Appearance
Are you an LLM? You can read better optimized documentation at /permissions/workspace.md for this page in Markdown format
Workspace permissions
For operations tied only to the workspace, whether they're allowed is determined by the user's workspace role.
Operations
"X or higher" in the table means that role and any higher role can perform the operation. For the definition of the hierarchy, see Role hierarchy.
| Operation | Category | Required workspace role |
|---|---|---|
| Inviting and removing users / changing a user's role | Users | Workspace Owner |
| Viewing the audit log and user activity history | Audit log | Workspace Owner |
| Viewing information about the workspace | Workspace | Workspace Viewer or higher |
| Changing workspace settings (including policy, security, API key, and PAT management) | Workspace | Workspace Owner |
| Viewing information for all groups | Group | Workspace Viewer or higher |
| Creating a group | Group | Workspace Owner |
| Creating a connection | Connection | Workspace Editor or higher |
| Creating a teamspace | Teamspace | Workspace Editor or higher |
| Creating and editing tag definitions | Tag | Workspace Editor or higher |
| Creating a workflow | Workflow | Workspace Editor or higher |
| Managing workflows | Workflow | Workspace Owner |
Inviting guests from the report screen isn't determined by the workspace role alone. For details, see Report permissions and Invitations and joining.
Editing or deleting a group, and changing its members, can be done by the Workspace Owner as well as the Group Owner. For details, see Group.
For operations tied to resources such as connections, notebooks, and reports, see Permissions overview and the page for each resource.