Skip to main content
Every user on the platform has a role and a set of privileges. The role controls whether they can access the platform’s administrative features. Privileges control which perimeters they can access and what they can do there.

Roles

A user’s role determines what actions they can take on the platform. The role does not, on its own, grant access to any particular perimeter’s work.

Privileges

Privileges grant access to the work inside a perimeter. A user holds unique privileges for each perimeter they work in. A user might have Execute privileges on one perimeter, View on another, and no access to a third. For example, a data scientist is typically a Member with Execute privileges on their team’s perimeters, letting them run workloads there without any ability to manage the platform. This separation keeps everyday work and platform administration distinct; for instance, granting someone the ability to run workloads doesn’t also give them control over the platform’s configuration.

Managing roles and privileges

Administrators assign roles and grant perimeter privileges.