Role Limitations and Examples
Organization Roles
- Organization Super Admin: Full read and write access to all resources and configurations in the account — org, all workspaces, and all projects.
- Organization Admin: Configure settings at the org level but no project access.
- Organization Governance Admin: Create and manage policies, and assign them to apps in the organization.
- Organization Policy Assigner: View policies and create/delete policy assignments across the organization. Pair with Workspace Policy Manager.
- Organization Policy Reader: View policies, their alert and attestation rules, and each policy's assignments and compliance history for applications the user can view.
- Organization Reader: View organizational settings; no workspace/project data access.
- Organization Read All: Full read-only access across organization, workspaces, and projects.
- Organization Member: Minimal read access that allows a user to view the basic Arthur UI.
Workspace Roles
- Workspace Super Admin: Full read and write access to all resources and configurations in a workspace and its projects.
- Workspace Admin: Configure workspace settings; no organization-level control.
- Workspace Policy Manager: View policy assignments in a workspace, assign and remove policies from applications in the workspace, and read basic info, alerts, and alert rules for all models in the workspace. Pair with Organization Policy Assigner.
- Workspace Read All: Read-only access to all workspace projects and resources.
- Workspace Reader: View workspace configurations; no access to project data.
- Custom Aggregation Manager: Read and write access to all custom aggregations in a workspace.
- Engine Manager: Create and configure engines in the workspace.
- Engine Workspace: Access to resources in the workspace that an engine needs to execute jobs in it.
Project Roles
- Project Admin: Manage project-level resources and datasets. Can view the raw data of datasets.
- Project Reader: View project resources; no edit permissions. Does not grant access to raw dataset data.
- Data Plane Project: Grants access needed by a data plane for job execution for an associated project.
Multi-Scope Roles (bindable at org, workspace, or project level)
- Raw Data Reader: Read access to view raw dataset data within the bound scope.
- Data Plane Execution: Read access to dequeue jobs from the data plane's job queue and view its own configuration.
Updated 16 days ago
Did this page help you?