Visual Designer

Roles & Permissions

Workspace-scoped role-based access control — workspace admin, member, and viewer roles govern who can do what across connections, datasets, and settings.

What it does

Every workspace member has a role — workspace admin, member, or viewer — and that role determines what they can do across connections, datasets, saved queries, storage, and workspace settings. A system admin role exists separately for cross-workspace administration. Adding someone to a workspace is done through an email invitation carrying a specific role; the invite link expires and the recipient sets their own password.

What it doesn't do yet

Two enterprise-governance features are explicitly on the roadmap rather than available today: an Activity & Audit Log (no activity history is currently recorded), and User Groups, which is also where SSO and LDAP/Active Directory group sync are planned. Authentication today is local email and password only. Nothing on this site claims otherwise — wherever these are mentioned, they're marked "Coming Soon."

Common use cases

Give an analyst view-only access without letting them edit connections
Invite a new teammate by email with a defined role
Separate who can manage workspace settings from who can just build workflows

Frequently asked questions

Workspace-level roles are workspace admin, member, and viewer, each with different permissions across connections, datasets, saved queries, storage, users, and workspace settings. A separate system admin role applies across workspaces.

See the Roles & Permissions node in the Visual Designer.