Roles and Permissions

Roles in the Tetra Data Platform (TDP) help you securely control access to which parts of the TDP users can access. By assigning TDP users and groups either preconfigured or custom roles that have specific Policies attached to them, you can grant granular permissions based on common user personas and the Functionality access each requires.

Users can be assigned either View Access or Full Access to each platform functionality.

To create and assign custom roles, see Create Custom Roles. To assign preconfigured roles, see Edit a User Role.

Preconfigured Roles

Each TDP deployment includes three preconfigured roles:

By default, each preconfigured role is assigned one or more Policies based on common TDP user personas and the Functionality access each requires.

To assign preconfigured roles, see Edit a User Role.

📘

NOTE

Customer hosted TDP deployments also include a ts-admin role. The ts-admin role provides the same permissions as the Org Admin role, along with additional permissions for creating and managing organizations. As part of standard platform support and maintenance agreements, TetraScience Customers Success and Support Engineers are granted access to the platform as a Read-Only user by default.

Administrator Role Permissions

Assigned policies: Organization Admin and Tenant Admin

FunctionalityView accessFull access
AdministrationYesYes
ArtifactsYesYes
Attribute ManagementYesYes
Audit TrailYesYes
Bulk ActionsYesYes
Data AppsYesYes
Data SourcesYesYes
Health MonitoringYesYes
IDS ArtifactsYesYes
My AccountYesYes
PipelinesYesYes
ProjectsYesYes
SearchYesYes
SQL SearchYesYes

Member Role Permissions

Assigned policies: Member

FunctionalityView accessFull access
AdministrationYesNo
ArtifactsYesYes
Attribute ManagementYesYes
Audit TrailYesNo
Bulk ActionsYesNo
Data AppsYesNo
Data SourcesYesNo
Health MonitoringYesNo
IDS ArtifactsYesYes
My AccountYesYes
PipelinesYesNo
ProjectsYesYes
SearchYesYes
SQL SearchYesYes

Read Only Role Permissions

Assigned policies: Support

FunctionalityView accessFull access
AdministrationYesNo
ArtifactsYesYes
Attribute ManagementYesNo
Audit TrailYesNo
Bulk ActionsYesNo
Data AppsYesNo
Data SourcesYesNo
Health MonitoringYesNo
IDS ArtifactsYesNo
My AccountYesYes
PipelinesYesNo
ProjectsYesNo
SearchYesNo
SQL SearchYesYes

Custom Roles

Custom roles are configured through a combination of Policies based on common TDP user personas and the Functionality access each requires. Organization administrators can create or edit roles assigned one or more Policies to make sure that functionality access is limited to only what is necessary for each user’s role through both the TDP user interface and TetraScience API.

To create and assign custom roles, see Create Custom Roles and Edit a User Role.

Policies

You can assign one or more of the following policies to any custom role in the TDP:

Developer Policy Permissions

FunctionalityView accessFull access
AdministrationNoNo
ArtifactsYesYes
Attribute ManagementYesYes
Audit TrailNoNo
Bulk ActionsYesYes
Data AppsYesYes
Data SourcesYesYes
Health MonitoringYesYes
IDS ArtifactsYesYes
My AccountYesYes
PipelinesYesYes
ProjectsYesYes
SearchYesYes
SQL SearchYesYes

Data User Policy Permissions

FunctionalityView accessFull access
AdministrationNoNo
ArtifactsNoNo
Attribute ManagementNoNo
Audit TrailNoNo
Bulk ActionsNoNo
Data AppsNoNo
Data SourcesNoNo
Health MonitoringNoNo
IDS ArtifactsYesNo
My AccountYesYes
PipelinesYesNo
ProjectsYesNo
SearchYesNo
SQL SearchYesYes

Data Owner Policy Permissions

FunctionalityView accessFull access
AdministrationNoNo
ArtifactsYesNo
Attribute ManagementYesYes
Audit TrailNoNo
Bulk ActionsNoNo
Data AppsYesYes
Data SourcesYesNo
Health MonitoringNoNo
IDS ArtifactsYesNo
My AccountYesYes
PipelinesYesNo
ProjectsYesYes
SearchYesYes
SQL SearchYesYes

Auditor Policy Permissions

FunctionalityView accessFull access
AdministrationNoNo
ArtifactsNoNo
Attribute ManagementNoNo
Audit TrailYesYes
Bulk ActionsNoNo
Data AppsNoNo
Data SourcesNoNo
Health MonitoringNoNo
IDS ArtifactsNoNo
My AccountYesYes
PipelinesNoNo
ProjectsNoNo
SearchNoNo
SQL SearchNoNo

Analyst Policy Permissions

FunctionalityView accessFull access
AdministrationNoNo
ArtifactsYesNo
Attribute ManagementYesYes
Audit TrailNoNo
Bulk ActionsYesYes
Data AppsYesYes
Data SourcesYesNo
Health MonitoringYesYes
IDS ArtifactsYesNo
My AccountYesYes
PipelinesYesYes
ProjectsYesNo
SearchYesYes
SQL SearchYesYes

Tenant Admin Policy Permissions

FunctionalityView accessFull access
AdministrationYesYes
ArtifactsYesYes
Attribute ManagementYesYes
Audit TrailYesYes
Bulk ActionsYesYes
Data AppsYesYes
Data SourcesYesYes
Health MonitoringYesYes
IDS ArtifactsYesYes
My AccountYesYes
PipelinesYesYes
ProjectsYesYes
SearchYesYes
SQL SearchYesYes

Organization Admin Policy Permissions

FunctionalityView accessFull access
AdministrationYesYes
ArtifactsYesYes
Attribute ManagementYesYes
Audit TrailYesYes
Bulk ActionsYesYes
Data AppsYesYes
Data SourcesYesYes
Health MonitoringYesYes
IDS ArtifactsYesYes
My AccountYesYes
PipelinesYesYes
ProjectsYesYes
SearchYesYes
SQL SearchYesYes

Member Policy Permissions

FunctionalityView accessFull access
AdministrationYesNo
ArtifactsYesYes
Attribute ManagementYesYes
Audit TrailYesNo
Bulk ActionsYesNo
Data AppsYesNo
Data SourcesYesNo
Health MonitoringYesNo
IDS ArtifactsYesYes
My AccountYesYes
PipelinesYesNo
ProjectsYesYes
SearchYesYes
SQL SearchYesYes

Support Policy Permissions

FunctionalityView accessFull access
AdministrationYesNo
ArtifactsYesYes
Attribute ManagementYesNo
Audit TrailYesNo
Bulk ActionsYesNo
Data AppsYesNo
Data SourcesYesNo
Health MonitoringYesNo
IDS ArtifactsYesNo
My AccountYesYes
PipelinesYesNo
ProjectsYesNo
SearchYesNo
SQL SearchYesYes

Functionalities

Each policy's Functionality permissions map to the following features within the TDP:

FunctionalityFeatures
AdministrationTenant settings, Organization Settings, Login Users, Service Users, Roles, Certificates, Settings SQL Access, Access Groups, Shared Settings, Commands, Event Subscriptions, System Log
ArtifactsProtocols, Task Scripts, Connectors, Tetraflows
Attribute ManagementLabels, Metadata, Tags
Audit TrailAudit Trail
Bulk ActionsLabels, Data Reconciliation, Pipelines
Data AppsData Apps, Sessions
Data SourcesSources, Sources API
Health MonitoringDashboard, Agents, Data Hubs, Connectors, Cloud Connectors, Files, Events
IDS ArtifactsIntermediate Data Schemas (IDSs)
My AccountMy Account
PipelinesFile Processing, Scan Unprocessed, Reprocess, Timeline, Pipelines, Pipelines API
ProjectsProjects
SearchCreate a new Saved Search, Upload Files, File Details, File Download, File Preview, More File Info, Upload New File Version, Delete File, Open file in Tetra Data & AI Workspace, Download select files, Create bulk label change job, Download search results as a CSV file, Manage Collection, Query API Sandbox
SQL SearchSQL Search