Role Limitations and Examples

Organization Roles

  • Organization Super Admin: Full read and write access to all resources and configurations in the account — org, all workspaces, and all projects.
  • Organization Admin: Configure settings at the org level but no project access.
  • Organization Governance Admin: Create and manage policies, and assign them to apps in the organization.
  • Organization Policy Assigner: View policies and create/delete policy assignments across the organization. Pair with Workspace Policy Manager.
  • Organization Policy Reader: View policies, their alert and attestation rules, and each policy's assignments and compliance history for applications the user can view.
  • Organization Reader: View organizational settings; no workspace/project data access.
  • Organization Read All: Full read-only access across organization, workspaces, and projects.
  • Organization Member: Minimal read access that allows a user to view the basic Arthur UI.

Workspace Roles

  • Workspace Super Admin: Full read and write access to all resources and configurations in a workspace and its projects.
  • Workspace Admin: Configure workspace settings; no organization-level control.
  • Workspace Policy Manager: View policy assignments in a workspace, assign and remove policies from applications in the workspace, and read basic info, alerts, and alert rules for all models in the workspace. Pair with Organization Policy Assigner.
  • Workspace Read All: Read-only access to all workspace projects and resources.
  • Workspace Reader: View workspace configurations; no access to project data.
  • Custom Aggregation Manager: Read and write access to all custom aggregations in a workspace.
  • Engine Manager: Create and configure engines in the workspace.
  • Engine Workspace: Access to resources in the workspace that an engine needs to execute jobs in it.

Project Roles

  • Project Admin: Manage project-level resources and datasets. Can view the raw data of datasets.
  • Project Reader: View project resources; no edit permissions. Does not grant access to raw dataset data.
  • Data Plane Project: Grants access needed by a data plane for job execution for an associated project.

Multi-Scope Roles (bindable at org, workspace, or project level)

  • Raw Data Reader: Read access to view raw dataset data within the bound scope.
  • Data Plane Execution: Read access to dequeue jobs from the data plane's job queue and view its own configuration.


Did this page help you?