Visual Designer
Roles & Permissions
Workspace-scoped role-based access control — workspace admin, member, and viewer roles govern who can do what across connections, datasets, and settings.
What it does
Every workspace member has a role — workspace admin, member, or viewer — and that role determines what they can do across connections, datasets, saved queries, storage, and workspace settings. A system admin role exists separately for cross-workspace administration. Adding someone to a workspace is done through an email invitation carrying a specific role; the invite link expires and the recipient sets their own password.
What it doesn't do yet
Two enterprise-governance features are explicitly on the roadmap rather than available today: an Activity & Audit Log (no activity history is currently recorded), and User Groups, which is also where SSO and LDAP/Active Directory group sync are planned. Authentication today is local email and password only. Nothing on this site claims otherwise — wherever these are mentioned, they're marked "Coming Soon."
Common use cases
Frequently asked questions
Workspace-level roles are workspace admin, member, and viewer, each with different permissions across connections, datasets, saved queries, storage, users, and workspace settings. A separate system admin role applies across workspaces.
See the Roles & Permissions node in the Visual Designer.