Permission model
Collections and assets define access scope with the Owner, Editor, and Viewer roles. Connectors and secrets use a separate use permission to manage who can execute or reference them.
Roles
| Role | Primary allowed actions |
|---|---|
| Owner | Performs all actions, including changing settings, granting and revoking roles, and deleting. |
| Editor | Edits contents and saves new versions. |
| Viewer | Views assets and runs SELECT queries on permitted data. |
Collection permission inheritance
A collection role is the minimum permission on its child assets. On a specific asset, you can directly grant only a role higher than the inherited role.
- An inherited role appears as an Inherited · {role} badge and cannot be lowered on the asset screen.
- Selecting a higher role under Elevate grants a direct permission on that asset only.
- Selecting No elevation removes the direct permission and leaves only the inherited permission.
- Lowering or removing a collection member's role also changes the inherited permissions on child assets.
Removing a member from a collection also removes roles granted directly on its child assets. Review the impact in the confirmation dialog before applying the change.
Use permission
Use permission is separate from the Owner, Editor, and Viewer roles. It does not allow listing the resource or editing its settings; it allows a saved connector or secret to be used at runtime.
| Target | Allowed action | Additional condition |
|---|---|---|
| Connector | Runs the connection with the saved connection details and credentials. | Connection testing and Query Console may also check the account type or settings. |
| Secret | Allows a data connection or tool to reference the stored value. | Secret values are not displayed, even with use permission. |
| Parent collection | Meets the prerequisite for using a collection-scoped connector or secret. | A subject that does not own the collection needs use permission on the parent collection. |
Revoking use permission does not change the Owner, Editor, or Viewer role. Changing a general role does not automatically revoke a directly granted use permission.
Permission criteria by action
| Action | Criterion | Without permission |
|---|---|---|
| Create a collection or connector, or import | Administrator or Manager account | The action button is disabled. |
| Create an asset in a collection | Signed-in user and permission on the target location | The action button is disabled. |
| Edit | Edit permission on the asset | The edit menu is disabled. |
| Delete | Delete permission on the asset | The delete menu is disabled. |
Administrators can perform all actions. Controls may be briefly disabled while permissions are being checked.
Collection display scopes
- My Collections: Collections where you have the Owner role.
- Shared Collections: Collections shared with you with the Editor or Viewer role.
- Other Collections: The remaining collections, visible only to Administrators.
These scopes only determine how the tree displays collections; they do not change actual access permissions.
Related tasks
- Assign roles to users and groups in Sharing permissions.
- Manage connector use permission.
- Manage secret use permission.
- Restrict the column and row scope of datasets with Data Access Policies.