Skip to content

Scopes

Note

To learn about access control in Qlik Cloud, read the access control overview.

Scopes are grouped into:

  • Administrator scopes, which provide broad access to resources the user may not otherwise have access to in the user interface.
  • User scopes, which provide access to resources the user already has direct access to.

This table outlines which scopes are supported in which use cases (for example, for use in custom roles versus for use in OAuth). Some scopes are multi-purpose, and others may only be available in one place.

Scopes may also have child scopes, which are displayed as such in the user interface. A parent scope of a child will contain the same permissions as the child, so if you select the parent, you need not also set the child. Child scopes are displayed with a and nested under the relevant parent scope.

Administrator scopes

These scopes permit administrator-level access.

Note

For OAuth flows, the admin_classic scope permits broad administrator access to the tenant. Where possible, use a less permissive scope which grants access only to required administrative functions.

Scope NameDescriptionOAuthCustom RoleUser Default
admin_classicFull administrator access to your tenant
admin.ai-descriptionsGenerate descriptions for any resource using AI, and give feedback about result.
admin.aiplatformCreate a chat conversation with an LLM
admin.appsRead and manage all apps in the tenant
↳ admin.apps:exportExport all apps in the tenant
↳ admin.apps:readRead all apps in the tenant
admin.assistantsRead and manage all assistants
admin.automationsRead and manage all automations in the tenant
↳ admin.automations:readRead all automations in the tenant
admin.automl-models:approveApprove or reject all ML models in the tenant
admin.automl:fullManage all ML experiments and deployments within Administration
admin.collections.publicgovernedCreate and update public collections
admin.cspDescription not available
admin.dataqualityrulesCreate, update, read, list, delete, and manage validation rules. View validation result on data across all spaces.
admin.insightshome:editCurate content for better findability.
admin.knowledgebasesRead and manage all knowledge bases
admin.lakehouse-clusterCreate, edit, and operate lakehouse clusters
admin.semantictypeRead, list and delete semantic types
admin.spacesRead and manage all spaces in the tenant
↳ admin.spaces:readRead all spaces in the tenant
admin.usersRead and manage all users
↳ admin.users:readFull read access to all users
admin.webhooksManage webhooks in the Administration activity center.

User scopes

These scopes permit user-level access to create and manage resources that the user has named access to, or owns.

Note

For OAuth flows, the user_default scope permits broad user level access to the tenant. Where possible, use a less permissive scope which grants access only to required content or functions.

Scope NameDescriptionOAuthCustom RoleUser Default
user_defaultFull access to your account and content
ai-descriptionsGenerate descriptions for any resource using AI, and give feedback about result.
api-keysCreate, view, update, and delete your own API keys.
app.shareShare apps with other users from shared and managed spaces.
appsRead and manage your apps
↳ apps:exportExport your apps
↳ apps:readRead your apps
apps.data:exportDownload all app content or images and PDFs only, blocking data downloads.
↳ apps.image:exportDownload app content as images and PDFs only
assistantsRead and manage assistants
↳ assistants:readBasic query access to assistants
automationsRead and manage your automations
↳ automations:readRead your automations
automations.sharedRead and manage your automations in shared spaces
automl-deploymentsRead and manage your ML deployments
automl-deployments:predictRun ML predictions directly with the APIs or with the Qlik Predict analytics connector
automl-experimentsRead and manage your ML experiments
automl-models:approveApprove or reject ML models in spaces to which you have edit access
data-connectionsRead and manage your data connections
↳ data-connections:readRead your data connections
dataproductCreate and manage data products
↳ dataproduct:consumeRead and list data products
dataqualityCompute and refresh data qualities
↳ dataquality:readView data quality
dataqualityrulesCreate, update, read, list, delete, and manage validation rules in datasets. View validation result on data.
↳ dataqualityrules:assignRead, list, and apply validation rules. View validation results on data.
↳ dataqualityrules:consumeRead and list validation rules. View validation results on data.
datasetCreate, read, update, list, and delete datasets.
genericlink:allCreate, update, and use links within spaces.
identity.email:readRead your email address
identity.name:readRead your full name
identity.picture:readRead your profile picture
identity.subject:readRead your user subject identifier
knowledgebasesRead and manage knowledge bases
↳ knowledgebases:readRead access to knowledge bases
knowledgebases:indexIndex content in knowledge bases
knowledgebases:searchSearch content in knowledge bases
lakehouse-cluster-moderatorEdit settings and operate lakehouse clusters
↳ lakehouse-cluster-viewerView lakehouse clusters
lakehouse-cluster-operatorStop, start, scale, and roll lakehouse clusters
learning-center:allLearn more about Qlik features and capabilities.
lineage:createCreate lineage.
network-integration-viewerView network integration
notesCreate and manage notes based on roles within the space.
offline_accessAccess resources while you are offline
semantictypeManage semantic types used for the data quality of datasets
↳ semantictype:readRead and list semantic types
spaces.dataRead and manage your data spaces
↳ spaces.data:readRead your data spaces
spaces.managedRead and manage your managed spaces
↳ spaces.managed:readRead your managed spaces
spaces.sharedRead and manage your shared spaces
↳ spaces.shared:createCreate shared spaces for collaboration.
↳ spaces.shared:readRead your shared spaces
trustscoreConfigure Qlik Trust Score™ axes and weights
usersBasic read access to users and management of your user preferences
↳ users:readBasic read access to users
webhooksCreate and update webhooks using the webhooks API and automations UI.
Was this page helpful?