Skip to content

Role scopes

Role scopes allow you to specify the level of access granted to any users or groups via tenant roles.

By default, every user in a tenant inherits the scopes assigned to the userDefault role. Users assigned the TenantAdmin role can make changes to userDefault to amend this default configuration, as well as create and manage their own role definitions, which can provide fine-grained access to specific users or groups.

Note: Where OAuth2 is used for authorization, a user’s access via that OAuth2 client can be further configured with OAuth2 scopes.

Role scopes

Not all scopes are available for use in userDefault. Some scopes will only be available with certain subscription entitlements. To retrieve your entitlements, you can call the License overview endpoint.

Scope NameScope DescriptionCan be assigned to custom rolesCan be assigned to userDefaultRequired entitlement
automations.sharedRead and manage your automations in shared spaces✖️-
apps.data:exportDownload all app content or images and PDFs only, blocking data downloads.-
apps.image:exportDownload app content as images and PDFs only-
insight-advisor.limitedGenerate advanced analysis types with visualizations and natural language insights in a few clicks.-
insight-advisor.genaiGenerate advanced analysis types with visualizations and natural language insights in a few clicks.-
insight-advisor-chat.limitedUse natural language to ask questions and search apps.-
insight-advisor-chat.genaiUse natural language to ask questions and search apps.-
knowledgebases:readRead access to knowledge basestotalPagesIndexed
knowledgebases:indexIndex content in knowledge basestotalPagesIndexed
knowledgebases:searchSearch content in knowledge basestotalPagesIndexed
knowledgebasesRead and manage knowledge basestotalPagesIndexed
assistants:readBasic query access to assistantsnumQuestionsPerMonth
assistantsRead and manage assistantsnumQuestionsPerMonth
admin.automl-models:approveApprove or reject all AutoML models in the tenant✖️-
automl-models:approveApprove or reject AutoML models in spaces to which you have edit access-
shareable-links.publicCreate and manage public content linksanonymousCapacity
dataproductCreate and manage data products✖️dataProduct
dataproduct:consumeRead and list data productsdataProduct
dataqualityCompute and refresh data qualitiesdataQuality
semantictypeCreate and manage semantic typesdataQuality
semantictype.consumeRead and list semantic typesdataQuality
admin.semantictypeRead, list and delete semantic types✖️dataQuality

ON THIS PAGE

Was this page helpful?