Roles (deprecated)

Deprecated, see Access Control

Overview

Users and Access Tokens can be assigned to different roles that come with different sets of permissions.

Roles

Users and Access Tokens can be assigned to the following roles:

  • Admin
  • Editor
  • Viewer

The API role is a legacy role that could be assigned to Access Tokens but that is no longer available for new Access Tokens. Existing tokens with the API role however still function.

Permissions

Each role comes with a given set of permissions on the various Sifflet objects. Unless specified, below matrix applies regardless of how you are trying to access the information (UI, API, CLI, etc.).

ScopeAdminEditorViewer
INTEGRATIONS
Secrets management (create, edit, delete):white-check-mark:
Integrations management (create, edit, delete, trigger run):white-check-mark::white-check-mark:
Submit dbt metadata files and trigger the related datasource refresh (API only):white-check-mark::white-check-mark:
Create declarative pipeline & edge lineage (API only):white-check-mark:
DATA CATALOG
Data catalog search:white-check-mark::white-check-mark::white-check-mark:
Data assets (read):white-check-mark::white-check-mark::white-check-mark:
Data assets (edit - manual or through AI suggestions):white-check-mark::white-check-mark:
Preview data:white-check-mark::white-check-mark:
MONITORS
Monitors (read)(overview, runs, details):white-check-mark::white-check-mark::white-check-mark:
Show failing rows:white-check-mark::white-check-mark:
Datapoint qualification on monitors' runs:white-check-mark::white-check-mark:
Monitors (create, edit, delete, trigger run):white-check-mark::white-check-mark:
INCIDENTS
Incidents management (assignment, closing):white-check-mark::white-check-mark:
SETTINGS
Business Glossary (read):white-check-mark::white-check-mark::white-check-mark:
Business Glossary (create, edit, delete):white-check-mark::white-check-mark:
Tags (read):white-check-mark::white-check-mark::white-check-mark:
Tags (create, edit, delete):white-check-mark::white-check-mark:
Domains (read, create, edit, delete):white-check-mark:
Users (read, create, edit, delete):white-check-mark:
Access Tokens (read, create, delete):white-check-mark:
SSO (read, create, edit, delete):white-check-mark:
Alert Destinations (read, create, edit, delete):white-check-mark: