The exact roles in your workspace are institution-specific. This reference describes the
permission areas represented in the current K16 application.
Separate feature access from data access
Workspace configuration makes a product available. Your role then controls which pages and actions you can use. DataX data access separately controls the entities and protected columns available to that role. Permissions are specific to each action. For example, integration View does not grant Manage, and Manage snapshots does not grant Manage scheduled exports. Creating users, managing existing users, and deleting users also have separate permissions. Use the role permission catalog for the exact options exposed in the role editor. It covers Archive, Analytics, Documentation, Lakehouse, organization settings, and AI tools.System roles and custom roles
Your workspace can include system roles and institution-defined roles. System roles provide a stable baseline. Custom roles let administrators combine permissions for a specific responsibility.Review access safely
1
Start with the person's job
List the product areas and actions the person must use. Avoid granting a broad administrative
role only to expose one action.
2
Choose the narrowest role
Reuse an existing role when its permissions match the responsibility. Create a custom role when
the existing roles are too broad.
3
Check data access separately
Product permissions and granular data access solve different problems. A person can have
worksheet access while still being limited to approved tables or columns.
4
Verify the result
Confirm the person can complete the intended workflow and cannot open unrelated administrative
or data-management actions.