Skip to main content

User Roles and Permissions

A role determines what a user can do in the Digital.ai Platform itself: which pages they reach, which settings they change, and whether they can author analytics content. The Platform has five roles, and this topic is the authoritative reference for all of them.

Roles govern the Platform only. What a user can do inside a Digital.ai product such as Release or Deploy is determined separately, by the user groups that product maps to its own roles. For more information, see Prepare the Platform for a Product Integration.

Compare the Roles

RoleIntended forWhat it grants
account-adminAdministrators who own the accountFull administrative access: user, user group, and role management, SSO and identity provider configuration, account settings, applications, AI providers, and the audit log. This documentation refers to a user with this role as an administrator.
account-application-adminAdministrators who manage product instances but not identityAdministrative access to manage the applications registered under the account. Doesn't include SSO configuration.
account-analytics-authorDashboard and report authorsEverything account-user grants, plus viewing, creating, and editing datasets and dashboards.
account-userEveryone elseThe default role and the lowest level of access: sign in, reach assigned Digital.ai applications, use the support and documentation portals, view dashboards, and edit their own profile and preferences. This documentation refers to a user with this role as an end user.
account-serviceAutomation, not peopleAuthentication as a service account, for programmatic access to APIs and services within the scopes assigned to it. Used with an application of type For API Use rather than assigned to a person. For more information, see API Overview.
note

account-user is the default. Users created through an identity provider, and users who self-register, receive account-user unless a role mapper assigns something else. For more information, see User Self-Registration and Create a Role Mapper.

Review Analytics Permissions

Analytics permissions differ enough by role to be worth stating on their own. Out-of-the-box dashboards that carry the Digital.ai tag can't be edited or removed by anyone; every role can duplicate them to use as a template.

Capabilityaccount-adminaccount-application-adminaccount-analytics-authoraccount-user
View published dashboardsYesYesYesYes
Use the Featured and Favorites tabsYesYesYesYes
Use the All tab to see every dashboardYesYesYesNo
Create and edit custom dashboardsYesYesYesNo
Edit a custom published dashboardYesYesYesNo
Create and edit datasetsYesYesYesNo

For more information, see Access Dashboards, Featured Dashboards, and Save, Publish, and Manage a Dashboard.

Assign a Role

You can assign roles three ways:

  • When you create a user. Choose the role in the Roles field on the create user form. See Users.
  • By editing an existing user. Go to Users, click the Edit icon in the Actions column, and change the Roles value.
  • Automatically, from your identity provider. A role mapper assigns a role based on the user's group membership in your identity provider, so you manage role membership centrally in your corporate directory rather than user by user. See Create a Role Mapper.

For accounts of any size, the role mapper approach is worth the setup. It keeps role assignment in the system your organization already governs, and new employees arrive with the right access on first sign-in.

Choose the Right Role

  • Grant account-admin sparingly. It includes SSO configuration, so an account-admin can change how every user in your account authenticates.
  • Use account-application-admin for the administrator who registers and maintains product instances but has no reason to touch identity configuration.
  • Assign account-analytics-author to anyone responsible for building dashboards who doesn't otherwise need administrative access. This is the role most often overlooked, and granting account-admin instead is the usual mistake.
  • Leave everyone else as account-user. It's the default, and it covers signing in, reaching applications, and viewing dashboards.
  • Don't assign account-service to a person. It exists for programmatic access.
note

Users with the account-admin role always have unrestricted access to the support portal, even when you restrict support access to specific user groups. For more information, see Account Settings.