All Products
Search
Document Center

Dataphin:Appendix: Global and project role permissions

Last Updated:Sep 16, 2026

This topic describes the permissions for global and project roles.

Global role permissions

Super X

Feature

Actions

Description

X-Analytics

View

View the X-Analytics page and ask questions using natural language.

X-Data Engineering

View

View X-Data Engineering.

Intelligent App Management-Model Configuration & Intelligent App

Manage

Enable, disable, and edit assistants.

Configure the large models used by intelligent assistants.

Intelligent App Management-Operations Management

View Credit consumption statistics

View statistics on Credit consumption.

Intelligent App Management-Intelligent Analysis Collection

Create

Create Intelligent Analysis Collections and collection groups.

Manage

Edit and delete Intelligent Analysis Collections and collection groups.

Enterprise Knowledge Base

View

View authorized knowledge bases and their knowledge.

Manage

Create, edit, and delete knowledge bases.

Create, edit, and delete knowledge within knowledge bases.

Data development

Feature area

Global permission point

Description

Development

Development

View

Lets you view the development module.

Modify the default cluster for the resource dashboard

Lets you modify the default display cluster on the O&M > Resource Scheduling Dashboard.

Tag

Asset marketplace

View

Grants view-only access to the asset marketplace.

Lets you view the asset list in the public marketplace.

Lets you view asset details and perform group analysis.

(Permitted actions depend on asset visibility. All assets in the public marketplace are accessible. Assets in the private marketplace are accessible only if they are visible.)

Workbench

View

Grants view-only access to the workbench.

(Access is determined by project roles. Users can view the workbench if added to a tag project, even without this global permission.)

Asset application - Tag offline service

View

Lets you view the task list for tag offline services.

Lets you view the details of tag offline service tasks.

Lets you create a tag offline service.

(Anyone can initiate this action, but it only succeeds if you have permission for the target application.)

Asset application - Group offline service

View

Lets you view the offline service task list across all your permitted applications.

Lets you view the details of group offline service tasks.

Lets you create a group offline service.

(Anyone can initiate this action, but it only succeeds if you have permission for the target application.)

Asset application - Group paginated query

View

Lets you view the task list for group paginated queries across all your permitted applications.

Lets you view the details of group paginated query tasks.

Lets you create a group paginated query.

(Anyone can initiate this action, but it only succeeds if you have permission for the target application.)

Asset application - User profile service

View

Lets you view the list of user profiles across all your permitted applications.

Lets you view user profile details.

Lets you create a user profile.

(Anyone can initiate this action, but it only succeeds if you have permission for the target application.)

Asset application - Application management

View

Lets you create an application.

Event center - Attribute management

View

Lets you view the attribute list.

Lets you view attribute details.

Manage

Lets you create an attribute.

Lets you edit an attribute.

Lets you delete an attribute.

Event center - Event management

View

Lets you view the event list.

Lets you view event details.

Manage

Lets you create an event.

Lets you edit an event.

Lets you delete an event.

Event center - Category management

View

Lets you view the category list.

Manage

Lets you create a category.

Lets you edit a category.

Lets you delete a category.

Asset governance

Feature

Actions

Description

Governance

Asset inventory

View

Search for assets.

View asset details.

Initiate data profiling

Initiate data profiling for data tables (automatic/manual).

View data profiling records and reports for data tables.

Perform operations on data profiling records for data tables (for example, view logs and terminate runs).

Data standard

Data standard/Standard set

View

View the standard sets you have joined.

View the list of batch operation records.

View the standard sets you have joined.

Manage data standards

Create a data standard.

Edit a data standard.

Clone a data standard.

Submit a data standard for release.

Take a data standard offline.

Delete a data standard.

Edit associated standards for a data standard.

Edit associated documents for a data standard.

Batch import data standards. This action requires the "Standard template - Batch import standards" permission.

Batch export data standards. This action requires the "Standard template - Batch export standards" permission.

View details of batch operations. This action requires the "Standard template - View import records" permission.

Create a standard within a standard set.

Manage standard set catalog

Create a standard set catalog.

Edit a standard set catalog.

Delete a standard set catalog.

Manage standard set

View all standard sets.

Create a standard set.

Edit a standard set.

Batch export standards from a standard set.

Clone a standard set.

Delete a standard set.

Standard mapping rule

View

View the list of standard mapping rules.

View the list of execution records for standard mapping rules.

View a mapping rule.

View execution records for a mapping rule. You can only view records for mapping rules that you have permission to access.

View standard mapping details from an execution record.

Manage

Create a standard mapping rule.

Edit a standard mapping rule.

Change the effective status of a mapping rule.

Manually run a mapping rule as a temporary task.

Delete a standard mapping rule.

View execution logs for a mapping rule.

View execution logs from an execution record.

Mapping

View

View global mappings (valid and invalid).

View the standard mapping evaluation configuration.

View standard mapping evaluation records.

View mapping details (valid and invalid).

View the details of valid mappings.

View standard mapping evaluation results for valid mappings.

View the list of batch import records for mappings (valid and invalid).

Batch import mappings (valid and invalid).

Batch export mappings (valid and invalid).

Manage

Edit the standard mapping evaluation configuration.

View execution logs from a standard mapping evaluation record.

View configured data standard quality monitoring rules for valid mappings.

Create data standard quality monitoring rules for valid mappings.

Edit configured data standard quality monitoring rules for valid mappings.

Delete configured data standard quality monitoring rules for valid mappings.

Set a valid mapping to invalid.

Configure quality monitoring for a valid mapping.

Remove a valid mapping.

View batch import record details for mappings (valid and invalid).

Revert an invalid mapping.

Standard mapping evaluation details

View

View public standard mapping evaluation details (standard view and asset object view).

View mapping details from the standard mapping evaluation details page (standard view and asset object details).

Standard mapping execution records

View

View all execution records for standard mappings.

View mapping details and execution logs from a standard mapping execution record.

Code table

View

View the code table list.

View code table details.

View the list of batch import records for code tables.

View the list of batch export records for code tables.

View code table references.

View the code table catalog.

Batch export code tables.

Manage code table catalog

Create a code table catalog.

Edit a code table catalog.

Delete a code table catalog.

Manage code table

Create a code table.

Edit a code table.

Batch import code tables.

View batch import record details for code tables.

Download batch export files for code tables.

Delete a code table.

Root term

View

View the root term list.

View the list of batch operation records for root terms.

Batch export root terms.

Manage

Create a root term.

Batch import root terms.

Edit a root term.

Delete a root term.

View batch operation record details for root terms.

Standard document

View

View the standard document list.

Preview standard documents online (PDF only).

View associated standards for a standard document.

View the standard document catalog.

Manage standard document catalog

Create a standard document catalog.

Edit a standard document catalog.

Delete a standard document catalog.

Manage standard document

Upload a standard document.

Edit a standard document.

Move a standard document.

Download a standard document.

Delete a standard document.

Common standard attribute

View

View the list of common standard attributes.

View details of a system attribute.

Manage

Create a custom attribute.

View details of a custom attribute.

Edit a custom attribute.

Clone a custom attribute.

Delete a custom attribute.

Standard template

View

View the standard template list.

View standard template details.

Manage

Create a standard template.

Edit a standard template.

Delete a standard template.

Identification feature

View

View the list of identification features.

View identification feature details.

Manage

Configure feature scanning.

Note

This is a separate permission from the Rule run configuration permission in Asset Security. Either of these permissions allows you to modify feature scanning configurations.

Create an identification feature.

Edit an identification feature.

Clone an identification feature.

Delete an identification feature.

Quality

Quality dashboard

View

View the quality dashboard.

Validation record

View

View validation records for the current account.

View validation records for joined projects.

View validation details.

View rule validation details.

View execution logs.

View a quality report.

Manage

Download exception data from validation details.

Pause a validation run.

Quality rule

View

View quality rules for the current account.

View quality rules for joined projects.

View quality rule details.

View a quality report.

View the rule configuration list.

View rule configuration details.

View the scheduling configuration list.

View the alert configuration list.

View the exception archiving list.

View a quality report.

View rule validation details from a quality report.

View execution logs from a quality report.

View the permissions list for a quality rule.

Manage

Add monitored objects (all resources).

Add a quality rule.

Run a quality rule.

Manage quality owners.

Edit quality score weights.

Delete a quality rule.

Enable or disable a quality rule.

Perform batch operations

(such as run, manage quality owners, enable, disable, edit quality score weights, delete, and manage permissions).

Modify the quality score weight from the quality rule details page.

Create a quality rule from the quality rule details page.

Clone a rule configuration.

Edit a rule configuration.

Test run a rule configuration.

Run a rule configuration.

Configure scheduling for a rule.

Configure the quality score for a rule.

Delete a rule configuration.

Change the effective status of a rule configuration.

Edit, clone, or delete a scheduling configuration.

Modify an alert configuration.

Add an exception archive table.

Set an exception archive table as default or delete it.

Edit permissions for a quality rule.

Download exception data from a validation record.

Pause a validation record.

In the governance workbench, perform actions such as viewing details, initiating rectification, ignoring, unignoring, whitelisting, notifying owners, re-validating, and viewing operation records.

Perform actions in the rectification process.

Perform actions in the governance whitelist.

Perform actions in the knowledge base (view, create, edit, delete).

Rule template

View

View the rule template list.

Manage

Create a rule template.

View references for a rule template.

Edit a rule template.

Add a quality rule.

View template details.

Clone a rule template.

Transfer a rule template.

Delete a rule template.

Data source management

View

View the data source list.

Manage

Set a rate limit.

Issue list

View

View the issue list for the current account.

View the issue list for joined projects.

Manage

Perform actions on issues

(such as view details, initiate rectification, ignore, unignore, whitelist, notify owner, re-validate, and view operation records).

Rectification process

View

View the rectification process for the current account.

Manage

Perform actions in the rectification process (such as view details, ignore, unignore, notify owner, re-validate, and link to knowledge base).

Knowledge base

View

View the knowledge base.

Manage

Perform actions in the knowledge base (create, link, edit, delete).

Governance whitelist

View

View the governance whitelist for the current account.

Manage

Perform actions in the governance whitelist (edit and delete).

Asset security

Identification result

View

View all identification results.

View upload history for identification results.

View identification details.

Manage

Upload identification results from an Excel file.

Manually add an identification result.

Lock or unlock data classification, or change the identification mode for a result.

Identification rule

View

View all identification rules.

View the classification scan scope.

View identification rule details.

Manage

Create an identification rule.

Scan with a manual rule.

Configure a rule run.

Configure automatic inheritance for an identification rule.

Enable or disable automatic identification.

Reset, edit, copy, transfer, delete, or test an identification rule.

Identification run record

View

View all identification run records.

Manage

Terminate an identification run.

View task identification details from a run record.

Data masking rule

View

View all data masking rules (dynamic masking rules, whitelists, static masking).

View masking algorithms or masking whitelists.

Manage

View or modify the default data masking policy.

Create, edit, transfer, or delete dynamic masking rules, or change their effective status.

Create, edit, clone, or delete a dynamic masking whitelist, or change its effective status.

Key management

View

View all key lists.

View references for a key.

Register key

Register a key.

Manage

Manage key permissions.

Edit, transfer, or delete a key.

Data classification

View

View all data classifications.

View all identification features for a data classification.

View an identification feature.

View the data classification model.

View model details for a data classification.

View the number of effective fields for a data classification.

Manage

Create, change the effective status of, edit, move, or delete a data classification.

Configure data masking for a data classification.

Specify, enable, or disable the data sensitivity level for a data classification.

Data sensitivity level

View

View all data sensitivity levels.

Manage

Create, edit, or delete a data sensitivity level.

Identification feature

View

View the list of identification features.

View identification feature details.

Manage

Create an identification feature.

Edit an identification feature.

Clone an identification feature.

Delete an identification feature.

Security algorithm

View

View all data masking algorithms.

Manage

Test a data masking algorithm.

Project security policy

View

View the global project security policy.

View details

View project security policy details.

Manage

Edit the project security policy.

Resource governance

Resource analysis

View

View the resource analysis page.

Governance analysis

View

View the governance analysis page.

Governance effectiveness

View

View the governance effectiveness page.

My governance

View

View the my governance page.

Project governance

View

View the project governance page.

Governance item management

View

View the governance item management page.

Push management

View

View the push management page.

Task management

View

View the task management page.

Recycle bin

View

View the recycle bin.

Metadata

Metadata collection

Manage

View the collection task list.

Create a collection task.

Edit a collection task.

Delete a collection task.

View the metadata inventory.

View metadata instances.

Set a collection task to active or inactive.

Run a collection task manually or as a temporary task.

Retry updating a collection task.

View the collection instance list.

View the metadata change overview.

View run logs.

View a collection task.

Rerun a collection instance.

Terminate a collection instance.

Metadata inventory

View

View the list of source system metadata.

View source system metadata details.

Data profiling

Profiling and analysis

Configure data profiling.

Source system

Manage

View the source system list.

Create a source system.

Edit a source system.

Delete a source system.

Sampling configuration

View

View the sampling configuration.

Manage

Edit the sampling configuration.

Other features

Metadata management

Register and delete external lineage using the OpenGauss API.

Asset

Overview

View

View the asset overview.

Catalog

Display menu

Displays the asset catalog menu. If this permission is not granted, the menu is hidden, but the page remains accessible using its URL. You can use this with custom menus to redesign the asset page. For more information, see Rebuild the asset page by using custom menus.

Table

View and use the corresponding tab in the asset catalog. For example, if only the Table permission is granted, only the Table tab is displayed in the asset catalog, and other tabs are hidden.

Note

Before upgrading Dataphin to v6.3, if the "Asset catalog - View" permission was granted, all permissions under "Asset - Catalog" are automatically granted after the upgrade. Otherwise, none are granted.

Metric

API

Dashboard

Catalog management - Catalog planning

View

View all topics and catalogs.

Manage

Create asset topics and catalogs.

Edit asset topics and catalogs.

Delete asset topics and catalogs.

Catalog management - Listing management

View

View the listing management and menu pages.

Manage

Edit an asset.

List an asset.

Delist an asset.

Postpone the listing of an asset.

Set maintenance permissions.

Standard

View

View standard assets.

Asset consumption

My consumption - Available to me

View

View the list of available assets.

  • View all application records

  • View Quick BI dashboards

  • View Quick BI self-service data retrievals

  • Renew assets

  • Apply for more permissions on a specific asset

  • View application records

  • View asset details

  • Create a Quick BI dashboard

  • Create a Quick BI self-service data retrieval

  • Apply for permissions

  • Add to application basket

Analyze in Notebook.

My consumption - My BI analysis

View

View the list of my BI analyses.

Edit dashboards or self-service data retrievals.

View dashboards or self-service data retrievals.

Consumption configuration - Consumption channels

Manage

Create, edit, or delete consumption channels.

Asset analysis

Level-1 permission

Global permission

Permission

Analytics

notebook

View

View directory

View notebook

Create directory

Edit directory

Delete directory

Create notebook

Edit notebook

Save notebook

Delete notebook

Share notebook

Unshare notebook

Run notebook

SQL query

View

View directory

View SQL

Create directory

Edit directory

Delete directory

Create SQL

Edit SQL

Save SQL

Delete SQL

Share SQL

Unshare SQL

Run SQL

manual table

View

View directory

View manual table

Create manual table

Edit data - manual table

Edit table structure - manual table

Save - manual table

Publish - manual table

Download - manual table

Share - manual table

Unshare - manual table

Delete table - manual table

Transfer owner - manual table

Services

Marketplace

View

API service - View API service list

API service - View API documentation

API service - Download API documentation

API service - Apply for API

Dataphin data source service - View Dataphin data source service list

Dataphin data source service - View Dataphin data source documentation

Dataphin data source service - Apply for Dataphin data source

Invocation

View

Authorized API service - View authorized API list

Authorized API service - Apply for API

Authorized API service - Debug API

Authorized API service - Revoke API permission

Authorized Dataphin data source - View authorized Dataphin data source list

Authorized Dataphin data source - Apply for Dataphin data source

Authorized Dataphin data source - Revoke Dataphin data source permission

Application management - View application list

Application management - Create application

Application management - Edit application

Application management - Delete application

Application management - Apply for application

Application management - Show AppSecret

Application management - Copy AppSecret

Application management - Reset AppSecret

Application management - Transfer application owner

Usage example - View API usage example

Usage example - Edit API usage example

Usage example - Download SDK

Usage example - View Dataphin data source usage example

Usage example - Edit Dataphin data source usage example

Usage example - Download JDBC JAR

Development

View

API - View my APIs

API - Create API

API - Create API: Select service unit drop-down

API - Create API: Select Dataphin logical table

API - Create API: Select Dataphin logical table - business module

API - Create API: Select Dataphin logical table - business module - logical table

API - Edit API

API - View API details

API - Test API

API - Publish API

API - Delete API

API - Transfer API owner

service unit - View service unit list

service unit - Create service unit

service unit - Create service unit: Service unit name

service unit - Create service unit: Select data source

service unit - Edit service unit

service unit - View service unit details

service unit - Publish service unit

service unit - Delete service unit

service unit - Transfer service unit owner

metadata management - View authorized metadata list

metadata management - Create metadata

metadata management - Edit metadata

metadata management - Delete metadata

Dataphin data source - View my Dataphin data sources

Dataphin data source - Create Dataphin data source

Dataphin data source - Edit Dataphin data source

Dataphin data source - View Dataphin data source details

Dataphin data source - Delete Dataphin data source

Dataphin data source - Data source acceleration

Dataphin data source - Transfer Dataphin data source owner

Operations

View

Operations monitoring - API call statistics

Operations monitoring - API rate limiting

Operations monitoring - API alerts

API operations - API rate limiting configuration

API operations - API alert configuration

Service call log query - API call log query - View API call logs

Service call log query - Dataphin data source usage log query

- View Dataphin data source service call logs

Management

View

project management - View project list

project management - Create project

project management - Edit project

project management - Delete project

project management - Member management

project management - View group management

project management - Group management - Create service unit group

project management - Group management - Edit service unit group

project management - Group management - Delete service unit group

project management - Group management - Create application group

project management - Group management - Edit application group

project management - Group management - Delete application group

project management - Group management - Create data source group

project management - Group management - Edit data source group

project management - Group management - Delete data source group

system configuration - View configurations

system configuration - Modify configurations

network configuration - View network configurations

network configuration - Enable and disable public subdomain (public cloud standalone deployment)

network configuration - Enable and disable internal VPC domain (public cloud standalone deployment)

network configuration - Bind independent domain (public cloud standalone deployment)

network configuration - Enable and disable subdomain (private cloud)

network configuration - Show and hide invocation IP address (on-premises deployment)

network configuration - Bind independent domain (on-premises deployment)

Usage example - View API usage example

Usage example - Edit API usage example

Usage example - Download SDK

Usage example - View Dataphin data source usage example

Usage example - Edit Dataphin data source usage example

Usage example - Download JDBC JAR

More

Feature

Action

Description

Planning

Data architecture

View

Data architecture - View global data board list

Data architecture - View data board details

Data architecture - View associated projects

Data architecture - data board - business entity - View version information

Create

Data architecture - Create data board

Data architecture - Create subject domain

Data architecture - Create business entity

Data architecture - data board - subject domain management - Create subject domain

Data architecture - data board - subject domain management - Create sub-domain

Data architecture - data board - subject domain management - Create business entity

Data architecture - data board - business entity - Create business entity

Edit

Data architecture - Edit data board

Data architecture - data board - subject domain management - Edit subject domain

Data architecture - data board - business entity - Publish/Unpublish

Data architecture - data board - business entity - Create table

Data architecture - data board - business entity - Edit

Delete

Data architecture - Delete data board

Data architecture - data board - subject domain management - Delete subject domain

Data architecture - data board - business entity - Unpublish and delete

Common definitions

View

Common definitions - Statistical periods - View all statistical periods

Common definitions - Global variables - View global variables

Common definitions - Public calendars - View public calendars

Common definitions - Global variables - Request permissions

Common definitions - Global variables - View dependencies

Common definitions - Global variables - View version history

Common definitions - Public calendars - View calendar references

Common definitions - Public calendars - View calendar references - Referenced tags - View references

Common definitions - Public calendars - View calendar references - Referenced tags - View tag details

Common definitions - Public calendars - View calendar references - Referenced date types - View details

Common definitions - Public calendars - View calendar references - Referenced calendars - View details

Common definitions - Offline scheduling templates - View details

Manage

Common definitions - Statistical periods - Create statistical period

Common definitions - Statistical periods - Edit

Common definitions - Statistical periods - Delete

Common definitions - Global variables - View dependencies - View object

Common definitions - Global variables - View version history - Compare versions

Common definitions - Global variables - View version history - Roll back version

Common definitions - Global variables - Create variable group

Common definitions - Global variables - Create global variable

Common definitions - Global variables - Edit/Delete variable group

Common definitions - Global variables - Edit/Delete variable

Common definitions - Public calendars - Create public calendar

Common definitions - Public calendars - View calendar references - Referenced tags - Edit tag

Common definitions - Public calendars - View calendar references - Referenced tags - Delete tag

Common definitions - Public calendars - Create tag

Common definitions - Public calendars - Edit/Delete public calendar

Common definitions - Offline scheduling templates - Create offline scheduling template

Common definitions - Offline scheduling templates - Edit/Delete offline scheduling template

Attribute management

View Quality, API, Table, Metric, and dashboard attributes

Attribute management - View

Attribute management - Quality, API, Table, Metric, and dashboard - View details

Manage Quality, API, Table, Metric, and dashboard attributes

Attribute management - Quality, API, Table, Metric, and dashboard - Create attribute

Attribute management - Quality, API, Table, Metric, and dashboard - Edit

Attribute management - Quality, API, Table, Metric, and dashboard - Clone

Attribute management - Quality, API, Table, Metric, and dashboard - Enable/Disable

Attribute management - Quality, API, Table, Metric, and dashboard - Delete

View tag attributes

Attribute management - View

Attribute management - Tag - View details

Manage tag attributes

Attribute management - Tag - Create attribute

Attribute management - Tag - Edit

Attribute management - Tag - Clone

Attribute management - Tag - Delete

Attribute management - Tag - Enable/Disable

Tag architecture

View

Tag architecture - View

Manage

Tag architecture - Asset market management - Add/Edit/Set category/Delete market

Tag architecture - Entity management - Add/Edit/Delete entity

Tag architecture - ID management - Add/Edit/Delete ID

Project management

View

Project management - View my projects and all projects

Project management - View details of all projects (including configuration and information settings)

Project management - Member management - View all members in each project

Create

Project management - Create project - General/Tag project

Edit

Project management - Member management - Edit members in each project

Delete

Project management - Delete any project

Compute source

View

Compute source - View compute source list

Compute source - Test connection

Create

Compute source - Add compute source

Edit

Compute source - Edit/Transfer ownership/Delete

Delete

Compute source - Delete

Hadoop cluster

Databricks cluster

Amazon EMR cluster

SelectDB cluster

Doris cluster

AnalyticDB for PostgreSQL cluster

View

Compute source - Manage clusters - View details of each cluster (view, view version history, and compare versions)

Manage

Compute source - Manage clusters (create, edit, clone, and delete clusters)

Acceleration source management

View

Acceleration source - View acceleration source list

Acceleration source - Test connection

Create

Acceleration source - Add acceleration source

Edit

Acceleration source - Edit

Delete

Acceleration source - Delete

Admin center

Member management

View

View

Member management - View list of all members

Global role management - View all global roles

Global role management - View role details

Project role management - View all project roles

Project role management - View role details

Project role management - View project references

User group management - View my user groups and all user groups

Member management - My groups - View user group details and permissions

Member management - Member management

Manage tenant members

Member management - View contact information for all members

Member management - Add member

Member management - Automatically add members (SSO)

Member management - View ownership transfer history

Member management - Sync with account system (SSO)

Member management - Edit/Enable/Disable/Transfer ownership/Add to user group/Delete

Member management - Create account/Batch create (self-created)

Member management - Reset password (self-created account)

(The password of a super admin account cannot be reset.)

Member management - Project role management

Manage project roles

Project role management - Create, clone, edit, enable/disable, delete, or replace roles

Member management - User group

Manage user groups

User group management - Create and clone user groups

Member management - Manage members, and edit, delete, or enable/disable user groups

Permission management

View

View permission management

Permission management - Table management

Manage table permissions

Allows granting permissions on all tables when creating new roles. This permission can only be assigned by a super admin.

Authorize all tables

Permission management - Table permissions - Batch grant/revoke

Permission management - Permission audit

Audit permissions

Permission audit - Asset permission audit - View/Export

Permission audit - Asset operation audit - View/Export

Data source management

View

View data sources

Data source management - data source - View all data sources/Test connection

Data source management - Custom source types - View all source types

View connection information

Data source management - data source - View connection information

Data source management - data source

Create

Data source management - data source - Create data source

Edit

Data source management - data source - Edit data source

Data source management - data source - View connection information

Data source management - data source - Edit/Transfer ownership

Data source management - data source - Manage tags/Source systems

Delete

Data source management - data source - Delete data source

Data source management - data source - Delete production and development data sources

Data source management - Custom source type

Manage

Data source management - Custom source types - Add custom source type

Data source management - Custom source types - Transfer/Edit

Data source management - Custom source types - Delete custom source type

System settings

View

View system settings

System settings - Compute settings - View/Validate

System settings - Resource settings - View resource settings list

System settings - Resource settings - Session cluster - Go to Flink UI/View start/stop logs

System settings - Message channels - View all channel configurations

System settings - Intelligent engine - View

System settings - Cross-platform migration - View

System settings - Approval templates - View

System settings - Global tag settings - View

System settings - Analysis platform settings - View

System settings - Development platform settings - View

System settings - Logon security settings - View

System settings - Basic settings

Manage

System settings - Basic settings - Manage

System settings - Compute settings

Manage

System settings - Compute settings - Edit

System settings - Resource settings

Manage

System settings - Resource settings - Resource group configuration - Create, edit, enable/disable, or delete custom resource groups

System settings - Resource settings - Resource group configuration - Change the tenant's default resource group

System settings - Resource settings - Session cluster - Create, enable/disable, edit, or delete

System settings - Message channels

Manage

System settings - Message channels - Edit message channel

System settings - Style configuration

Manage

System settings - Style configuration - Edit style configuration

System settings - Intelligent engine

Manage

System settings - Intelligent engine - Edit

System settings - Cross-platform migration

Manage

System settings - Cross-platform migration - Edit

System settings - Approval templates

Manage

System settings - Approval templates - Add/Edit/Delete

System settings - Python third-party packages

Manage

System settings - Python third-party packages - Install Python module

System settings - Tag platform settings

Manage

System settings - Tag platform settings - Edit

System settings - Analysis platform settings

Manage

System settings - Analysis platform settings - Edit

System settings - Development platform settings

Manage

System settings - Development platform settings - Edit

System settings - Logon security settings

Manage

System settings - Logon security settings - Edit

Standard settings

View

View standard settings

Standard settings - Naming conventions - View

Standard settings - Security settings - View

Standard settings - Data download - View

Standard settings - Data permissions - View

Standard settings - Change policy - View

Standard settings - Change rules - View

Standard settings - Naming conventions

Manage

Standard settings - Naming conventions - Edit

Standard settings - Security settings

Manage

Standard settings - Security settings - Edit

Standard settings - Data download

Manage

Standard settings - Data download - Edit

Standard settings - Data permissions

Manage

Standard settings - Data permissions - Edit

Standard settings - Change policy

Manage

Standard settings - Change policy - Edit

Standard settings - Change rules

Manage

Standard settings - Change rules - Edit

Standard settings - Filename conventions

Manage

Standard settings - Filename conventions - Edit

Cross-tenant publishing

View

View cross-tenant publishing

Cross-tenant publishing - View publishing settings

Enable cross-tenant publishing mode

Maintenance and Upgrade - Cross-tenant publishing

  • Selecting this permission also grants the 'View' permission.

  • For non-admin users, this permission grants access only to the 'Cross-tenant publishing' section in 'Maintenance and Upgrade'.

My workspace

Notification center

Manage notification settings

Notification settings - View and edit

Alert center

View

Alert center - View

Alert center - Alert events - View all alert events

Alert center - Push history - View all push history

Alert center - Alert events - Address alert

Alert center - Push history - View alert content

Alert center - Message templates - View

Alert center - on-call schedule - View on-call schedules

Alert center - on-call schedule - View details of on-call schedules

Manage

Alert center - Alert events - Mute

Alert center - Message templates - Edit

Alert center - Create/Edit/Delete on-call schedule

Project role permissions

Feature

Action

Description

Project management

Member management

Edit

Add, delete, or modify roles for project members.

Configure project information

View

View project information settings.

Edit

Edit project information settings.

Call JDBC Driver

Call JDBC Driver

Execute SQL queries in the project using the JDBC Driver.

Project quality management

Quality rule management

Create monitored objects from objects within a project, and manage monitoring rules, validation records, and the issue list.

Planning

Business entity

Edit

Create, edit, delete, and deactivate business entities.

Data integration

Data integration

Access directory

View, search, and filter the real-time integration directory.

View, search, and filter the pipeline task directory.

View details

View real-time integration details, including the canvas, operators, properties, and history.

View pipeline task details, including the canvas, operators, properties, and history.

Edit

Create folders in the real-time integration directory.

Edit, rename, or delete folders in the real-time integration directory.

Create real-time full-database synchronization tasks.

Move real-time full-database synchronization tasks.

Deactivate real-time full-database synchronization tasks.

Edit real-time full-database synchronization tasks, including data source, sync settings, target table configuration, and DDL handling policy.

Change the owner of a real-time full-database synchronization task in its properties.

Configure resources for real-time full-database synchronization tasks.

Lock real-time full-database synchronization tasks.

Save real-time full-database synchronization tasks.

Deactivate and delete real-time full-database synchronization tasks.

Create folders in the pipeline task directory.

Edit, rename, or delete folders in the pipeline task directory.

Upload files to the pipeline task directory.

Delete tasks from the pipeline task directory.

Create pipeline tasks.

Edit pipeline tasks, including adding, editing, and deleting components.

Clone pipeline tasks.

Save pipeline tasks.

Delete pipeline tasks.

Deactivate and delete pipeline tasks.

Configure properties for pipeline tasks, including scheduling, channel, and quality monitoring configurations.

Lock pipeline tasks.

Refresh pipeline tasks.

Move pipeline tasks.

Execute

Submit real-time full-database synchronization tasks.

Run pipeline tasks.

Preview pipeline tasks.

Submit pipeline tasks.

Data development

Standardized modeling

Access directory

View directories for dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables.

Filter and search directories for dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables.

View details

View dimension logic table details, including model view, list view, table properties, history, version details, and version comparison.

View fact logic table details, including model view, list view, table properties, history, version details, and version comparison.

View atomic metric details, including model view, list view, table properties, history, version details, and version comparison.

View business qualifier details, including model view, list view, table properties, history, version details, and version comparison.

View derived metric details, including model view, list view, table properties, history, version details, and version comparison.

View summary logic table details, including model view, list view, table properties, history, version details, and version comparison.

Edit

Create dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables.

Edit tables such as dimension logic tables, fact logic tables, and metrics. This includes performing canvas operations, configuring materialization, locking, editing properties, and rolling back versions.

Save dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables.

Delete dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables.

For summary logic tables: manage metrics and create, register, or associate metrics.

Clone atomic metrics and business qualifiers.

Create logic tables from the Data Architecture module.

Execute

Smoke test, submit, deactivate, or deactivate and delete dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables.

Data processing

Access directory

View, filter, and search the code task directory.

View, filter, and search the Resource/Function directory.

View, filter, and search code templates.

View, filter, and search in Table Management.

View, filter, and search sync tasks.

View details

View code task content, properties (read-only), and history (rollback unavailable), and refresh tasks or view logs.

View content, properties, history, and logs for resources and functions, and download them.

View code template information, version information, and reference information.

View table content, properties, and history in Table Management (rollback unavailable).

View sync task content, properties (read-only), and history (rollback unavailable).

Directory permission management

Configure visible directories for offline compute tasks within a project. To use this feature, you must first enable directory permissions in Management Center > System Settings > R&D Platform > Directory Permissions.

Edit

Create folders in the code task directory.

Edit folders in the code task directory.

Delete folders from the code task directory.

Create code tasks.

Edit code tasks, including cloning, renaming, modifying code, saving, formatting, locking, editing properties, and rolling back versions.

Delete code tasks.

Move code tasks.

Create folders in the Resource/Function directory.

Edit folders in the Resource/Function directory.

Delete folders from the Resource/Function directory.

Create resources and functions.

Edit resources and functions.

Roll back resources and functions.

Delete resources and functions.

Move resources and functions.

Create code templates.

Edit code templates. Operations include editing, cloning, renaming, modifying code, saving, and locking.

Delete code templates.

Create tables in Table Management.

Edit tables in Table Management. Operations include editing, renaming, moving, saving, locking, and rolling back versions.

Delete tables in Table Management.

Perform special edit operations for mirror tables, such as batch association and auto-association.

Create sync tasks.

Edit sync tasks. Operations include editing, renaming, moving, modifying the task, saving, and locking.

Delete sync tasks.

Execute

Execute, submit, pre-compile, deactivate, or deactivate and delete code tasks.

Submit resources and functions.

Debug, submit, or deactivate and delete code templates.

Submit, deactivate, or deactivate and delete tables in Table Management.

Submit, deactivate, or deactivate and delete sync tasks.

Ad-hoc query

Access directory

View the ad-hoc query directory.

View details

View ad-hoc query content, assistant, history, and logs.

Edit

Create folders in the ad-hoc query directory.

Edit folders (rename, move) in the ad-hoc query directory.

Delete folders from the ad-hoc query directory.

Create ad-hoc queries.

Edit ad-hoc queries. Operations include editing, renaming, modifying code, saving, formatting, and locking.

Delete ad-hoc queries.

Refresh ad-hoc queries.

Move ad-hoc queries.

Execute

Note

This permission applies to executing compute tasks and ad-hoc queries. Behavior varies by interface: In the UI, this specific permission is required. Via OpenAPI, any execution permission is sufficient.

Execute ad-hoc query code.

Pre-compile ad-hoc query code.

Global search

Global search

Search for resources by using Global Search.

Search for code by using Global Search.

Recycle Bin

Permanently delete

Permanently delete items from the Recycle Bin.

Restore

Restore items from the Recycle Bin.

Project asset permissions

Physical table

Create

Create physical tables.

Query table data

Query data from physical tables and physical views in the project.

Modify table data

Modify data in the project's physical tables.

Modify table structure

Modify the structure of the project's physical tables.

Delete table

Delete the project's physical tables.

Logical table

Query table data

Query data from logical tables (metrics in this project's summary tables) and logical views within the project.

Real-time metatable

Query table data

Query data from real-time metatables.

Modify table data

Modify data in real-time metatables.

Mirror table

Query table data

Query data from mirror tables.

Dataset

Use

Use all datasets within the project.

Publishing and O&M

Publishing module

View details

View the pending objects list and their version history.

View the publishing list, publishing details, and failure logs.

Publish (prod only)

Publish objects from the pending objects list.

Republish items from the publishing list.

Remove

Remove objects from the pending objects list.

O&M

Access directory

View exception statistics and dashboards.

View lists of scheduled, manual, and real-time tasks.

Search and filter scheduled, manual, and real-time tasks.

View lists of scheduled, manual, real-time, and backfill data instances.

Search and filter scheduled, manual, real-time, and backfill data instances.

View basic information

For scheduled, manual, and real-time tasks: view the DAG, node details, and operation logs.

For scheduled, manual, and real-time tasks: view task instances and backfill data instances.

For scheduled, manual, and real-time tasks: edit development nodes and view production nodes.

For scheduled tasks on logic tables: perform batch operations on fields, view production lineage, and view consumption lineage.

For scheduled, manual, and real-time tasks: expand parent and child nodes.

For scheduled, manual, real-time, and backfill data instances: view the DAG, node details, and operation logs.

For scheduled, manual, real-time, and backfill data instances: edit development nodes and view production nodes.

For scheduled, manual, real-time, and backfill data instances: expand parent and child nodes.

For scheduled, manual, real-time, and backfill data instances: view tasks.

For scheduled instances on logic tables: perform batch operations on fields, view production lineage, and view consumption lineage.

View details (with code)

View node code for scheduled, manual, and real-time tasks.

For scheduled tasks on logic tables: view materialization code.

For scheduled, manual, real-time, and backfill data instances: view node code, run logs, and run diagnostics.

For scheduled instances on logic tables: view materialization code.

O&M operations

Backfill data for scheduled, manual, and real-time tasks.

Change the owner of scheduled, manual, and real-time tasks.

Pause or resume scheduled, manual, and real-time tasks.

Configure monitoring alerts for scheduled, manual, and real-time tasks.

For scheduled, manual, real-time, and backfill data instances: rerun, rerun downstream, set to success and continue scheduling, terminate, or force rerun.

For scheduled, manual, real-time, and backfill data instances: remove upstream dependencies, pause, or resume.

Resource configuration

Modify the priority of scheduled, manual, and real-time tasks.

Modify the resource queue for scheduled, manual, and real-time tasks.

Modify the configuration of real-time tasks.

Task monitoring configuration

Access directory

View directories for offline and real-time monitoring.

Filter offline and real-time monitoring tasks.

Create

Create new offline or real-time monitoring rules.

Edit

Edit, enable, or disable monitoring configurations.

Modify recipients.

Delete monitoring configurations.