This topic describes the permissions for global and project roles.
Global role permissions
Super X
Feature | Actions | Description |
X-Analytics | View | View the X-Analytics page and ask questions using natural language. |
X-Data Engineering | View | View X-Data Engineering. |
Intelligent App Management-Model Configuration & Intelligent App | Manage | Enable, disable, and edit assistants. |
Configure the large models used by intelligent assistants. | ||
Intelligent App Management-Operations Management | View Credit consumption statistics | View statistics on Credit consumption. |
Intelligent App Management-Intelligent Analysis Collection | Create | Create Intelligent Analysis Collections and collection groups. |
Manage | Edit and delete Intelligent Analysis Collections and collection groups. | |
Enterprise Knowledge Base | View | View authorized knowledge bases and their knowledge. |
Manage | Create, edit, and delete knowledge bases. | |
Create, edit, and delete knowledge within knowledge bases. |
Data development
Feature area | Global permission point | Description |
Development | ||
Development | View | Lets you view the development module. |
Modify the default cluster for the resource dashboard | Lets you modify the default display cluster on the O&M > Resource Scheduling Dashboard. | |
Tag | ||
Asset marketplace | View | Grants view-only access to the asset marketplace. |
Lets you view the asset list in the public marketplace. | ||
Lets you view asset details and perform group analysis. (Permitted actions depend on asset visibility. All assets in the public marketplace are accessible. Assets in the private marketplace are accessible only if they are visible.) | ||
Workbench | View | Grants view-only access to the workbench. (Access is determined by project roles. Users can view the workbench if added to a tag project, even without this global permission.) |
Asset application - Tag offline service | View | Lets you view the task list for tag offline services. |
Lets you view the details of tag offline service tasks. | ||
Lets you create a tag offline service. (Anyone can initiate this action, but it only succeeds if you have permission for the target application.) | ||
Asset application - Group offline service | View | Lets you view the offline service task list across all your permitted applications. |
Lets you view the details of group offline service tasks. | ||
Lets you create a group offline service. (Anyone can initiate this action, but it only succeeds if you have permission for the target application.) | ||
Asset application - Group paginated query | View | Lets you view the task list for group paginated queries across all your permitted applications. |
Lets you view the details of group paginated query tasks. | ||
Lets you create a group paginated query. (Anyone can initiate this action, but it only succeeds if you have permission for the target application.) | ||
Asset application - User profile service | View | Lets you view the list of user profiles across all your permitted applications. |
Lets you view user profile details. | ||
Lets you create a user profile. (Anyone can initiate this action, but it only succeeds if you have permission for the target application.) | ||
Asset application - Application management | View | Lets you create an application. |
Event center - Attribute management | View | Lets you view the attribute list. |
Lets you view attribute details. | ||
Manage | Lets you create an attribute. | |
Lets you edit an attribute. | ||
Lets you delete an attribute. | ||
Event center - Event management | View | Lets you view the event list. |
Lets you view event details. | ||
Manage | Lets you create an event. | |
Lets you edit an event. | ||
Lets you delete an event. | ||
Event center - Category management | View | Lets you view the category list. |
Manage | Lets you create a category. | |
Lets you edit a category. | ||
Lets you delete a category. | ||
Asset governance
Feature | Actions | Description |
Governance | ||
Asset inventory | View | Search for assets. |
View asset details. | ||
Initiate data profiling | Initiate data profiling for data tables (automatic/manual). | |
View data profiling records and reports for data tables. | ||
Perform operations on data profiling records for data tables (for example, view logs and terminate runs). | ||
Data standard | ||
Data standard/Standard set | View | View the standard sets you have joined. |
View the list of batch operation records. | ||
View the standard sets you have joined. | ||
Manage data standards | Create a data standard. | |
Edit a data standard. | ||
Clone a data standard. | ||
Submit a data standard for release. | ||
Take a data standard offline. | ||
Delete a data standard. | ||
Edit associated standards for a data standard. | ||
Edit associated documents for a data standard. | ||
Batch import data standards. This action requires the "Standard template - Batch import standards" permission. | ||
Batch export data standards. This action requires the "Standard template - Batch export standards" permission. | ||
View details of batch operations. This action requires the "Standard template - View import records" permission. | ||
Create a standard within a standard set. | ||
Manage standard set catalog | Create a standard set catalog. | |
Edit a standard set catalog. | ||
Delete a standard set catalog. | ||
Manage standard set | View all standard sets. | |
Create a standard set. | ||
Edit a standard set. | ||
Batch export standards from a standard set. | ||
Clone a standard set. | ||
Delete a standard set. | ||
Standard mapping rule | View | View the list of standard mapping rules. |
View the list of execution records for standard mapping rules. | ||
View a mapping rule. | ||
View execution records for a mapping rule. You can only view records for mapping rules that you have permission to access. | ||
View standard mapping details from an execution record. | ||
Manage | Create a standard mapping rule. | |
Edit a standard mapping rule. | ||
Change the effective status of a mapping rule. | ||
Manually run a mapping rule as a temporary task. | ||
Delete a standard mapping rule. | ||
View execution logs for a mapping rule. | ||
View execution logs from an execution record. | ||
Mapping | View | View global mappings (valid and invalid). |
View the standard mapping evaluation configuration. | ||
View standard mapping evaluation records. | ||
View mapping details (valid and invalid). | ||
View the details of valid mappings. | ||
View standard mapping evaluation results for valid mappings. | ||
View the list of batch import records for mappings (valid and invalid). | ||
Batch import mappings (valid and invalid). | ||
Batch export mappings (valid and invalid). | ||
Manage | Edit the standard mapping evaluation configuration. | |
View execution logs from a standard mapping evaluation record. | ||
View configured data standard quality monitoring rules for valid mappings. | ||
Create data standard quality monitoring rules for valid mappings. | ||
Edit configured data standard quality monitoring rules for valid mappings. | ||
Delete configured data standard quality monitoring rules for valid mappings. | ||
Set a valid mapping to invalid. | ||
Configure quality monitoring for a valid mapping. | ||
Remove a valid mapping. | ||
View batch import record details for mappings (valid and invalid). | ||
Revert an invalid mapping. | ||
Standard mapping evaluation details | View | View public standard mapping evaluation details (standard view and asset object view). |
View mapping details from the standard mapping evaluation details page (standard view and asset object details). | ||
Standard mapping execution records | View | View all execution records for standard mappings. |
View mapping details and execution logs from a standard mapping execution record. | ||
Code table | View | View the code table list. |
View code table details. | ||
View the list of batch import records for code tables. | ||
View the list of batch export records for code tables. | ||
View code table references. | ||
View the code table catalog. | ||
Batch export code tables. | ||
Manage code table catalog | Create a code table catalog. | |
Edit a code table catalog. | ||
Delete a code table catalog. | ||
Manage code table | Create a code table. | |
Edit a code table. | ||
Batch import code tables. | ||
View batch import record details for code tables. | ||
Download batch export files for code tables. | ||
Delete a code table. | ||
Root term | View | View the root term list. |
View the list of batch operation records for root terms. | ||
Batch export root terms. | ||
Manage | Create a root term. | |
Batch import root terms. | ||
Edit a root term. | ||
Delete a root term. | ||
View batch operation record details for root terms. | ||
Standard document | View | View the standard document list. |
Preview standard documents online (PDF only). | ||
View associated standards for a standard document. | ||
View the standard document catalog. | ||
Manage standard document catalog | Create a standard document catalog. | |
Edit a standard document catalog. | ||
Delete a standard document catalog. | ||
Manage standard document | Upload a standard document. | |
Edit a standard document. | ||
Move a standard document. | ||
Download a standard document. | ||
Delete a standard document. | ||
Common standard attribute | View | View the list of common standard attributes. |
View details of a system attribute. | ||
Manage | Create a custom attribute. | |
View details of a custom attribute. | ||
Edit a custom attribute. | ||
Clone a custom attribute. | ||
Delete a custom attribute. | ||
Standard template | View | View the standard template list. |
View standard template details. | ||
Manage | Create a standard template. | |
Edit a standard template. | ||
Delete a standard template. | ||
Identification feature | View | View the list of identification features. |
View identification feature details. | ||
Manage | Configure feature scanning. Note This is a separate permission from the Rule run configuration permission in Asset Security. Either of these permissions allows you to modify feature scanning configurations. | |
Create an identification feature. | ||
Edit an identification feature. | ||
Clone an identification feature. | ||
Delete an identification feature. | ||
Quality | ||
Quality dashboard | View | View the quality dashboard. |
Validation record | View | View validation records for the current account. |
View validation records for joined projects. | ||
View validation details. | ||
View rule validation details. | ||
View execution logs. | ||
View a quality report. | ||
Manage | Download exception data from validation details. | |
Pause a validation run. | ||
Quality rule | View | View quality rules for the current account. |
View quality rules for joined projects. | ||
View quality rule details. | ||
View a quality report. | ||
View the rule configuration list. | ||
View rule configuration details. | ||
View the scheduling configuration list. | ||
View the alert configuration list. | ||
View the exception archiving list. | ||
View a quality report. | ||
View rule validation details from a quality report. | ||
View execution logs from a quality report. | ||
View the permissions list for a quality rule. | ||
Manage | Add monitored objects (all resources). | |
Add a quality rule. | ||
Run a quality rule. | ||
Manage quality owners. | ||
Edit quality score weights. | ||
Delete a quality rule. | ||
Enable or disable a quality rule. | ||
Perform batch operations (such as run, manage quality owners, enable, disable, edit quality score weights, delete, and manage permissions). | ||
Modify the quality score weight from the quality rule details page. | ||
Create a quality rule from the quality rule details page. | ||
Clone a rule configuration. | ||
Edit a rule configuration. | ||
Test run a rule configuration. | ||
Run a rule configuration. | ||
Configure scheduling for a rule. | ||
Configure the quality score for a rule. | ||
Delete a rule configuration. | ||
Change the effective status of a rule configuration. | ||
Edit, clone, or delete a scheduling configuration. | ||
Modify an alert configuration. | ||
Add an exception archive table. | ||
Set an exception archive table as default or delete it. | ||
Edit permissions for a quality rule. | ||
Download exception data from a validation record. | ||
Pause a validation record. | ||
In the governance workbench, perform actions such as viewing details, initiating rectification, ignoring, unignoring, whitelisting, notifying owners, re-validating, and viewing operation records. | ||
Perform actions in the rectification process. | ||
Perform actions in the governance whitelist. | ||
Perform actions in the knowledge base (view, create, edit, delete). | ||
Rule template | View | View the rule template list. |
Manage | Create a rule template. | |
View references for a rule template. | ||
Edit a rule template. | ||
Add a quality rule. | ||
View template details. | ||
Clone a rule template. | ||
Transfer a rule template. | ||
Delete a rule template. | ||
Data source management | View | View the data source list. |
Manage | Set a rate limit. | |
Issue list | View | View the issue list for the current account. |
View the issue list for joined projects. | ||
Manage | Perform actions on issues (such as view details, initiate rectification, ignore, unignore, whitelist, notify owner, re-validate, and view operation records). | |
Rectification process | View | View the rectification process for the current account. |
Manage | Perform actions in the rectification process (such as view details, ignore, unignore, notify owner, re-validate, and link to knowledge base). | |
Knowledge base | View | View the knowledge base. |
Manage | Perform actions in the knowledge base (create, link, edit, delete). | |
Governance whitelist | View | View the governance whitelist for the current account. |
Manage | Perform actions in the governance whitelist (edit and delete). | |
Asset security | ||
Identification result | View | View all identification results. |
View upload history for identification results. | ||
View identification details. | ||
Manage | Upload identification results from an Excel file. | |
Manually add an identification result. | ||
Lock or unlock data classification, or change the identification mode for a result. | ||
Identification rule | View | View all identification rules. |
View the classification scan scope. | ||
View identification rule details. | ||
Manage | Create an identification rule. | |
Scan with a manual rule. | ||
Configure a rule run. | ||
Configure automatic inheritance for an identification rule. | ||
Enable or disable automatic identification. | ||
Reset, edit, copy, transfer, delete, or test an identification rule. | ||
Identification run record | View | View all identification run records. |
Manage | Terminate an identification run. | |
View task identification details from a run record. | ||
Data masking rule | View | View all data masking rules (dynamic masking rules, whitelists, static masking). |
View masking algorithms or masking whitelists. | ||
Manage | View or modify the default data masking policy. | |
Create, edit, transfer, or delete dynamic masking rules, or change their effective status. | ||
Create, edit, clone, or delete a dynamic masking whitelist, or change its effective status. | ||
Key management | View | View all key lists. |
View references for a key. | ||
Register key | Register a key. | |
Manage | Manage key permissions. | |
Edit, transfer, or delete a key. | ||
Data classification | View | View all data classifications. |
View all identification features for a data classification. | ||
View an identification feature. | ||
View the data classification model. | ||
View model details for a data classification. | ||
View the number of effective fields for a data classification. | ||
Manage | Create, change the effective status of, edit, move, or delete a data classification. | |
Configure data masking for a data classification. | ||
Specify, enable, or disable the data sensitivity level for a data classification. | ||
Data sensitivity level | View | View all data sensitivity levels. |
Manage | Create, edit, or delete a data sensitivity level. | |
Identification feature | View | View the list of identification features. |
View identification feature details. | ||
Manage | Create an identification feature. | |
Edit an identification feature. | ||
Clone an identification feature. | ||
Delete an identification feature. | ||
Security algorithm | View | View all data masking algorithms. |
Manage | Test a data masking algorithm. | |
Project security policy | View | View the global project security policy. |
View details | View project security policy details. | |
Manage | Edit the project security policy. | |
Resource governance | ||
Resource analysis | View | View the resource analysis page. |
Governance analysis | View | View the governance analysis page. |
Governance effectiveness | View | View the governance effectiveness page. |
My governance | View | View the my governance page. |
Project governance | View | View the project governance page. |
Governance item management | View | View the governance item management page. |
Push management | View | View the push management page. |
Task management | View | View the task management page. |
Recycle bin | View | View the recycle bin. |
Metadata | ||
Metadata collection | Manage | View the collection task list. |
Create a collection task. | ||
Edit a collection task. | ||
Delete a collection task. | ||
View the metadata inventory. | ||
View metadata instances. | ||
Set a collection task to active or inactive. | ||
Run a collection task manually or as a temporary task. | ||
Retry updating a collection task. | ||
View the collection instance list. | ||
View the metadata change overview. | ||
View run logs. | ||
View a collection task. | ||
Rerun a collection instance. | ||
Terminate a collection instance. | ||
Metadata inventory | View | View the list of source system metadata. |
View source system metadata details. | ||
Data profiling | Profiling and analysis | Configure data profiling. |
Source system | Manage | View the source system list. |
Create a source system. | ||
Edit a source system. | ||
Delete a source system. | ||
Sampling configuration | View | View the sampling configuration. |
Manage | Edit the sampling configuration. | |
Other features | Metadata management | Register and delete external lineage using the OpenGauss API. |
Asset | ||
Overview | View | View the asset overview. |
Catalog | Display menu | Displays the asset catalog menu. If this permission is not granted, the menu is hidden, but the page remains accessible using its URL. You can use this with custom menus to redesign the asset page. For more information, see Rebuild the asset page by using custom menus. |
Table | View and use the corresponding tab in the asset catalog. For example, if only the Table permission is granted, only the Table tab is displayed in the asset catalog, and other tabs are hidden. Note Before upgrading Dataphin to v6.3, if the "Asset catalog - View" permission was granted, all permissions under "Asset - Catalog" are automatically granted after the upgrade. Otherwise, none are granted. | |
Metric | ||
API | ||
Dashboard | ||
Catalog management - Catalog planning | View | View all topics and catalogs. |
Manage | Create asset topics and catalogs. | |
Edit asset topics and catalogs. | ||
Delete asset topics and catalogs. | ||
Catalog management - Listing management | View | View the listing management and menu pages. |
Manage | Edit an asset. | |
List an asset. | ||
Delist an asset. | ||
Postpone the listing of an asset. | ||
Set maintenance permissions. | ||
Standard | View | View standard assets. |
Asset consumption | ||
My consumption - Available to me | View | View the list of available assets. |
| ||
Analyze in Notebook. | ||
My consumption - My BI analysis | View | View the list of my BI analyses. |
Edit dashboards or self-service data retrievals. | ||
View dashboards or self-service data retrievals. | ||
Consumption configuration - Consumption channels | Manage | Create, edit, or delete consumption channels. |
Asset analysis
Level-1 permission | Global permission | Permission |
Analytics | ||
notebook | View | View directory |
View notebook | ||
Create directory | ||
Edit directory | ||
Delete directory | ||
Create notebook | ||
Edit notebook | ||
Save notebook | ||
Delete notebook | ||
Share notebook | ||
Unshare notebook | ||
Run notebook | ||
SQL query | View | View directory |
View SQL | ||
Create directory | ||
Edit directory | ||
Delete directory | ||
Create SQL | ||
Edit SQL | ||
Save SQL | ||
Delete SQL | ||
Share SQL | ||
Unshare SQL | ||
Run SQL | ||
manual table | View | View directory |
View manual table | ||
Create manual table | ||
Edit data - manual table | ||
Edit table structure - manual table | ||
Save - manual table | ||
Publish - manual table | ||
Download - manual table | ||
Share - manual table | ||
Unshare - manual table | ||
Delete table - manual table | ||
Transfer owner - manual table | ||
Services | ||
Marketplace | View | API service - View API service list |
API service - View API documentation | ||
API service - Download API documentation | ||
API service - Apply for API | ||
Dataphin data source service - View Dataphin data source service list | ||
Dataphin data source service - View Dataphin data source documentation | ||
Dataphin data source service - Apply for Dataphin data source | ||
Invocation | View | Authorized API service - View authorized API list |
Authorized API service - Apply for API | ||
Authorized API service - Debug API | ||
Authorized API service - Revoke API permission | ||
Authorized Dataphin data source - View authorized Dataphin data source list | ||
Authorized Dataphin data source - Apply for Dataphin data source | ||
Authorized Dataphin data source - Revoke Dataphin data source permission | ||
Application management - View application list | ||
Application management - Create application | ||
Application management - Edit application | ||
Application management - Delete application | ||
Application management - Apply for application | ||
Application management - Show AppSecret | ||
Application management - Copy AppSecret | ||
Application management - Reset AppSecret | ||
Application management - Transfer application owner | ||
Usage example - View API usage example | ||
Usage example - Edit API usage example | ||
Usage example - Download SDK | ||
Usage example - View Dataphin data source usage example | ||
Usage example - Edit Dataphin data source usage example | ||
Usage example - Download JDBC JAR | ||
Development | View | API - View my APIs |
API - Create API | ||
API - Create API: Select service unit drop-down | ||
API - Create API: Select Dataphin logical table | ||
API - Create API: Select Dataphin logical table - business module | ||
API - Create API: Select Dataphin logical table - business module - logical table | ||
API - Edit API | ||
API - View API details | ||
API - Test API | ||
API - Publish API | ||
API - Delete API | ||
API - Transfer API owner | ||
service unit - View service unit list | ||
service unit - Create service unit | ||
service unit - Create service unit: Service unit name | ||
service unit - Create service unit: Select data source | ||
service unit - Edit service unit | ||
service unit - View service unit details | ||
service unit - Publish service unit | ||
service unit - Delete service unit | ||
service unit - Transfer service unit owner | ||
metadata management - View authorized metadata list | ||
metadata management - Create metadata | ||
metadata management - Edit metadata | ||
metadata management - Delete metadata | ||
Dataphin data source - View my Dataphin data sources | ||
Dataphin data source - Create Dataphin data source | ||
Dataphin data source - Edit Dataphin data source | ||
Dataphin data source - View Dataphin data source details | ||
Dataphin data source - Delete Dataphin data source | ||
Dataphin data source - Data source acceleration | ||
Dataphin data source - Transfer Dataphin data source owner | ||
Operations | View | Operations monitoring - API call statistics |
Operations monitoring - API rate limiting | ||
Operations monitoring - API alerts | ||
API operations - API rate limiting configuration | ||
API operations - API alert configuration | ||
Service call log query - API call log query - View API call logs | ||
Service call log query - Dataphin data source usage log query - View Dataphin data source service call logs | ||
Management | View | project management - View project list |
project management - Create project | ||
project management - Edit project | ||
project management - Delete project | ||
project management - Member management | ||
project management - View group management | ||
project management - Group management - Create service unit group | ||
project management - Group management - Edit service unit group | ||
project management - Group management - Delete service unit group | ||
project management - Group management - Create application group | ||
project management - Group management - Edit application group | ||
project management - Group management - Delete application group | ||
project management - Group management - Create data source group | ||
project management - Group management - Edit data source group | ||
project management - Group management - Delete data source group | ||
system configuration - View configurations | ||
system configuration - Modify configurations | ||
network configuration - View network configurations | ||
network configuration - Enable and disable public subdomain (public cloud standalone deployment) | ||
network configuration - Enable and disable internal VPC domain (public cloud standalone deployment) | ||
network configuration - Bind independent domain (public cloud standalone deployment) | ||
network configuration - Enable and disable subdomain (private cloud) | ||
network configuration - Show and hide invocation IP address (on-premises deployment) | ||
network configuration - Bind independent domain (on-premises deployment) | ||
Usage example - View API usage example | ||
Usage example - Edit API usage example | ||
Usage example - Download SDK | ||
Usage example - View Dataphin data source usage example | ||
Usage example - Edit Dataphin data source usage example | ||
Usage example - Download JDBC JAR | ||
More
Feature | Action | Description |
Planning | ||
Data architecture | View | Data architecture - View global data board list |
Data architecture - View data board details | ||
Data architecture - View associated projects | ||
Data architecture - data board - business entity - View version information | ||
Create | Data architecture - Create data board | |
Data architecture - Create subject domain | ||
Data architecture - Create business entity | ||
Data architecture - data board - subject domain management - Create subject domain | ||
Data architecture - data board - subject domain management - Create sub-domain | ||
Data architecture - data board - subject domain management - Create business entity | ||
Data architecture - data board - business entity - Create business entity | ||
Edit | Data architecture - Edit data board | |
Data architecture - data board - subject domain management - Edit subject domain | ||
Data architecture - data board - business entity - Publish/Unpublish | ||
Data architecture - data board - business entity - Create table | ||
Data architecture - data board - business entity - Edit | ||
Delete | Data architecture - Delete data board | |
Data architecture - data board - subject domain management - Delete subject domain | ||
Data architecture - data board - business entity - Unpublish and delete | ||
Common definitions | View | Common definitions - Statistical periods - View all statistical periods |
Common definitions - Global variables - View global variables | ||
Common definitions - Public calendars - View public calendars | ||
Common definitions - Global variables - Request permissions | ||
Common definitions - Global variables - View dependencies | ||
Common definitions - Global variables - View version history | ||
Common definitions - Public calendars - View calendar references | ||
Common definitions - Public calendars - View calendar references - Referenced tags - View references | ||
Common definitions - Public calendars - View calendar references - Referenced tags - View tag details | ||
Common definitions - Public calendars - View calendar references - Referenced date types - View details | ||
Common definitions - Public calendars - View calendar references - Referenced calendars - View details | ||
Common definitions - Offline scheduling templates - View details | ||
Manage | Common definitions - Statistical periods - Create statistical period | |
Common definitions - Statistical periods - Edit | ||
Common definitions - Statistical periods - Delete | ||
Common definitions - Global variables - View dependencies - View object | ||
Common definitions - Global variables - View version history - Compare versions | ||
Common definitions - Global variables - View version history - Roll back version | ||
Common definitions - Global variables - Create variable group | ||
Common definitions - Global variables - Create global variable | ||
Common definitions - Global variables - Edit/Delete variable group | ||
Common definitions - Global variables - Edit/Delete variable | ||
Common definitions - Public calendars - Create public calendar | ||
Common definitions - Public calendars - View calendar references - Referenced tags - Edit tag | ||
Common definitions - Public calendars - View calendar references - Referenced tags - Delete tag | ||
Common definitions - Public calendars - Create tag | ||
Common definitions - Public calendars - Edit/Delete public calendar | ||
Common definitions - Offline scheduling templates - Create offline scheduling template | ||
Common definitions - Offline scheduling templates - Edit/Delete offline scheduling template | ||
Attribute management | View Quality, API, Table, Metric, and dashboard attributes | Attribute management - View |
Attribute management - Quality, API, Table, Metric, and dashboard - View details | ||
Manage Quality, API, Table, Metric, and dashboard attributes | Attribute management - Quality, API, Table, Metric, and dashboard - Create attribute | |
Attribute management - Quality, API, Table, Metric, and dashboard - Edit | ||
Attribute management - Quality, API, Table, Metric, and dashboard - Clone | ||
Attribute management - Quality, API, Table, Metric, and dashboard - Enable/Disable | ||
Attribute management - Quality, API, Table, Metric, and dashboard - Delete | ||
View tag attributes | Attribute management - View | |
Attribute management - Tag - View details | ||
Manage tag attributes | Attribute management - Tag - Create attribute | |
Attribute management - Tag - Edit | ||
Attribute management - Tag - Clone | ||
Attribute management - Tag - Delete | ||
Attribute management - Tag - Enable/Disable | ||
Tag architecture | View | Tag architecture - View |
Manage | Tag architecture - Asset market management - Add/Edit/Set category/Delete market | |
Tag architecture - Entity management - Add/Edit/Delete entity | ||
Tag architecture - ID management - Add/Edit/Delete ID | ||
Project management | View | Project management - View my projects and all projects |
Project management - View details of all projects (including configuration and information settings) | ||
Project management - Member management - View all members in each project | ||
Create | Project management - Create project - General/Tag project | |
Edit | Project management - Member management - Edit members in each project | |
Delete | Project management - Delete any project | |
Compute source | View | Compute source - View compute source list |
Compute source - Test connection | ||
Create | Compute source - Add compute source | |
Edit | Compute source - Edit/Transfer ownership/Delete | |
Delete | Compute source - Delete | |
Hadoop cluster Databricks cluster Amazon EMR cluster SelectDB cluster Doris cluster AnalyticDB for PostgreSQL cluster | View | Compute source - Manage clusters - View details of each cluster (view, view version history, and compare versions) |
Manage | Compute source - Manage clusters (create, edit, clone, and delete clusters) | |
Acceleration source management | View | Acceleration source - View acceleration source list Acceleration source - Test connection |
Create | Acceleration source - Add acceleration source | |
Edit | Acceleration source - Edit | |
Delete | Acceleration source - Delete | |
Admin center | ||
Member management | View | View |
Member management - View list of all members | ||
Global role management - View all global roles | ||
Global role management - View role details | ||
Project role management - View all project roles | ||
Project role management - View role details | ||
Project role management - View project references | ||
User group management - View my user groups and all user groups | ||
Member management - My groups - View user group details and permissions | ||
Member management - Member management | Manage tenant members | Member management - View contact information for all members |
Member management - Add member | ||
Member management - Automatically add members (SSO) | ||
Member management - View ownership transfer history | ||
Member management - Sync with account system (SSO) | ||
Member management - Edit/Enable/Disable/Transfer ownership/Add to user group/Delete | ||
Member management - Create account/Batch create (self-created) | ||
Member management - Reset password (self-created account) (The password of a super admin account cannot be reset.) | ||
Member management - Project role management | Manage project roles | Project role management - Create, clone, edit, enable/disable, delete, or replace roles |
Member management - User group | Manage user groups | User group management - Create and clone user groups |
Member management - Manage members, and edit, delete, or enable/disable user groups | ||
Permission management | View | View permission management |
Permission management - Table management | Manage table permissions | Allows granting permissions on all tables when creating new roles. This permission can only be assigned by a super admin. |
Authorize all tables | Permission management - Table permissions - Batch grant/revoke | |
Permission management - Permission audit | Audit permissions | Permission audit - Asset permission audit - View/Export |
Permission audit - Asset operation audit - View/Export | ||
Data source management | View | View data sources |
Data source management - data source - View all data sources/Test connection | ||
Data source management - Custom source types - View all source types | ||
View connection information | Data source management - data source - View connection information | |
Data source management - data source | Create | Data source management - data source - Create data source |
Edit | Data source management - data source - Edit data source | |
Data source management - data source - View connection information | ||
Data source management - data source - Edit/Transfer ownership | ||
Data source management - data source - Manage tags/Source systems | ||
Delete | Data source management - data source - Delete data source | |
Data source management - data source - Delete production and development data sources | ||
Data source management - Custom source type | Manage | Data source management - Custom source types - Add custom source type |
Data source management - Custom source types - Transfer/Edit | ||
Data source management - Custom source types - Delete custom source type | ||
System settings | View | View system settings |
System settings - Compute settings - View/Validate | ||
System settings - Resource settings - View resource settings list | ||
System settings - Resource settings - Session cluster - Go to Flink UI/View start/stop logs | ||
System settings - Message channels - View all channel configurations | ||
System settings - Intelligent engine - View | ||
System settings - Cross-platform migration - View | ||
System settings - Approval templates - View | ||
System settings - Global tag settings - View | ||
System settings - Analysis platform settings - View | ||
System settings - Development platform settings - View | ||
System settings - Logon security settings - View | ||
System settings - Basic settings | Manage | System settings - Basic settings - Manage |
System settings - Compute settings | Manage | System settings - Compute settings - Edit |
System settings - Resource settings | Manage | System settings - Resource settings - Resource group configuration - Create, edit, enable/disable, or delete custom resource groups |
System settings - Resource settings - Resource group configuration - Change the tenant's default resource group | ||
System settings - Resource settings - Session cluster - Create, enable/disable, edit, or delete | ||
System settings - Message channels | Manage | System settings - Message channels - Edit message channel |
System settings - Style configuration | Manage | System settings - Style configuration - Edit style configuration |
System settings - Intelligent engine | Manage | System settings - Intelligent engine - Edit |
System settings - Cross-platform migration | Manage | System settings - Cross-platform migration - Edit |
System settings - Approval templates | Manage | System settings - Approval templates - Add/Edit/Delete |
System settings - Python third-party packages | Manage | System settings - Python third-party packages - Install Python module |
System settings - Tag platform settings | Manage | System settings - Tag platform settings - Edit |
System settings - Analysis platform settings | Manage | System settings - Analysis platform settings - Edit |
System settings - Development platform settings | Manage | System settings - Development platform settings - Edit |
System settings - Logon security settings | Manage | System settings - Logon security settings - Edit |
Standard settings | View | View standard settings |
Standard settings - Naming conventions - View | ||
Standard settings - Security settings - View | ||
Standard settings - Data download - View | ||
Standard settings - Data permissions - View | ||
Standard settings - Change policy - View | ||
Standard settings - Change rules - View | ||
Standard settings - Naming conventions | Manage | Standard settings - Naming conventions - Edit |
Standard settings - Security settings | Manage | Standard settings - Security settings - Edit |
Standard settings - Data download | Manage | Standard settings - Data download - Edit |
Standard settings - Data permissions | Manage | Standard settings - Data permissions - Edit |
Standard settings - Change policy | Manage | Standard settings - Change policy - Edit |
Standard settings - Change rules | Manage | Standard settings - Change rules - Edit |
Standard settings - Filename conventions | Manage | Standard settings - Filename conventions - Edit |
Cross-tenant publishing | View | View cross-tenant publishing |
Cross-tenant publishing - View publishing settings | ||
Enable cross-tenant publishing mode | Maintenance and Upgrade - Cross-tenant publishing
| |
My workspace | ||
Notification center | Manage notification settings | Notification settings - View and edit |
Alert center | View | Alert center - View |
Alert center - Alert events - View all alert events | ||
Alert center - Push history - View all push history | ||
Alert center - Alert events - Address alert | ||
Alert center - Push history - View alert content | ||
Alert center - Message templates - View | ||
Alert center - on-call schedule - View on-call schedules | ||
Alert center - on-call schedule - View details of on-call schedules | ||
Manage | Alert center - Alert events - Mute | |
Alert center - Message templates - Edit | ||
Alert center - Create/Edit/Delete on-call schedule | ||
Project role permissions
Feature | Action | Description |
Project management | ||
Member management | Edit | Add, delete, or modify roles for project members. |
Configure project information | View | View project information settings. |
Edit | Edit project information settings. | |
Call JDBC Driver | Call JDBC Driver | Execute SQL queries in the project using the JDBC Driver. |
Project quality management | Quality rule management | Create monitored objects from objects within a project, and manage monitoring rules, validation records, and the issue list. |
Planning | ||
Business entity | Edit | Create, edit, delete, and deactivate business entities. |
Data integration | ||
Data integration | Access directory | View, search, and filter the real-time integration directory. |
View, search, and filter the pipeline task directory. | ||
View details | View real-time integration details, including the canvas, operators, properties, and history. | |
View pipeline task details, including the canvas, operators, properties, and history. | ||
Edit | Create folders in the real-time integration directory. | |
Edit, rename, or delete folders in the real-time integration directory. | ||
Create real-time full-database synchronization tasks. | ||
Move real-time full-database synchronization tasks. | ||
Deactivate real-time full-database synchronization tasks. | ||
Edit real-time full-database synchronization tasks, including data source, sync settings, target table configuration, and DDL handling policy. | ||
Change the owner of a real-time full-database synchronization task in its properties. | ||
Configure resources for real-time full-database synchronization tasks. | ||
Lock real-time full-database synchronization tasks. | ||
Save real-time full-database synchronization tasks. | ||
Deactivate and delete real-time full-database synchronization tasks. | ||
Create folders in the pipeline task directory. | ||
Edit, rename, or delete folders in the pipeline task directory. | ||
Upload files to the pipeline task directory. | ||
Delete tasks from the pipeline task directory. | ||
Create pipeline tasks. | ||
Edit pipeline tasks, including adding, editing, and deleting components. | ||
Clone pipeline tasks. | ||
Save pipeline tasks. | ||
Delete pipeline tasks. | ||
Deactivate and delete pipeline tasks. | ||
Configure properties for pipeline tasks, including scheduling, channel, and quality monitoring configurations. | ||
Lock pipeline tasks. | ||
Refresh pipeline tasks. | ||
Move pipeline tasks. | ||
Execute | Submit real-time full-database synchronization tasks. | |
Run pipeline tasks. | ||
Preview pipeline tasks. | ||
Submit pipeline tasks. | ||
Data development | ||
Standardized modeling | Access directory | View directories for dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables. |
Filter and search directories for dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables. | ||
View details | View dimension logic table details, including model view, list view, table properties, history, version details, and version comparison. | |
View fact logic table details, including model view, list view, table properties, history, version details, and version comparison. | ||
View atomic metric details, including model view, list view, table properties, history, version details, and version comparison. | ||
View business qualifier details, including model view, list view, table properties, history, version details, and version comparison. | ||
View derived metric details, including model view, list view, table properties, history, version details, and version comparison. | ||
View summary logic table details, including model view, list view, table properties, history, version details, and version comparison. | ||
Edit | Create dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables. | |
Edit tables such as dimension logic tables, fact logic tables, and metrics. This includes performing canvas operations, configuring materialization, locking, editing properties, and rolling back versions. | ||
Save dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables. | ||
Delete dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables. | ||
For summary logic tables: manage metrics and create, register, or associate metrics. | ||
Clone atomic metrics and business qualifiers. | ||
Create logic tables from the Data Architecture module. | ||
Execute | Smoke test, submit, deactivate, or deactivate and delete dimension logic tables, fact logic tables, atomic metrics, business qualifiers, metrics, and summary logic tables. | |
Data processing | Access directory | View, filter, and search the code task directory. |
View, filter, and search the Resource/Function directory. | ||
View, filter, and search code templates. | ||
View, filter, and search in Table Management. | ||
View, filter, and search sync tasks. | ||
View details | View code task content, properties (read-only), and history (rollback unavailable), and refresh tasks or view logs. | |
View content, properties, history, and logs for resources and functions, and download them. | ||
View code template information, version information, and reference information. | ||
View table content, properties, and history in Table Management (rollback unavailable). | ||
View sync task content, properties (read-only), and history (rollback unavailable). | ||
Directory permission management | Configure visible directories for offline compute tasks within a project. To use this feature, you must first enable directory permissions in Management Center > System Settings > R&D Platform > Directory Permissions. | |
Edit | Create folders in the code task directory. | |
Edit folders in the code task directory. | ||
Delete folders from the code task directory. | ||
Create code tasks. | ||
Edit code tasks, including cloning, renaming, modifying code, saving, formatting, locking, editing properties, and rolling back versions. | ||
Delete code tasks. | ||
Move code tasks. | ||
Create folders in the Resource/Function directory. | ||
Edit folders in the Resource/Function directory. | ||
Delete folders from the Resource/Function directory. | ||
Create resources and functions. | ||
Edit resources and functions. | ||
Roll back resources and functions. | ||
Delete resources and functions. | ||
Move resources and functions. | ||
Create code templates. | ||
Edit code templates. Operations include editing, cloning, renaming, modifying code, saving, and locking. | ||
Delete code templates. | ||
Create tables in Table Management. | ||
Edit tables in Table Management. Operations include editing, renaming, moving, saving, locking, and rolling back versions. | ||
Delete tables in Table Management. | ||
Perform special edit operations for mirror tables, such as batch association and auto-association. | ||
Create sync tasks. | ||
Edit sync tasks. Operations include editing, renaming, moving, modifying the task, saving, and locking. | ||
Delete sync tasks. | ||
Execute | Execute, submit, pre-compile, deactivate, or deactivate and delete code tasks. | |
Submit resources and functions. | ||
Debug, submit, or deactivate and delete code templates. | ||
Submit, deactivate, or deactivate and delete tables in Table Management. | ||
Submit, deactivate, or deactivate and delete sync tasks. | ||
Ad-hoc query | Access directory | View the ad-hoc query directory. |
View details | View ad-hoc query content, assistant, history, and logs. | |
Edit | Create folders in the ad-hoc query directory. | |
Edit folders (rename, move) in the ad-hoc query directory. | ||
Delete folders from the ad-hoc query directory. | ||
Create ad-hoc queries. | ||
Edit ad-hoc queries. Operations include editing, renaming, modifying code, saving, formatting, and locking. | ||
Delete ad-hoc queries. | ||
Refresh ad-hoc queries. | ||
Move ad-hoc queries. | ||
Execute Note This permission applies to executing compute tasks and ad-hoc queries. Behavior varies by interface: In the UI, this specific permission is required. Via OpenAPI, any execution permission is sufficient. | Execute ad-hoc query code. | |
Pre-compile ad-hoc query code. | ||
Global search | Global search | Search for resources by using Global Search. |
Search for code by using Global Search. | ||
Recycle Bin | Permanently delete | Permanently delete items from the Recycle Bin. |
Restore | Restore items from the Recycle Bin. | |
Project asset permissions | ||
Physical table | Create | Create physical tables. |
Query table data | Query data from physical tables and physical views in the project. | |
Modify table data | Modify data in the project's physical tables. | |
Modify table structure | Modify the structure of the project's physical tables. | |
Delete table | Delete the project's physical tables. | |
Logical table | Query table data | Query data from logical tables (metrics in this project's summary tables) and logical views within the project. |
Real-time metatable | Query table data | Query data from real-time metatables. |
Modify table data | Modify data in real-time metatables. | |
Mirror table | Query table data | Query data from mirror tables. |
Dataset | Use | Use all datasets within the project. |
Publishing and O&M | ||
Publishing module | View details | View the pending objects list and their version history. |
View the publishing list, publishing details, and failure logs. | ||
Publish (prod only) | Publish objects from the pending objects list. | |
Republish items from the publishing list. | ||
Remove | Remove objects from the pending objects list. | |
O&M | Access directory | View exception statistics and dashboards. |
View lists of scheduled, manual, and real-time tasks. | ||
Search and filter scheduled, manual, and real-time tasks. | ||
View lists of scheduled, manual, real-time, and backfill data instances. | ||
Search and filter scheduled, manual, real-time, and backfill data instances. | ||
View basic information | For scheduled, manual, and real-time tasks: view the DAG, node details, and operation logs. | |
For scheduled, manual, and real-time tasks: view task instances and backfill data instances. | ||
For scheduled, manual, and real-time tasks: edit development nodes and view production nodes. | ||
For scheduled tasks on logic tables: perform batch operations on fields, view production lineage, and view consumption lineage. | ||
For scheduled, manual, and real-time tasks: expand parent and child nodes. | ||
For scheduled, manual, real-time, and backfill data instances: view the DAG, node details, and operation logs. | ||
For scheduled, manual, real-time, and backfill data instances: edit development nodes and view production nodes. | ||
For scheduled, manual, real-time, and backfill data instances: expand parent and child nodes. | ||
For scheduled, manual, real-time, and backfill data instances: view tasks. | ||
For scheduled instances on logic tables: perform batch operations on fields, view production lineage, and view consumption lineage. | ||
View details (with code) | View node code for scheduled, manual, and real-time tasks. | |
For scheduled tasks on logic tables: view materialization code. | ||
For scheduled, manual, real-time, and backfill data instances: view node code, run logs, and run diagnostics. | ||
For scheduled instances on logic tables: view materialization code. | ||
O&M operations | Backfill data for scheduled, manual, and real-time tasks. | |
Change the owner of scheduled, manual, and real-time tasks. | ||
Pause or resume scheduled, manual, and real-time tasks. | ||
Configure monitoring alerts for scheduled, manual, and real-time tasks. | ||
For scheduled, manual, real-time, and backfill data instances: rerun, rerun downstream, set to success and continue scheduling, terminate, or force rerun. | ||
For scheduled, manual, real-time, and backfill data instances: remove upstream dependencies, pause, or resume. | ||
Resource configuration | Modify the priority of scheduled, manual, and real-time tasks. | |
Modify the resource queue for scheduled, manual, and real-time tasks. | ||
Modify the configuration of real-time tasks. | ||
Task monitoring configuration | Access directory | View directories for offline and real-time monitoring. |
Filter offline and real-time monitoring tasks. | ||
Create | Create new offline or real-time monitoring rules. | |
Edit | Edit, enable, or disable monitoring configurations. | |
Modify recipients. | ||
Delete monitoring configurations. | ||