Skip to main content

Available Console user permissions and roles

To set a user's permissions, navigate to Settings > Users and then to the user whose account you'd like to manage.

What permissions can be set?​

Snowplow Console sets permissions for each area of Console as summarized below:

Console featureDescriptionPossible permissions
User managementThe management and addition of user access. This permission cannot be configured on a Custom role.No access
Edit
Create
EnvironmentsThe management of pipeline and development environments. This includes managing which Enrichments run on each environment.No access
View
Edit
Tracking plansThe management and creation of tracking plans.No access
View
Edit
Create
Data structuresThe management and creation of the schemas that define the events and entities you are capturing.No access
View
Edit on development
Edit on production
Create
Data modelsThe management and creation of your data models.No access
View
Edit
Create
API keysThe management and creation of API keys.No access
View
Manage

How are permissions set?​

To set permissions for a user, navigate to Settings > Users and select the user, within the management screen for their user you will be able to set their permissions.

There are three ways of setting user permissions:

  • Global Admin (pre-defined role)
  • User (pre-defined role)
  • Custom (custom permissions role)

The following tables describe the default permissions for each role.

User permission set​

Console featurePermissions
EnvironmentsView access
User managementView access
Tracking plansView access
Data structuresView access
Data modelsView access
API keysView access

Global Admin permission set​

Console featurePermissions
User managementFull access
EnvironmentsFull access
Tracking plansFull access
Data structuresFull access
Data modelsFull access
API keysFull access

Custom permission set​

Console featurePermissions
User managementCustomized by you, per user
EnvironmentsCustomized by you, per user
Tracking plansCustomized by you, per user
Data structuresCustomized by you, per user
Data models & jobsCustomized by you, per user
API keysCustomized by you, per user
API keys and permissions

A Snowplow API key is scoped to the permissions selected when it is created, and can never hold more than its creator's own permissions. Two exceptions apply:

  • Keys marked Global admin on the API keys page have full admin permissions. Replace them with scoped keys and delete them.

  • Iglu Server keys authenticate directly against the Iglu Server, so they bypass Console permissions entirely.

Set the API keys permission so that only trusted users can create new Iglu Server keys.

What does each permission mean?​

Environments​

An environment is the collective name for your Production pipelines, QA pipelines and development environments.

An environment has three permissions:

  • No access - the user will not see the environment management screens.
  • View - the user can see the environment management screen, but cannot edit anything. This is the default setting for the User role.
  • Edit - the user can make edits to the environment. This includes configuration such as enrichment enablement, enrichment configuration and collector configuration.

Tracking plans​

Tracking plans have four permissions:

  • No access - the user will not see the tracking plan management screens.
  • View - the user can see the tracking plan management screens, but cannot edit anything. This permission and all tracking plan permissions below require the user to have at least the View permission on data structures.
  • Edit - the user can see the tracking plan management screens, and can make edits to existing tracking plans.
  • Create - the user can create new tracking plans.

Data structures​

Data structures have five permissions:

  • No access - the user will not see the data structure management screen.
  • View - the user can see the data structure management screen, but cannot edit anything.
  • Edit on development - the user can see the data structure management screen, and can make edits to data structures but only publish them to the development registry.
  • Edit on production - the user can see the data structure management screen, and can make edits to data structures, and can publish changes to the production registry.
  • Create - the user can create new data structures.

Data models​

Data models and jobs have four permissions:

  • No access - the user will not see the data model management screens.
  • View - the user can see the data model management screens, but cannot edit anything. This is the default setting for the User role.
  • Edit - the user can see the data model management and can make edits to data models in production. This is the default setting for the Global Admin role.
  • Create - the user can create new data models.

API keys​

API keys have four permissions:

  • No access - the user will not see the API key management screens.
  • View - the user can see the API key descriptions but cannot see the keys themselves or manage them.
  • Manage - the user can see and manage the API keys.
  • Create - the user can generate new API keys.

Troubleshooting​

You shouldn’t be required to logout for new permissions to take effect, but if you do find permissions aren’t applying as requested logging out and back in should force the new permissions to apply.