User Roles and Permissions
A role determines what a user can do in the Digital.ai Platform itself: which pages they reach, which settings they change, and whether they can author analytics content. The Platform has five roles, and this topic is the authoritative reference for all of them.
Roles govern the Platform only. What a user can do inside a Digital.ai product such as Release or Deploy is determined separately, by the user groups that product maps to its own roles. For more information, see Prepare the Platform for a Product Integration.
Compare the Roles
| Role | Intended for | What it grants |
|---|---|---|
account-admin | Administrators who own the account | Full administrative access: user, user group, and role management, SSO and identity provider configuration, account settings, applications, AI providers, and the audit log. This documentation refers to a user with this role as an administrator. |
account-application-admin | Administrators who manage product instances but not identity | Administrative access to manage the applications registered under the account. Doesn't include SSO configuration. |
account-analytics-author | Dashboard and report authors | Everything account-user grants, plus viewing, creating, and editing datasets and dashboards. |
account-user | Everyone else | The default role and the lowest level of access: sign in, reach assigned Digital.ai applications, use the support and documentation portals, view dashboards, and edit their own profile and preferences. This documentation refers to a user with this role as an end user. |
account-service | Automation, not people | Authentication as a service account, for programmatic access to APIs and services within the scopes assigned to it. Used with an application of type For API Use rather than assigned to a person. For more information, see API Overview. |
account-user is the default. Users created through an identity provider, and users who self-register, receive account-user unless a role mapper assigns something else. For more information, see User Self-Registration and Create a Role Mapper.
Review Analytics Permissions
Analytics permissions differ enough by role to be worth stating on their own. Out-of-the-box dashboards that carry the Digital.ai tag can't be edited or removed by anyone; every role can duplicate them to use as a template.
| Capability | account-admin | account-application-admin | account-analytics-author | account-user |
|---|---|---|---|---|
| View published dashboards | Yes | Yes | Yes | Yes |
| Use the Featured and Favorites tabs | Yes | Yes | Yes | Yes |
| Use the All tab to see every dashboard | Yes | Yes | Yes | No |
| Create and edit custom dashboards | Yes | Yes | Yes | No |
| Edit a custom published dashboard | Yes | Yes | Yes | No |
| Create and edit datasets | Yes | Yes | Yes | No |
For more information, see Access Dashboards, Featured Dashboards, and Save, Publish, and Manage a Dashboard.
Assign a Role
You can assign roles three ways:
- When you create a user. Choose the role in the Roles field on the create user form. See Users.
- By editing an existing user. Go to Users, click the Edit icon in the Actions column, and change the Roles value.
- Automatically, from your identity provider. A role mapper assigns a role based on the user's group membership in your identity provider, so you manage role membership centrally in your corporate directory rather than user by user. See Create a Role Mapper.
For accounts of any size, the role mapper approach is worth the setup. It keeps role assignment in the system your organization already governs, and new employees arrive with the right access on first sign-in.
Choose the Right Role
- Grant
account-adminsparingly. It includes SSO configuration, so anaccount-admincan change how every user in your account authenticates. - Use
account-application-adminfor the administrator who registers and maintains product instances but has no reason to touch identity configuration. - Assign
account-analytics-authorto anyone responsible for building dashboards who doesn't otherwise need administrative access. This is the role most often overlooked, and grantingaccount-admininstead is the usual mistake. - Leave everyone else as
account-user. It's the default, and it covers signing in, reaching applications, and viewing dashboards. - Don't assign
account-serviceto a person. It exists for programmatic access.
Users with the account-admin role always have unrestricted access to the support portal, even when you restrict support access to specific user groups. For more information, see Account Settings.