Roles and Permissions
Roles in the Tetra Data Platform (TDP) help you securely control access to which parts of the TDP users can access. By assigning TDP users and groups either preconfigured or custom roles that have specific Policies attached to them, you can grant granular permissions based on common user personas and the Functionality access each requires.
Users can be assigned either View Access or Full Access to each platform functionality.
To create and assign custom roles, see Create Custom Roles. To assign preconfigured roles, see Edit a User Role.
Preconfigured Roles
Each TDP deployment includes three preconfigured roles:
By default, each preconfigured role is assigned one or more Policies based on common TDP user personas and the Functionality access each requires.
To assign preconfigured roles, see Edit a User Role.
NOTE
Customer hosted TDP deployments also include a ts-admin role. The ts-admin role provides the same permissions as the Org Admin role, along with additional permissions for creating and managing organizations. As part of standard platform support and maintenance agreements, TetraScience Customers Success and Support Engineers are granted access to the platform as a Read-Only user by default.
Administrator Role Permissions
Assigned policies: Organization Admin and Tenant Admin
Functionality | View access | Full access |
---|---|---|
Administration | Yes | Yes |
Artifacts | Yes | Yes |
Attribute Management | Yes | Yes |
Audit Trail | Yes | Yes |
Bulk Actions | Yes | Yes |
Data Apps | Yes | Yes |
Data Sources | Yes | Yes |
Health Monitoring | Yes | Yes |
IDS Artifacts | Yes | Yes |
My Account | Yes | Yes |
Pipelines | Yes | Yes |
Projects | Yes | Yes |
Search | Yes | Yes |
SQL Search | Yes | Yes |
Member Role Permissions
Assigned policies: Member
Functionality | View access | Full access |
---|---|---|
Administration | Yes | No |
Artifacts | Yes | Yes |
Attribute Management | Yes | Yes |
Audit Trail | Yes | No |
Bulk Actions | Yes | No |
Data Apps | Yes | No |
Data Sources | Yes | No |
Health Monitoring | Yes | No |
IDS Artifacts | Yes | Yes |
My Account | Yes | Yes |
Pipelines | Yes | No |
Projects | Yes | Yes |
Search | Yes | Yes |
SQL Search | Yes | Yes |
Read Only Role Permissions
Assigned policies: Support
Functionality | View access | Full access |
---|---|---|
Administration | Yes | No |
Artifacts | Yes | Yes |
Attribute Management | Yes | No |
Audit Trail | Yes | No |
Bulk Actions | Yes | No |
Data Apps | Yes | No |
Data Sources | Yes | No |
Health Monitoring | Yes | No |
IDS Artifacts | Yes | No |
My Account | Yes | Yes |
Pipelines | Yes | No |
Projects | Yes | No |
Search | Yes | No |
SQL Search | Yes | Yes |
Custom Roles
Custom roles are configured through a combination of Policies based on common TDP user personas and the Functionality access each requires. Organization administrators can create or edit roles assigned one or more Policies to make sure that functionality access is limited to only what is necessary for each user’s role through both the TDP user interface and TetraScience API.
To create and assign custom roles, see Create Custom Roles and Edit a User Role.
Policies
You can assign one or more of the following policies to any custom role in the TDP:
Developer Policy Permissions
Functionality | View access | Full access |
---|---|---|
Administration | No | No |
Artifacts | Yes | Yes |
Attribute Management | Yes | Yes |
Audit Trail | No | No |
Bulk Actions | Yes | Yes |
Data Apps | Yes | Yes |
Data Sources | Yes | Yes |
Health Monitoring | Yes | Yes |
IDS Artifacts | Yes | Yes |
My Account | Yes | Yes |
Pipelines | Yes | Yes |
Projects | Yes | Yes |
Search | Yes | Yes |
SQL Search | Yes | Yes |
Data User Policy Permissions
Functionality | View access | Full access |
---|---|---|
Administration | No | No |
Artifacts | No | No |
Attribute Management | No | No |
Audit Trail | No | No |
Bulk Actions | No | No |
Data Apps | No | No |
Data Sources | No | No |
Health Monitoring | No | No |
IDS Artifacts | Yes | No |
My Account | Yes | Yes |
Pipelines | Yes | No |
Projects | Yes | No |
Search | Yes | No |
SQL Search | Yes | Yes |
Data Owner Policy Permissions
Functionality | View access | Full access |
---|---|---|
Administration | No | No |
Artifacts | Yes | No |
Attribute Management | Yes | Yes |
Audit Trail | No | No |
Bulk Actions | No | No |
Data Apps | Yes | Yes |
Data Sources | Yes | No |
Health Monitoring | No | No |
IDS Artifacts | Yes | No |
My Account | Yes | Yes |
Pipelines | Yes | No |
Projects | Yes | Yes |
Search | Yes | Yes |
SQL Search | Yes | Yes |
Auditor Policy Permissions
Functionality | View access | Full access |
---|---|---|
Administration | No | No |
Artifacts | No | No |
Attribute Management | No | No |
Audit Trail | Yes | Yes |
Bulk Actions | No | No |
Data Apps | No | No |
Data Sources | No | No |
Health Monitoring | No | No |
IDS Artifacts | No | No |
My Account | Yes | Yes |
Pipelines | No | No |
Projects | No | No |
Search | No | No |
SQL Search | No | No |
Analyst Policy Permissions
Functionality | View access | Full access |
---|---|---|
Administration | No | No |
Artifacts | Yes | No |
Attribute Management | Yes | Yes |
Audit Trail | No | No |
Bulk Actions | Yes | Yes |
Data Apps | Yes | Yes |
Data Sources | Yes | No |
Health Monitoring | Yes | Yes |
IDS Artifacts | Yes | No |
My Account | Yes | Yes |
Pipelines | Yes | Yes |
Projects | Yes | No |
Search | Yes | Yes |
SQL Search | Yes | Yes |
Tenant Admin Policy Permissions
Functionality | View access | Full access |
---|---|---|
Administration | Yes | Yes |
Artifacts | Yes | Yes |
Attribute Management | Yes | Yes |
Audit Trail | Yes | Yes |
Bulk Actions | Yes | Yes |
Data Apps | Yes | Yes |
Data Sources | Yes | Yes |
Health Monitoring | Yes | Yes |
IDS Artifacts | Yes | Yes |
My Account | Yes | Yes |
Pipelines | Yes | Yes |
Projects | Yes | Yes |
Search | Yes | Yes |
SQL Search | Yes | Yes |
Organization Admin Policy Permissions
Functionality | View access | Full access |
---|---|---|
Administration | Yes | Yes |
Artifacts | Yes | Yes |
Attribute Management | Yes | Yes |
Audit Trail | Yes | Yes |
Bulk Actions | Yes | Yes |
Data Apps | Yes | Yes |
Data Sources | Yes | Yes |
Health Monitoring | Yes | Yes |
IDS Artifacts | Yes | Yes |
My Account | Yes | Yes |
Pipelines | Yes | Yes |
Projects | Yes | Yes |
Search | Yes | Yes |
SQL Search | Yes | Yes |
Member Policy Permissions
Functionality | View access | Full access |
---|---|---|
Administration | Yes | No |
Artifacts | Yes | Yes |
Attribute Management | Yes | Yes |
Audit Trail | Yes | No |
Bulk Actions | Yes | No |
Data Apps | Yes | No |
Data Sources | Yes | No |
Health Monitoring | Yes | No |
IDS Artifacts | Yes | Yes |
My Account | Yes | Yes |
Pipelines | Yes | No |
Projects | Yes | Yes |
Search | Yes | Yes |
SQL Search | Yes | Yes |
Support Policy Permissions
Functionality | View access | Full access |
---|---|---|
Administration | Yes | No |
Artifacts | Yes | Yes |
Attribute Management | Yes | No |
Audit Trail | Yes | No |
Bulk Actions | Yes | No |
Data Apps | Yes | No |
Data Sources | Yes | No |
Health Monitoring | Yes | No |
IDS Artifacts | Yes | No |
My Account | Yes | Yes |
Pipelines | Yes | No |
Projects | Yes | No |
Search | Yes | No |
SQL Search | Yes | Yes |
Functionalities
Each policy's Functionality permissions map to the following features within the TDP:
Functionality | Features |
---|---|
Administration | Tenant settings, Organization Settings, Login Users, Service Users, Roles, Certificates, Settings SQL Access, Access Groups, Shared Settings, Commands, Event Subscriptions, System Log |
Artifacts | Protocols, Task Scripts, Connectors, Tetraflows |
Attribute Management | Labels, Metadata, Tags |
Audit Trail | Audit Trail |
Bulk Actions | Labels, Data Reconciliation, Pipelines |
Data Apps | Data Apps, Sessions |
Data Sources | Sources, Sources API |
Health Monitoring | Dashboard, Agents, Data Hubs, Connectors, Cloud Connectors, Files, Events |
IDS Artifacts | Intermediate Data Schemas (IDSs) |
My Account | My Account |
Pipelines | File Processing, Scan Unprocessed, Reprocess, Timeline, Pipelines, Pipelines API |
Projects | Projects |
Search | Create a new Saved Search, Upload Files, File Details, File Download, File Preview, More File Info, Upload New File Version, Delete File, Open file in Tetra Data & AI Workspace, Download select files, Create bulk label change job, Download search results as a CSV file, Manage Collection, Query API Sandbox |
SQL Search | SQL Search |
Updated 24 days ago