> ## Documentation Index
> Fetch the complete documentation index at: https://docs.k16solutions.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage data access by role

> Select roles and configure their DataX view access in one matrix.

Open **Settings** > **Data access** to control DataX access independently from general workspace permissions.

<Note>
  You need **Manage** access under **Roles** and DataX availability to open and change the matrix.
  The page can hide protected system roles unless your own role is allowed to manage them.
</Note>

## Select roles to compare

1. Open **Roles** in the toolbar.
2. Use **Search roles…** to find the roles you need.
3. Select individual roles, or use **Select all** to select or clear the filtered list.
4. Close the picker and review the selected roles as columns in the access matrix.

The role picker shows each role's granted and total DataX privileges. **New in DataX** means the organization role exists but does not yet have a saved DataX access record.

## Grant or revoke access

Each matrix row represents an entity, a future-entity rule, or a column-masking tag.

* Select a checkbox to change one role and one resource.
* Select a section-level control to grant or revoke all rows in that section for a role.
* A check mark means all resources in the section are granted.
* A minus sign means only some resources in the section are granted.

<Warning>
  Section-level controls can change many resources at once. Expand the section and review its rows
  before you use them.
</Warning>

## Save or reset

The toolbar shows **No changes** or the number of changed records.

* Select **Save changes** to create or update the affected DataX role records.
* Select **Reset** to discard all unsaved changes in the matrix.
* If a partial save fails, read the displayed error and verify the affected roles before retrying.

## Recommended review

1. Select a single role.
2. Search for the expected entity or constraint.
3. Confirm each granted row.
4. Save.
5. Sign in with a test member assigned to that role and verify the accessible data.

General workspace permissions and DataX data access are separate. A role may be able to open a DataX feature without being able to view every entity within it.

See [Entities and column constraints](/administration/data-access/entities-and-columns) and [Permissions](/administration/roles/permissions).
