Open Settings > Roles and select a role to review its permissions. You need role-management permission to change a custom role. System roles are read-only.
The editor shows permissions relevant to your workspace’s products. The tables below describe the visible options, not a guarantee that every option appears in every workspace. Data visibility remains subject to entity and column access.
Organization settings
Archive
Analytics
Documentation
Lakehouse
K16 adds prerequisite access when you select a dependent action. For example, managing integrations also grants viewing, and managing reporting also grants viewing. SIS student, financial aid, finance, and human-resources access depend on SIS account access. Clearing a parent permission can clear dependent selections; review the whole group before saving.
View enrolled courses restricts course visibility to the user’s enrollments. View courses provides archived-course viewing. Restore courses and Sync courses are separate actions; viewing a course alone does not authorize either.
The Data access settings page requires Manage under Roles and DataX availability. Use the access matrix to grant entity and masking-tag access separately from product permissions.
MCP setup is an alpha connection workflow. Its availability is determined by your workspace and account; do not infer MCP access from the assistant permission.
Verify a role change
- Select only the actions required for the user’s work.
- Review automatically selected dependencies and any group-wide selections.
- Select Save changes.
- Reopen the role and check the saved selections.
- Verify the intended workflow with a test member assigned to the role, including data that should remain unavailable.
See Manage users to assign the role and Manage roles to create or delete a custom role. Last modified on September 16, 2026