Skip to content

Workspace permissions

For operations tied only to the workspace, whether they're allowed is determined by the user's workspace role.

Operations

"X or higher" in the table means that role and any higher role can perform the operation. For the definition of the hierarchy, see Role hierarchy.

OperationCategoryRequired workspace role
Inviting and removing users / changing a user's roleUsersWorkspace Owner
Viewing the audit log and user activity historyAudit logWorkspace Owner
Viewing information about the workspaceWorkspaceWorkspace Viewer or higher
Changing workspace settings (including policy, security, API key, and PAT management)WorkspaceWorkspace Owner
Viewing information for all groupsGroupWorkspace Viewer or higher
Creating a groupGroupWorkspace Owner
Creating a connectionConnectionWorkspace Editor or higher
Creating a teamspaceTeamspaceWorkspace Editor or higher
Creating and editing tag definitionsTagWorkspace Editor or higher
Creating a workflowWorkflowWorkspace Editor or higher
Managing workflowsWorkflowWorkspace Owner

Inviting guests from the report screen isn't determined by the workspace role alone. For details, see Report permissions and Invitations and joining.

Editing or deleting a group, and changing its members, can be done by the Workspace Owner as well as the Group Owner. For details, see Group.

For operations tied to resources such as connections, notebooks, and reports, see Permissions overview and the page for each resource.