> ## Documentation Index
> Fetch the complete documentation index at: https://docs.k16solutions.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions

> Understand the current role editor and the access needed for customer workflows.

Open **Settings** > **Roles** and select a role to review its permissions. You need role-management permission to change a custom role. System roles are read-only.

The editor shows permissions relevant to your workspace's products. The tables below describe the visible options, not a guarantee that every option appears in every workspace. Data visibility remains subject to entity and column access.

## Organization settings

| Section or permission | Action     | What it allows                                                                                        |
| --------------------- | ---------- | ----------------------------------------------------------------------------------------------------- |
| **Users**             | **Create** | Send and cancel user invitations.                                                                     |
| **Users**             | **Manage** | Edit members and roles, deactivate or reactivate accounts, send password-reset emails, and reset MFA. |
| **Users**             | **Delete** | Remove users from the workspace.                                                                      |
| **Roles**             | **Create** | Create new role definitions.                                                                          |
| **Roles**             | **Manage** | Update existing role definitions.                                                                     |
| **Roles**             | **Delete** | Delete existing role definitions.                                                                     |
| **Integrations**      | **View**   | Open the integrations page and inspect integration details.                                           |
| **Integrations**      | **Manage** | Create, edit, duplicate, and delete integrations.                                                     |
| **Security policies** | **Manage** | Open security admin pages and update workspace authentication policies.                               |
| **Single sign-on**    | **View**   | Open the SSO admin list and view identity provider settings.                                          |
| **Single sign-on**    | **Manage** | Create, edit, and delete SAML/OIDC identity providers.                                                |

## Archive

| Section or permission          | What it allows                                                         |
| ------------------------------ | ---------------------------------------------------------------------- |
| **Access documents**           | View archived document folders and files.                              |
| **View enrolled courses**      | View only courses where the user is enrolled.                          |
| **View courses**               | View archived course data without editing it.                          |
| **Restore courses**            | Restore soft-deleted courses in the LMS.                               |
| **Sync courses**               | Sync archived courses to the LMS.                                      |
| **View people**                | Access the Archive People directory.                                   |
| **Access SIS accounts**        | Access the SIS Accounts directory and account details.                 |
| **Access SIS student data**    | View enrollments, academic history, test scores, and learner outcomes. |
| **Access SIS financial aid**   | View financial aid records for SIS accounts.                           |
| **Access SIS finance**         | View grants and purchasing details for SIS accounts.                   |
| **Access SIS human resources** | View human resources records for SIS accounts.                         |
| **Create course imports**      | Open course import creation and start new course import runs.          |

## Analytics

| Section or permission           | What it allows                                   |
| ------------------------------- | ------------------------------------------------ |
| **Access worksheets**           | Create, edit, and manage Analytics worksheets.   |
| **View reporting**              | View embedded Reporting dashboards.              |
| **Manage reporting**            | Manage Reporting dashboards and content.         |
| **View AI Detection reporting** | View embedded AI Detection reporting dashboards. |
| **Access AI Assistant**         | Use the in-app DataX AI assistant.               |

## Documentation

| Section or permission        | What it allows                                                      |
| ---------------------------- | ------------------------------------------------------------------- |
| **Manage business glossary** | Create, edit, version, publish, and delete business glossary terms. |

## Lakehouse

| Section or permission            | What it allows                                                              |
| -------------------------------- | --------------------------------------------------------------------------- |
| **Manage blueprints**            | Create, edit, version, publish, and delete blueprints.                      |
| **Manage snapshots**             | Create, edit, and delete Lakehouse snapshots and schedules.                 |
| **Manage scheduled exports**     | Create, edit, run, and delete scheduled Lakehouse exports.                  |
| **Manage data imports**          | Create, review, publish, and delete Lakehouse data imports.                 |
| **Manage Snowflake connections** | Generate, rotate, and delete Snowflake service-user connection credentials. |

## AI tools

| Section or permission    | What it allows                                                    |
| ------------------------ | ----------------------------------------------------------------- |
| **Access Snowflake MCP** | Connect external MCP clients to workspace-scoped Snowflake tools. |

## Related permissions

K16 adds prerequisite access when you select a dependent action. For example, managing integrations also grants viewing, and managing reporting also grants viewing. SIS student, financial aid, finance, and human-resources access depend on SIS account access. Clearing a parent permission can clear dependent selections; review the whole group before saving.

**View enrolled courses** restricts course visibility to the user's enrollments. **View courses** provides archived-course viewing. **Restore courses** and **Sync courses** are separate actions; viewing a course alone does not authorize either.

The **Data access** settings page requires **Manage** under **Roles** and DataX availability. Use [the access matrix](/administration/data-access/roles) to grant entity and masking-tag access separately from product permissions.

MCP setup is an [alpha connection workflow](/account/datax-mcp-alpha). Its availability is determined by your workspace and account; do not infer MCP access from the assistant permission.

## Verify a role change

1. Select only the actions required for the user's work.
2. Review automatically selected dependencies and any group-wide selections.
3. Select **Save changes**.
4. Reopen the role and check the saved selections.
5. Verify the intended workflow with a test member assigned to the role, including data that should remain unavailable.

See [Manage users](/administration/users/manage-users) to assign the role and [Manage roles](/administration/roles/manage-roles) to create or delete a custom role.
