Global permissions
A global permission is a permission that applies across all Collibra applications. It can be added to a global role.
The following table contains an overview of the global permissions and the default configuration of the out-of-the-box global roles.
Note Users with roles that have permissions with Read-only required licenses that start or participate in workflows count towards the Standard effective licenses for the month in which the workflow participation occurs.
Use these options to filter the columns of the table to your needs:
Global permission | Global permission | Description | Required license | New license | AI Business User (Standard) |
AI Legal Reviewer (Standard) |
Assessments (Read-only) |
Assessments Admin (Standard) |
Assessments Template Manager (Standard) |
Catalog (Read-only) |
Catalog Author (Standard) |
Data Dictionary (Read-only) |
Data Marketplace
(Read-only) |
Data Notebook Admin (Standard) |
Data Notebook Editor (Standard) |
Data Quality Integration (Read-only) |
DataSteward (Read-only) |
DataSteward Author (Standard) |
Edge integration engineer (Standard) |
Edge Management API (Read-only) |
Edge manager (Standard) |
Edge site (Standard) |
Edge site administrator (Standard) |
Export (Read-only) |
Glossary (Read-only) |
Helpdesk (Read-only) |
Import (Read-only) |
Insights (Standard) |
Policy Manager (Read-only) |
Privacy User (Read-only) |
Protect Admin (Standard) |
Protect Author (Standard) |
Protect Manager (Standard) |
Protect Reader (Read-only) |
ReferenceData (Read-only) |
Sysadmin (Standard) |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Assessments | Assessments | The Assessments global permission contains a global permission that allows users to view and manage all assessments. | ||||||||||||||||||||||||||||||||||
Administration
|
Assessments |
The Assessments > Administration global permission allows users to perform administrative tasks in Assessments. They can view all private assessments and change the permissions of all assessments. |
Read-only | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Conduct assessments
|
Assessments |
The Assessments > Conduct assessments global permission allows users to conduct, edit, copy, delete, and make assessments obsolete, including only public assessments and those that they own or are assigned. |
Standard | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage templates
|
Assessments |
The Assessments > Manage templates global permission allows users to view, create, edit, and manage assessment templates. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Notebook | Data Notebook | The Data Notebook global permission contains global permissions that allow users to manage data notebooks. | ||||||||||||||||||||||||||||||||||
Manage all notebooks
|
Data Notebook |
The Data Notebook > Manage all notebooks allows users to manage notebooks. Tip A user who has this permission can view the content in all the notebooks regardless of who created the notebooks, even including private notebooks via direct links. Therefore, consider giving this permission to only users who have the Sysadmin global role. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage data sources
|
Data Notebook
|
The Data Notebook > Manage data sources allows users to register data sources for Data Notebook and also remove the registered data sources. | Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage settings
|
Data Notebook
|
The Data Notebook > Manage settings allows users to customize settings for Data Notebook, such as chart colors and number formatting in query results. | Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Edge |
Edge |
The Edge global permission contains global permissions that allow users to install and manage Edge sites. Note Currently, Edge is an on-demand cloud service. It will only become the default service once the migration from Jobserver to Edge is complete. |
||||||||||||||||||||||||||||||||||
Manage connections and capabilities
|
Edge |
The Edge > Manage connections and capabilities permission allows users to add, edit and delete connections and capabilities. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Install Edge sites
|
Edge |
The Edge > Install Edge sites permission allows users to download the installer and properties file that you need to install an Edge site. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Connect as Edge site to Collibra
|
Edge |
The Edge > Connect as Edge site to Collibra permission allows Edge sites to connect to Collibra Data Intelligence Platform. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage Edge sites
|
Edge |
The Edge > Manage Edge sites permission allows users to create, edit and delete Edge sites. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Edge connections and capabilities
|
Edge |
The Edge > View Edge connections and capabilities permission allows users to open and see the connections and capabilities of an Edge site. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View logs from Edge site
|
Edge |
The Edge > View logs from Edge sites permission allows users to download JDBC log files from the Jobs Dashboard. | Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Catalog |
Catalog |
The Catalog global permission contains global permissions that allow users to use advanced features of Data Catalog. |
||||||||||||||||||||||||||||||||||
Advanced Data Type
|
Catalog |
The Catalog > Advanced Data Type permission group contains global permissions that allow users to manage advanced data types. |
||||||||||||||||||||||||||||||||||
Add
|
Catalog |
The Catalog > Advanced Data Type > Add global permission allows users to create advanced data types. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Update
|
Catalog |
The Catalog > Advanced Data Type > Update global permission allows users to edit advance data types. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Remove
|
Catalog |
The Catalog > Advanced Data Type > Remove global permission allows users to delete advanced data types. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Register Profiling Information
|
Catalog |
The Catalog > Register Profiling Information global permission allows API users to enable data profiling when registering a data source. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Technical Lineage
|
Catalog |
The Catalog > Technical Lineage global permission allows users to see the technical lineage of a data source. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Classification |
Classification |
The Classification permission group contains global permissions that allow users to use the new data classification method via Edge. |
||||||||||||||||||||||||||||||||||
Classify
|
Catalog |
The Classification > Classify global permission allows users to classify columns via the new classification method. |
Standard | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Classes
|
Classification |
The Classification > Data Classes permission group contains global permissions that allow users to manage data classes in the new data classification method. |
||||||||||||||||||||||||||||||||||
Add
|
Classification |
The Classification > Data Classes > Add global permission allows a user to add new data classes in the new data classification method. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Update
|
Classification |
The Classification > Data Classes > Update global permission allows a user to modify data classes in the new data classification method. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
List Values
|
Classification |
The Classification > Data Classes > List Values global permission allows the Edge Site to communicate with Collibra in the new data classification method. This permission should be enabled only for the Edge Site user. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Read
|
Classification |
The Classification > Data Classes > Read global permission allows a user to view the data classes in the new data classification method. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Remove
|
Classification |
The Classification > Data Classes > Update global permission allows a user to delete data classes in the new data classification method. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Workflow |
Workflow |
The Workflow permission group contains global permissions that allow users to manage workflows. |
||||||||||||||||||||||||||||||||||
View all running tasks
|
Workflow |
The Workflow > View all running tasks global permission allows users to see ongoing tasks that are assigned to other users in the All Tasks tab on the tasks page. |
Standard | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Use workflow message events
|
Workflow |
The Workflow > Use workflow message events global permission allows users to pass message events to the workflow engine via an API call. Note This is used for API users. |
Read-only | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Participate in workflow
|
Workflow |
The Workflow >Participate in workflow global permission allows users that meet workflow task configuration requirements to be assigned and complete workflow tasks. | Read-only | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Start workflow
|
Workflow |
The Workflow > Start workflow global permission allows users that meet workflow configuration requirements to start workflows. | Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Product Rights |
Product Rights |
The Product Rights permission group contains global permissions that allow users to access Collibra applications. |
||||||||||||||||||||||||||||||||||
AI Governance
|
Product Rights AI Governance |
The Product Rights > AI Governance global permission allows users to access AI Governance. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Assessments
|
Product Rights Assessments |
The Product Rights > Assessments global permission allows users to access Assessments. They can view public assessments and the assessments that they own or are assigned. |
Read-only | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Business Semantics Glossary
|
Product Rights |
The Product Rights > Business Semantics Glossary global permission allows users to access the Business Glossary application. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Catalog
|
Product Rights |
The Product Rights > Catalog global permission allows users to access the Data Catalog application and Data Classification. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Dictionary
|
Product Rights |
The Product Rights > Data Dictionary global permission allows users to access the Data Dictionary application. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Helpdesk
|
Product Rights |
The Product Rights > Data Helpdesk global permission allows users to access the Data Helpdesk application. |
Read-only | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Marketplace
|
Product Rights |
The Product Rights > Data Marketplace global permission allows users to access standalone Data Marketplace and Data Marketplace in Search. | Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Notebook
|
Product Rights |
The Product Rights > Data Notebook global permission allows users to access Data Notebook and create notebooks. For more details, go to Data Notebook permissions. | Standard | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Quality
|
Product Rights |
The Product Rights > Data Quality global permission allows users to access the assets, relations, and workflows required to support the integration of Collibra Data Intelligence Platform with Collibra Data Quality & Observability. | Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Data Stewardship Manager
|
Product Rights |
The Product Rights > Data Stewardship Manager global permission allows users to access the Stewardship application. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Edge
|
Product Rights Edge |
The Product Rights > Edge global permission allows users to manage Edge. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Guided Stewardship
|
Product Rights |
The Product Rights > Guided Stewardship global permission allows users to access Guided Stewardship tools such as the Physical Data Connector. |
Read-only | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Policy Manager
|
Product Rights |
The Product Rights > Policy Manager global permission allows users to access the Policy Manager application. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Privacy
|
Product Rights |
The Product Rights > Privacy global permission allows users to access the Privacy landing page. | Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Protect
|
Product Rights Protect |
Go to Protect roles and permissions. | Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Reference Data Manager
|
Product Rights |
The Product Rights > Reference Data Manager global permission allows users to access the Reference Data application. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
System Administration
|
Product Rights |
The Product Rights > System Administration global permission allows users to manage all sections of the Collibra Settings, including the general settings, the operating model , roles, permissions, users, groups and workflows. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
User Administration
|
Product Rights |
The Product Rights > User Administration global permission allows users to manage users and groups. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Workflow Administration
|
Product Rights |
The Product Rights > Workflow Administration global permission allows users to access the Workflow tab page of the Collibra Settings. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Workflow Designer access
|
Product Rights |
The Product Rights > Workflow Designer access global permission allows users to access the Workflow Designer application from the Collibra menu. Note This permission becomes available after you enable the Allow access to the Workflow Designer Collibra configuration setting. |
Read-only | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Protect | Protect | Go to Protect roles and permissions. | ||||||||||||||||||||||||||||||||||
Resources |
Resources |
The Resources permission group contains global permissions that allow users to see and manage assets, domains and communities. | ||||||||||||||||||||||||||||||||||
Export
|
Resources |
The Resources > Export global permission allows users to export assets or complex relations and their characteristics. |
Read-only | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Import
|
Resources |
The Resources > Import global permission allows users to import assets or complex relations. Users that have a role with this permission can also create or edit communities and domains that are related to the imported assets. |
Read-only | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage all resources
|
Resources |
The Resources > Manage all resources global permission allows users to see and manage all communities and domains, and assets whose type belongs to a product whose Product Right the user has, regardless of responsibilities. Note This permission does not include the Export and Import permissions. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Views, Dashboards, Search filters |
Views, Dashboards, Search filters |
The Views, Dashboards, Search filters permission group contains global permissions that allow users to manage and share views, dashboards and search filters. |
||||||||||||||||||||||||||||||||||
Manage shared Views, Dashboards, Search filters
|
Views, Dashboards, Search filters |
The Views, Dashboards, Search filters > Manage shared Views, Dashboards, Search filters global permission allows users to share, edit and delete views, dashboards and search filters that are shared. |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Manage your own Views, Dashboards, Search filters
|
Views, Dashboards, Search filters |
The Views, Dashboards, Search filters > Manage your own Views, Dashboards, Search filters global permission allows users to edit and delete your own views, dashboards and search filters. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Share your own Views, Dashboards, Search filters
|
Views, Dashboards, Search filters |
The Views, Dashboards, Search filters > Share you own Views, Dashboards, Search filters global permission allows users to share your own views, dashboards and search filters. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Permissions |
View Permissions |
The View Permissions permission group contains global permissions that allow users to see all views, which includes dashboards, diagram views, asset views, search filters and relation views on an asset page. |
||||||||||||||||||||||||||||||||||
View All
|
View Permissions |
The View Permissions > View All global permission allows users to see all communities, domains and the assets within them, thus ignoring view permissions. |
Read-only | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Insights |
Insights |
The Insights global permission contains global permissions related to Insights Data Access and Usage Analytics. |
||||||||||||||||||||||||||||||||||
Download the Insights reporting data
|
Insights |
The Insights > Download the Insights reporting data global permission allows users to download the data from the Insights Data Access API (formerly called Reporting Data Layer). |
Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Insights reports
|
Insights |
The Insights > View Insights reports global permission allows users to access the dashboard widgets. |
Read-only | Viewer |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Usage Analytics Summary
|
Insights |
The Insights > View Usage Analytics Summary global permission allows users to access the Usage Analytics dashboard, excluding the detailed usage data. |
Read-only | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View Usage Analytics reports
|
Insights |
The Insights > View Usage Analytics reports global permission allows users to access the Usage Analytics dashboard, including the detailed usage data, and also download the data. | Read-only | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Tags |
Tags |
The Tags permission group contains global permissions that allow users to see and manage tags in the Stewardship application. | ||||||||||||||||||||||||||||||||||
Manage tags
|
Tags |
The Tags > Manage tags global permission allows users to edit and delete tags on the tags page in the Stewardship application. | Standard | Creator |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
View tags
|
Tags |
The Tags > View tags global permission allows users to see the Tags Overview page in the Stewardship application. | Read-only | Contributor |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|