Managing Project Permissions

A user’s project access is determined by their project role. By default, each user inherits project roles based on their tenant role:

  • Tenant admins are granted the project admin, editor, and viewer roles.
  • Tenant editors are granted the project editor and viewer roles.
  • Tenant viewers are granted the project viewer role.
  • Users with no tenant role are not granted any project roles.

In Admin Center > Projects, tenant admins can review which users and groups have access to each project and their roles, and can manage project role assignments.

See Project Roles for information about the permissions allowed for each role.

Granting Project Roles

Project roles can be granted to individual users or to configured user groups.

To grant project roles:

  1. On the Admin Center > Projects page, select the Manage Permissions icon for the project.

  2. In the Manage Project Permissions page, select the user or user group from the User or Group dropdown menu, select the Role, and select Grant.

  3. To assign the user or group an additional role (for example, both editor and viewer roles), repeat step 2 and choose the additional role.



Removing a Project Role

You can remove granted roles from users and groups.

Important : You cannot remove project roles inherited from tenant roles. Non-editable inherited roles are identified with gray check marks in the table. To restrict the inherited permissions in a specific project, you must first change the user’s or group’s tenant role. Then, you can remove project roles that are no longer needed for that user or group.

To change a user's data product roles:

  1. On the Admin Center > Projects page, select the Manage Permissions icon for the project.

  2. Move your mouse over the blue checkmark for the user's role in the table.

  3. When the blue check becomes a red X, select the X to remove the role from the user.