Roles and Permission Matrix
Transform has a both primary and secondary roles in the product. Primary roles map to assignments that are given when a user is created in the interface, and secondary roles are roles that are assumed based on certain actions or assignments that come after a primary role designation.
Organization Administrators have elevated privileges and can take most actions across the Metrics Catalog. Currently, there are only administrative actions available in the Metrics Catalog.
Administrators can change metadata about a metric (without ownership), edit and remove team members, as well as view and update settings around DW credentials. Organization admins cannot edit Team specific objects and settings unless they are also administrators or members of a team.
Users can view and interact with most components of the interface but will not be able to take administrative actions, such as editing and managing users. Additionally, they will not be able to change anything about a metric in the UI unless they are explicitly an owner. A user is the default setting for an account that is not an administrator.
Team Administrator Team administrators can be either users or organization administrators. A person with an account in Transform can become a Team Admin by creating a team. Team Admins can take high-level actions around their team settings and on team pages.
Metric Owners Metric owners can be Teams (a set of users) or individual Users. These assignments must be designated through the Framework or User interface. Metric Owners can take high-level actions around the metric description, approval, and ownership of a given metric. Note: We've left metric owners out of the matrix and denoted where metric ownership matters by indicating how a user's permissions change based on ownership.
|Action||Organization Administrator||Users||Team Admins|
|Settings - Edit/Add Users to Transform||✔️||-||-|
|Settings - Edit/Add Users to Team||✔️||-||✔️|
|Settings - Create New Team||✔️||✔️||NA|
|Settings - Edit DW Credentials||✔️||-||-|
|Settings - Edit/Add/Remove MQL Server||✔️||-||-|
|Settings - Create API Keys for oneself||✔️||✔️||NA|
|Settings - View MQL Query Logs||✔️||✔️||NA|
|Metric Page - View Lineage, Edit Chart, Save Query, Annotate, Ask Question||✔️||✔️||NA|
|Metric Page - Edit Metric Description||✔️||If User Owns metric or is on Team that owns metric||If Team is Owner|
|Edit/Delete Annotation||✔️||If User authored Annotation||NA|
|Edit/Delete Question||If Admin authored||If User authored||NA|
|Edit/Delete Saved Query||If Admin authored||If User authored||NA|
|Metric Page - Approve Metric||✔️||If User Owns metric or is on Team that owns metric||If Team is Owner|
|Metric Page - Edit Owners||✔️||If User Owns metric or is on Team that owns metric||If Team is Owner|
|Collections - Create Collection||✔️||✔️||NA|
|Collections - Edit Collection||If Admin owns Collection is or on Team that owns Collection||If User owns Collection or is on a team that owns Collection||If Team is Owner of Collection|
|Collections - View All Collections||✔️||✔️||NA|
|Team Page - Edit Team||If Admin on Team||If User is on Team||✔️|
|Team Page - Add Metrics||If Admin on Team||If User is on Team||✔️|
|Team Page - Add Collections||If Admin on Team||If User is on Team||✔️|
|Team Page - Add Saved Queries||If Admin on Team||If User is on Team||✔️|
|CLI - Run MQL Query||✔️||✔️||NA|
|CLI - Commit Configs to Transform||✔️||✔️||NA|