Skip to content

Scopes

Note

To learn about access control in Qlik Cloud, read the access control overview.

Scopes are grouped into:

  • Administrator scopes, which provide broad access to resources the user may not otherwise have access to in the user interface.
  • User scopes, which provide access to resources the user already has direct access to.

This table outlines which scopes are supported in which use cases (for example, for use in custom roles versus for use in OAuth). Some scopes are multi-purpose, and others may only be available in one place.

Scopes may also have child scopes, which are displayed as such in the user interface. A parent scope of a child will contain the same permissions as the child, so if you select the parent, you need not also set the child. Child scopes are displayed with a and nested under the relevant parent scope.

Note

Some scopes are only available depending on your subscription and enabled features.

Administrator scopes

These scopes permit administrator-level access.

Note

For OAuth flows, the admin_classic scope permits broad administrator access to the tenant. Where possible, use a less permissive scope which grants access only to required administrative functions.

Scope NameDescriptionOAuthCustom RoleUser Default
admin_classicFull administrator access to your tenant
admin.ai-descriptionsManage tenant settings for generating AI-based descriptions for any resource and validation rule suggestions for datasets. Access and manage any generation without space restrictions.
admin.aiplatformCreate a chat conversation with an LLM
admin.appsRead and manage all apps in the tenant
↳ admin.apps:exportExport all apps in the tenant
↳ admin.apps:readRead all apps in the tenant
admin.assistantsRead and manage all assistants
admin.auth-settingsView and update authentication settings for a tenant, including session timeout settings.
admin.automationsRead and manage all automations in the tenant
↳ admin.automations:readRead all automations in the tenant
admin.automations:strictManage all automations in the tenant.
admin.automl-models:approveApprove or reject all ML models in the tenant
admin.automl:fullManage all ML experiments and deployments within Administration
admin.collections.publicgovernedCreate and update public collections
admin.cspCreate, update, read, list, delete.
admin.dataproductAccess and manage any data products without space restrictions.
admin.dataqualityAccess and manage data quality settings without space restrictions.
admin.dataqualityrulesAccess and manage any validation rules without space restrictions.
admin.direct-access-gateways:remote_configurationView and modify Direct Access gateway settings
admin.environmentsCreate, read, update, and delete environments. Allows linking environments to spaces.
admin.extensionsCreate, read, update, delete, and download extensions.
admin.insightshome:editCurate content for better findability.
admin.ip-policiesView and manage IP policies in the tenant, including creating, updating, and deleting them.
admin.knowledgebasesRead and manage all knowledge bases
admin.lakehouse-clusterCreate, edit, and operate lakehouse clusters
admin.report-tasksManage report tasks and subscriptions, and read the associated templates and filters.
admin.semantictypeAccess and manage any semantic type.
admin.spacesRead and manage all spaces in the tenant
↳ admin.spaces:readRead all spaces in the tenant
admin.sprintsAccess and manage all data stewardship sprints, without space restrictions.
admin.themesCreate, read, update, delete, and download themes.
admin.ui-config:editConfigure tenant-wide user interface settings and available options, such as pinned links.
admin.usersRead and manage all users
↳ admin.users:readFull read access to all users
admin.webhooksManage webhooks in the Administration activity center.

User scopes

These scopes permit user-level access to create and manage resources that the user has named access to, or owns.

Note

For OAuth flows, the user_default scope permits broad user level access to the tenant. Where possible, use a less permissive scope which grants access only to required content or functions.

Scope NameDescriptionOAuthCustom RoleUser Default
user_defaultFull access to your account and content
ai-descriptionsGenerate AI-based validation rules for datasets and descriptions for any resource.
analysis-agentLets users use Qlik Answers to analyse data, create charts, and gather insights from documents
api-keysCreate, view, update, and delete your own API keys.
app.shareSpace owners and users with the ‘Can manage’ role can share applications with any group or user without adding them to the space.
appsRead and manage your apps
↳ apps:exportExport your apps
↳ apps:readRead your apps
apps:manageOverride automatic engine selection by assigning an engine size to applications.
apps.data:exportDownload all app content or images and PDFs only, blocking data downloads.
↳ apps.image:exportDownload app content as images and PDFs only
apps.report:allGenerate all types of reports, including in-app, API, scheduled, on-demand, and automated. Also manage filters, recipients, and tasks. Author report templates in add-ins and embedded designers.
↳ apps.report:exportGenerate on-demand reports.
assistantsRead and manage assistants
↳ assistants:readBasic query access to assistants
automationsRead and manage your automations
↳ automations:readRead your automations
automations.privateRead and manage automations in your personal space
automations.sharedRead and manage your automations in shared spaces
automl-deploymentsAllow users to view and update ML deployments and run all predictions, run API and connector predictions only, or block access to ML deployments and predictions.
↳ automl-deployments:predictCreate predictions only
automl-experimentsRead and manage your ML experiments
↳ automl-experiments:no_gen_ai_assistCreate and update ML experiments without any GenAI-assisted functions.
automl-models:approveApprove or reject ML models in spaces to which you have edit access
classic_talend.audit_logs_viewTalend: View audit logs
classic_talend.connection_createTalend: Create connections
classic_talend.connection_deleteTalend: Delete connections
classic_talend.connection_readTalend: View connections
classic_talend.connection_shareTalend: Share connections
classic_talend.connection_updateTalend: Update connections
classic_talend.crawling_createTalend: Create crawlers
classic_talend.crawling_deleteTalend: Delete crawlers
classic_talend.crawling_readTalend: View crawlers
classic_talend.crawling_updateTalend: Update crawlers
classic_talend.custom_attribute_createTalend: Add custom attributes
classic_talend.custom_attribute_deleteTalend: Delete custom attributes
classic_talend.custom_attribute_readTalend: View custom attributes
classic_talend.custom_attribute_updateTalend: Edit custom attributes
classic_talend.dataset_advanced_searchTalend: Perform advanced dataset search
classic_talend.dataset_api_manageTalend: Manage APIs
classic_talend.dataset_api_viewTalend: View APIs
classic_talend.dataset_attributes_manageTalend: Manage custom attributes of a dataset
classic_talend.dataset_certifyTalend: Certify datasets
classic_talend.dataset_createTalend: Create datasets
classic_talend.dataset_deleteTalend: Delete datasets
classic_talend.dataset_downloadTalend: Download datasets
classic_talend.dataset_readTalend: View datasets
classic_talend.dataset_sample_updateTalend: Refresh sample
classic_talend.dataset_schema_updateTalend: Set semantic type
classic_talend.dataset_shareTalend: Share datasets with others
classic_talend.dataset_tags_manageTalend: Add or remove tags on datasets
classic_talend.dataset_updateTalend: Update datasets
classic_talend.execution_logs_deleteTalend: Delete execution logs
classic_talend.rule_createTalend: Create data quality rules
classic_talend.rule_deleteTalend: Delete data quality rules
classic_talend.rule_editTalend: Edit data quality rules
classic_talend.rule_viewTalend: View data quality rules
classic_talend.studio_entitlement_studio_developerTalend: Develop in Studio and Publish to Cloud Management Console
classic_talend.tapid_adminTalend: Administrate API Designer
classic_talend.tapid_definition_manageTalend: Create and Edit API contracts
classic_talend.tapid_definition_shareTalend: Share API contracts
classic_talend.tapid_portal_manageTalend: Create and Edit an API Portal
classic_talend.tapit_project_manageTalend: Create and Edit API scenarios
classic_talend.tapit_project_shareTalend: Share API scenarios
classic_talend.tdp_basicTalend: Manage preparations and local datasets
classic_talend.tdp_dataset_certifyTalend: Certify datasets
classic_talend.tdp_dataset_perform_liveTalend: Manage live datasets
classic_talend.tdp_full_run_performTalend: Export all data from preparations
classic_talend.tdp_hybrid_managementTalend: Configure and activate Data Preparation Hybrid
classic_talend.tdp_prep_version_createTalend: Create preparation versions
classic_talend.tdp_tcomp_useTalend: Manage remote datasets
classic_talend.tdq_semantic_type_createTalend: Create semantic types
classic_talend.tdq_semantic_type_deleteTalend: Delete semantic types
classic_talend.tdq_semantic_type_editTalend: Edit semantic types
classic_talend.tdq_semantic_type_listTalend: List semantic types
classic_talend.tdq_semantic_type_publishTalend: Publish semantic types
classic_talend.tdq_semantic_type_viewTalend: View semantic types
classic_talend.tds_assigned_task_assignTalend: Delegate tasks
classic_talend.tds_assigned_task_data_updateTalend: Edit assigned tasks
classic_talend.tds_assigned_task_metadata_updateTalend: Edit assigned tasks metadata
classic_talend.tds_assigned_task_readTalend: View assigned tasks
classic_talend.tds_campaign_createTalend: Add campaigns
classic_talend.tds_campaign_deleteTalend: Delete campaigns
classic_talend.tds_campaign_listTalend: List campaigns
classic_talend.tds_campaign_readTalend: View campaigns
classic_talend.tds_campaign_updateTalend: Edit campaigns
classic_talend.tds_hybrid_managementTalend: Configure and activate Data Stewardship Hybrid
classic_talend.tds_schema_createTalend: Add data models
classic_talend.tds_schema_deleteTalend: Delete data models
classic_talend.tds_schema_listTalend: List data models
classic_talend.tds_schema_readTalend: View data models
classic_talend.tds_schema_updateTalend: Edit data models
classic_talend.tds_task_assignTalend: Assign tasks
classic_talend.tds_task_createTalend: Add tasks
classic_talend.tds_task_deleteTalend: Delete tasks
classic_talend.tds_task_history_deleteTalend: Delete task history
classic_talend.tds_task_history_readTalend: View task history
classic_talend.tds_task_metadata_updateTalend: Edit tasks metadata
classic_talend.tds_task_readTalend: View tasks
classic_talend.tds_task_read_by_external_idTalend: View tasks using external ID
classic_talend.tds_task_updateTalend: Edit tasks
classic_talend.tds_unassigned_task_assignTalend: Self-assign unassigned tasks
classic_talend.tds_unassigned_task_readTalend: View unassigned tasks
classic_talend.tds_users_readTalend: View users
classic_talend.tmc_cloud_configuration_managementTalend: Manage cloud configurations
classic_talend.tmc_cluster_managementTalend: Manage Remote Engines and Remote Engine clusters
classic_talend.tmc_configuration_nexus_userlibsTalend: Set up user libraries in the artifact repository
classic_talend.tmc_connection_resource_editTalend: Edit connections and resources
classic_talend.tmc_engine_useTalend: View and use Remote Engines to run tasks
classic_talend.tmc_environment_managementTalend: Manage environments
classic_talend.tmc_group_managementTalend: Manage groups
classic_talend.tmc_operatorTalend: Manage operations
classic_talend.tmc_pipeline_managementTalend: Manage promotions
classic_talend.tmc_project_managementTalend: Manage projects (including project authorizations)
classic_talend.tmc_promotion_executionTalend: Execute promotions
classic_talend.tmc_role_managementTalend: Manage roles
classic_talend.tmc_run_profile_managementTalend: Manage run profiles
classic_talend.tmc_service_account_managementTalend: Manage service accounts
classic_talend.tmc_sso_managementTalend: Configure single sign-on
classic_talend.tmc_static_ip_managementTalend: Configure static IP addresses for Cloud Engines
classic_talend.tmc_subscription_managementTalend: Access subscription information
classic_talend.tmc_user_managementTalend: Manage users
data-connectionsRead and manage your data connections
↳ data-connections:readRead your data connections
dataproductCreate, activate, update, or consume data products.
↳ dataproduct:consumeRead and consume data products.
dataqualityCompute and read data qualities.
↳ dataquality:readRead data quality.
dataqualityrulesCreate, update, or apply validation rules to datasets.
↳ dataqualityrules:assignRead and apply validation rules to datasets.
datasetCreate, read, update, list, and delete datasets.
direct-access-gateways:consume_dataLoad data via Direct Access gateway connectors
discovery-agentCreate triggers for anomaly detection, serving user feeds with insights.
discovery-agent:readAllow users to consume and act on insights generated by the Discovery Agent in the activity center feed page.
environments:readRead access to environments where the user is a space member.
genericlink:allCreate, update, and use links within spaces.
geo-operationsExecute any geographic operation.
↳ geo-operations.limitedAllows all operations except geocoding
glossary:allFull access to glossaries and terms, including approving terms
↳ glossary:manageFull access to glossaries and terms, except for approving terms
↳ glossary:updateRead access to glossary metadata and access to glossary terms
governance-definition:readAssign classifications to dataset fields and regulations to datasets
help-agentLets users use Qlik Answers to find relevant product documentation.
identity.email:readRead your email address
identity.name:readRead your full name
identity.picture:readRead your profile picture
identity.subject:readRead your user subject identifier
insight-advisor:experienceLets users use Insight Advisor to analyse data and create charts.
knowledgebasesRead and manage knowledge bases
↳ knowledgebases:readRead access to knowledge bases
knowledgebases:indexIndex content in knowledge bases
knowledgebases:searchSearch content in knowledge bases
lakehouse-cluster-moderatorEdit settings and operate lakehouse clusters
↳ lakehouse-cluster-viewerView lakehouse clusters
lakehouse-cluster-operatorStop, start, scale, and roll lakehouse clusters
learning-center:allLearn more about Qlik features and capabilities.
lineage:createCreate lineage.
lineage:readView lineage between assets
mcp:executeLets users use the Qlik MCP server
network-integration-viewerView network integration
notesCreate and manage notes based on roles within the space.
offline_accessAccess resources while you are offline
pipelines-projectsCreate, update, or view pipeline projects based on space access
↳ pipelines-projects:readRead and list pipeline projects based on space access
question:createUser who can access Insight Advisor from collaboration platforms.
semantictypeCreate, update, or assign semantic types to datasets.
↳ semantictype:readRead and assign semantic types.
space-requests:createAllows users to request access to content. When set to ‘Not allowed,’ you can define a custom message in Administration > Settings. The message appears when users try to open content they don’t have permission to view and can direct them to the right team or process for requesting access.
spaces.dataRead and manage your data spaces
↳ spaces.data:readRead your data spaces
spaces.managedRead and manage your managed spaces
↳ spaces.managed:readRead your managed spaces
spaces.sharedRead and manage your shared spaces
↳ spaces.shared:createCreate shared spaces for collaboration.
↳ spaces.shared:readRead your shared spaces
sprints:allCreate, manage or contribute to sprints.
↳ sprints:contributeParticipate in data stewardship sprints as a sprint owner or data steward. Roles are assigned in the sprint settings.
trustscoreConfigure Qlik Trust Score™ axes and weights.
usersBasic read access to users and management of your user preferences
↳ users:readBasic read access to users
webhooksCreate and update webhooks using the webhooks API and automations UI.
write-table:external_readDescription not available
write-table:fullFull access, creation and configuration of write table charts
↳ write-table:accessRead and write changes in write table charts
Was this page helpful?