Global permissions
A global permission is a permission that applies across all Collibra applications. It can be added to a global role.
The following table contains an overview of the global permissions and the default configuration of the out-of-the-box global roles.
Note Users with roles that have permissions with Read-only required licenses that start or participate in workflows count towards the Standard effective licenses for the month the workflow participation occurs in.
Use these options to filter the columns of the table to your needs:
Global permission | Global permission | Description | Required license | AI Governance (Read-only) |
Assessments (Read-only) |
Assessments Admin (Read-only) |
Catalog (Read-only) |
Catalog Author (Standard) |
Data Dictionary (Read-only) |
Data Marketplace (Read-only) | DataSteward (Read-only) |
DataSteward Author (Standard) |
Edge integration engineer (Author) (Standard) |
Edge manager (Standard) |
Edge site (Standard) |
Edge site administrator (Standard) |
Export (Read-only) |
Glossary (Read-only) |
Helpdesk (Read-only) |
Import (Read-only) |
Insights (Standard) |
Policy Manager (Read-only) |
Privacy User (Read-only) | ReferenceData (Read-only) |
Sysadmin (Standard) |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Assessments | Assessments | The Assessments global permission contains a global permission that allows users to view and manage all assessments. | |||||||||||||||||||||||
Administration
|
Assessments Administration |
The Assessments > Administration global permission allows users to view and manage all assessments. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Catalog |
Catalog |
The Catalog global permission contains global permissions that allow users to use advanced features of Data Catalog. |
|||||||||||||||||||||||
Advanced Data Type
|
Catalog Advanced Data Type |
The Catalog > Advanced Data Type permission group contains global permissions that allow users to manage advanced data types. |
|||||||||||||||||||||||
Add
|
Catalog Advanced Data Type Add |
The Catalog > Advanced Data Type > Add global permission allows users to create advanced data types. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Remove
|
Catalog Advanced Data Type Remove |
The Catalog > Advanced Data Type > Remove global permission allows users to delete advanced data types. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Update
|
Catalog Advanced Data Type Update |
The Catalog > Advanced Data Type > Update global permission allows users to edit advance data types. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Register Profiling Information
|
Catalog Register Profiling Information |
The Catalog > Register Profiling Information global permission allows API users to enable data profiling when registering a data source. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Technical Lineage
|
Catalog Technical Lineage |
The Catalog > Technical Lineage global permission allows users to see the technical lineage of a data source. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Classification |
Classification |
The Classification permission group contains global permissions that allow users to use the new data classification method via Edge. |
|||||||||||||||||||||||
Classify
|
Catalog Classify |
The Classification > Classify global permission allows users to classify columns via the new classification method. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Classes
|
Classification Data Classes |
The Classification > Data Classes permission group contains global permissions that allow users to manage data classes in the new data classification method. |
|||||||||||||||||||||||
Add
|
Classification Data Classes Add |
The Classification > Data Classes > Add global permission allows a user to add new data classes in the new data classification method. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
List Values
|
Classification Data Classes List Values |
The Classification > Data Classes > List Values global permission allows the Edge Site to communicate with Collibra in the new data classification method. This permission should be enabled only for the Edge Site user. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Read
|
Classification Data Classes Read |
The Classification > Data Classes > Read global permission allows a user to view the data classes in the new data classification method. Note The Classification > Data Classes > Read permission is not enforced yet to open the Data Classification page in Stewardship. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Update
|
Classification Data Classes Update |
The Classification > Data Classes > Update global permission allows a user to modify data classes in the new data classification method. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Remove
|
Classification Data Classes Remove |
The Classification > Data Classes > Update global permission allows a user to delete data classes in the new data classification method. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Edge |
Edge |
The Edge global permission contains global permissions that allow users to install and manage Edge sites. Note Currently, Edge is an on-demand cloud service. It will only become the default service once the migration from Jobserver to Edge is complete. |
|||||||||||||||||||||||
Connect as Edge site to Collibra
|
Edge Connect as Edge site to Collibra |
The Edge > Connect as Edge site to Collibra permission allows Edge sites to connect to Collibra Data Intelligence Platform. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Install Edge sites
|
Edge Install Edge sites |
The Edge > Install Edge sites permission allows users to download the installer and properties file that you need to install an Edge site. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage Edge sites
|
Edge Manage Edge sites |
The Edge > Manage Edge sites permission allows users to create, edit and delete Edge sites. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage connections and capabilities
|
Edge Manage connections and capabilities |
The Edge > Manage connections and capabilities permission allows users to add, edit and delete connections and capabilities. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Edge connections and capabilities
|
Edge View Edge connections and capabilities |
The Edge > View Edge connections and capabilities permission allows users to open and see the connections and capabilities of an Edge site. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View logs from Edge site
|
Edge View logs from Edge sites |
The Edge > View logs from Edge sites permission allows users to download JDBC log files from the Jobs Dashboard. | Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
||
Insights |
Insights |
The Insights global permission contains global permissions related to Insights Data Access and Usage Analytics. |
|||||||||||||||||||||||
Download the Insights reporting data
|
Insights Download the Insights reporting data |
The Insights > Download the Insights reporting data global permission allows users to download the data from the Insights Data Access API (formerly called Reporting Data Layer). |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Insights reports
|
Insights View Insights reports |
The Insights > View Insights reports global permission allows users to access the dashboard widgets. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Usage Analytics Summary
|
Insights View Usage Analytics summary |
The Insights > View Usage Analytics Summary global permission allows users to access the Usage Analytics dashboard, excluding the detailed usage data. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Usage Analytics reports
|
Insights View Usage Analytics reports |
The Insights > View Usage Analytics reports global permission allows users to access the Usage Analytics dashboard, including the detailed usage data, and also download the data. | Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Product Rights |
Product Rights |
The Product Rights permission group contains global permissions that allow users to access Collibra applications. |
|||||||||||||||||||||||
AI Governance
|
Product Rights AI Governance |
The Product Rights > AI Governance global permission allows users to access AI Governance. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Assessments
|
Product Rights Assessments |
The Product Rights > Assessments global permission allows users to access Collibra Assessments. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Business Semantics Glossary
|
Product Rights Business Semantics Glossary |
The Product Rights > Business Semantics Glossary global permission allows users to access the Business Glossary application. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Catalog
|
Product Rights Catalog |
The Product Rights > Catalog global permission allows users to access the Data Catalog application and Data Classification. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Dictionary
|
Product Rights Data Dictionary |
The Product Rights > Data Dictionary global permission allows users to access the Data Dictionary application. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Helpdesk
|
Product Rights Data Helpdesk |
The Product Rights > Data Helpdesk global permission allows users to access the Data Helpdesk application. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Marketplace
|
Product Rights Data Marketplace |
The Product Rights > Data Marketplace global permission allows users to access the Data Marketplace application. | Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Stewardship Manager
|
Product Rights Data Stewardship Manager |
The Product Rights > Data Stewardship Manager global permission allows users to access the Data Stewardship application. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Edge
|
Product Rights Edge |
The Product Rights > Edge global permission allows users to manage Edge. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Policy Manager
|
Product Rights Policy Manager |
The Product Rights > Policy Manager global permission allows users to access the Policy Manager application. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Privacy
|
Product Rights Privacy |
The Product Rights > Privacy global permission allows users to access the Privacy landing page. | Read-only |
|
|
|
|
|
|
||||||||||||||||
Protect
|
Product Rights Protect |
Go to Protect global roles and permissions. | Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Reference Data Manager
|
Product Rights Reference Data Manager |
The Product Rights > Reference Data Manager global permission allows users to access the Reference Data application. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
System Administration
|
Product Rights System Administration |
The Product Rights > System Administration global permission allows users to manage all sections of the Collibra Settings, including the general settings, the operating model , roles, permissions, users, groups and workflows. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
User Administration
|
Product Rights User Administration |
The Product Rights > User Administration global permission allows users to manage users and groups. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Workflow Administration
|
Product Rights Workflow Administration |
The Product Rights > Workflow Administration global permission allows users to access the Workflow tab page of the Collibra Settings. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Workflow Designer access
|
Product Rights Workflow Designer access |
The Product Rights > Workflow Designer access global permission allows users to access the Workflow Designer application from the Collibra menu. Note This permission becomes available after you enable the Allow access to the Workflow Designer Collibra configuration setting. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Protect | Protect | Go to Protect global roles and permissions. | |||||||||||||||||||||||
Resources |
Resources |
The Resources permission group contains global permissions that allow users to see and manage assets, domains and communities. | |||||||||||||||||||||||
Export
|
Resources Export |
The Resources > Export global permission allows users to export assets or complex relations and their characteristics. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Import
|
Resources Import |
The Resources > Import global permission allows users to import assets or complex relations. Users that have a role with this permission can also create or edit communities and domains that are related to the imported assets. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage all resources
|
Resources Manage all resources |
The Resources > Manage all resources global permission allows users to see and manage all communities and domains, and assets whose type belongs to a product whose Product Right the user has, regardless of responsibilities. Note This permission does not include the Export and Import permissions. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Tags |
Tags |
The Tags permission group contains global permissions that allow users to see and manage tags in the Data Stewardship application. | |||||||||||||||||||||||
Manage tags
|
Tags Manage tags |
The Tags > Manage tags global permission allows users to edit and delete tags on the tags page in the Data Stewardship application. | Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View tags
|
Tags View tags |
The Tags > View tags global permission allows users to see the Tags Overview page in the Data Stewardship application. | Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Permissions |
View Permissions |
The View Permissions permission group contains global permissions that allow users to see all views, which includes dashboards, diagram views, asset views, search filters and relation views on an asset page. |
|||||||||||||||||||||||
View All
|
View Permissions View All |
The View Permissions > View All global permission allows users to see all communities, domains and the assets within them, thus ignoring view permissions. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Views, Dashboards, Search filters |
Views, Dashboards, Search filters |
The Views, Dashboards, Search filters permission group contains global permissions that allow users to manage and share views, dashboards and search filters. |
|||||||||||||||||||||||
Manage shared Views, Dashboards, Search filters
|
Views, Dashboards, Search filters Manage shared Views, Dashboards, Search filters |
The Views, Dashboards, Search filters > Manage shared Views, Dashboards, Search filters global permission allows users to share, edit and delete views, dashboards and search filters that are shared. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage your own Views, Dashboards, Search filters
|
Views, Dashboards, Search filters Manage your own Views, Dashboards, Search filters |
The Views, Dashboards, Search filters > Manage your own Views, Dashboards, Search filters global permission allows users to edit and delete your own views, dashboards and search filters. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Share your own Views, Dashboards, Search filters
|
Views, Dashboards, Search filters Share your own Views, Dashboards, Search filters |
The Views, Dashboards, Search filters > Share you own Views, Dashboards, Search filters global permission allows users to share your own views, dashboards and search filters. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Workflow |
Workflow |
The Workflow permission group contains global permissions that allow users to manage workflows. |
|||||||||||||||||||||||
Use workflow message events
|
Workflow Use workflow message events |
The Workflow > Use workflow message events global permission allows users to pass message events to the workflow engine via an API call. Note This is used for API users. |
Read-only |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View all running tasks
|
Workflow View all running tasks |
The Workflow > View all running tasks global permission allows users to see ongoing tasks that are assigned to other users in the All Tasks tab on the tasks page. |
Standard |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|