.
Default
The default role is assigned to each user when the user is initially created. This role contains the following permissions:
Privilege | Access Level—Name |
---|---|
Flows | 3—Author |
Connections | 3—Author |
Plans | 3—Author |
Datasets | 3—Author |
Tip
You can modify the default role if you want to set a lower level of base access for each new user of the product. For more information, see Overview of Authorization.
Workspace admin
This role provides super-user privileges to the assigned user.
Note
This role enables for the user owner-level access to all objects in the project or workspace and access to all admin-level settings and configuration pages in the admin console. This role should not be assigned to many users. At least one user should always have this role.
Note
You cannot modify or delete this role.
Application-Specific Roles
The following roles are available to manage access to individual applications and their features.
Note
To access a specific application in the Alteryx Analytics Cloud, a workspace user must have one of the following listed roles. Roles can be provisioned by a workspace admin to individual users. For more information, see Roles Page.
Note
Where applicable, adding a role to a user which permits the user to access the application increments the seat count for the licensed application. If insufficient seats are available for the application, the role is not assigned.
Note
Roles and authentication for Auto Insights are not governed by Alteryx Analytics Cloud.
Tip
The Creator
role for each application enables the user to access the application to create, edit, delete, and publish application assets.
Application Name | Role(s) | Notes |
---|---|---|
Designer Cloud | Designer Cloud Creator | Access to Designer Experience. |
Reporting | Report Creator | Access to application. |
Machine Learning | Machine Learning Creator | Access to application. |
Metrics Store | Metrics Store Creator | Access to application. Enables user to create workflow templates in application. |
Metrics Store Customizer | Access to application. Enables user to configure templates to meet enterprise data needs. | |
Metrics Store Consumer | Access to application. Enables user to use metrics reports from Metrics Store application or from third-party systems via API. | |
Auto Insights | Auto Insights Creator | Access to application. Enables user to create and share datasets and create Missions. |
Auto Insights Consumer | Access to application Enables user to view shared datasets and create Missions. |