Identity Broker Default Roles
The AtScale Identity Broker provides a number of default realm roles that control the actions users can perform.
These roles can be divided into two groups: simple and complex roles. Simple roles define the actions users can perform, like deploy catalogs or access the Aggregates page. Complex roles are groups of simple roles.
The following sections describe the complex and simple roles available in the Identity Broker. For information on assigning roles in the Identity Broker, see Managing Users with the Identity Broker.
Complex roles
The following table describes the complex roles available in the Identity Broker, as well as the simple roles associated with each.
| Role | Description | Associated Roles |
|---|---|---|
admin | Access the Settings page, Support page, and Identity Broker; access the Power BI tab of the Settings page to view/manage the Power BI reports connected to AtScale and update service tokens for them; set global configuration properties; administer users, roles, and groups; administer runtime permissions on catalogs/models; link, edit, and unlink Git repositories; grant or revoke the superuser_user role for other users; bypass all access control checks on catalogs/models. | repository_project_publish, superuser_user, application_admin, aggregates_view, datawarehouses_admin, support_logs_view, query_dataset_api_view, queries_view, aggregates_manage, repository_project_manage, repository_project_read, tableau_admin, powerbi_manage |
application_admin | Perform all tasks covered by the admin role, except make changes in the Identity Broker. | offline_access, queries_manage, repository_project_manage, repository_project_publish, superuser_user, application_admin, aggregates_view, uma_authorization, query_user, datawarehouses_admin, support_logs_view, impersonation_user, default-roles-atscale, designcenter_user, query_dataset_api_view, queries_view, aggregates_manage, repository_project_read, datawarehouses_manage, powerbi_manage |
designcenter_user | Access Design Center; interact with query datasets; link, edit, and unlink Git repositories; access the Queries page and cancel queries; publish catalogs; add, edit, and delete data warehouses; access repositories; access the Aggregates page and User Settings tab of the Settings page; view deployed catalogs in the Deployed Catalogs panel; view the list of deployed models and their connection strings on the Power BI > DAX Connections tab of the Connection Portal. | query_dataset_api_view, repository_project_manage, queries_manage, repository_project_publish, datawarehouses_manage, repository_project_read, aggregates_manage |
query_user | Automatically assigned to all users via the everyone group. Access models from BI tools and execute queries on them; access the Queries page and cancel queries; view deployed catalogs in the Deployed Catalogs panel; generate access URLs on the Power BI > Access details tab of the Connection Portal; view the list of connected Power BI reports and update tokens for them on the Power BI > Reports tab of the Connection Portal; view the list of deployed models and their connection strings on the Power BI > DAX Connections tab of the Connection Portal. | queries_manage, queries_view, repository_project_read, powerbi_connect |
Simple roles
The following table describes the simple roles available in the Identity Broker.
| Role | Description |
|---|---|
aggregates_manage | Access the Aggregates page, view aggregates, activate/deactivate aggregates, access the User Settings tab of the Settings page, invalidate aggregates for deployed models. |
aggregates_view | Access the Aggregates page, view aggregates. |
datawarehouses_admin | Access the Data Warehouses page; view, add, manage, and delete all data warehouses connected to AtScale. |
datawarehouses_manage | Add data warehouses; view, edit, and delete data warehouses the user has access to. |
default-roles-atscale | For system use only. |
impersonation_user | Impersonate other users when connecting to AtScale. This is used to configure impersonation for data warehouses, client BI tools, etc. |
metadata_access | Automatically assigned to the xmla-service-account user. Grants the xmla-service-account user XMLA metadata discovery permissions without requiring access to the data warehouse. This is required for Microsoft Power BI Gateway connections with service tokens. |
offline_access | For system use only. |
powerbi_connect | Generate access URLs on the Power BI > Access details tab of the Connection Portal; view the list of connected Power BI reports and update tokens for them on the Power BI > Reports tab of the Connection Portal. |
powerbi_manage | Access the Power BI tab of the Settings page to view/manage the Power BI reports connected to AtScale and update service tokens for them. |
queries_manage | Access the Queries page, cancel queries. |
queries_view | Access the Queries page, access outbound query details returned by the AtScale MCP Server. |
query_dataset_api_view | Preview, save, and interact with query datasets. |
repository_project_manage | Link, edit, and unlink Git repositories via the Workspace panel. |
repository_project_publish | Deploy catalogs. Note that read access to deployed catalogs on the Deployed Catalogs panel requires the user to also have the repository_project_read role. |
repository_project_read | View deployed catalogs in the Deployed Catalogs panel; view the list of deployed models and their connection strings on the Power BI > DAX Connections tab of the Connection Portal. |
superuser_user | Set global configuration properties; administer runtime permissions on catalogs/models; bypass all access control checks on catalogs/models. AtScale requires that you always have at least one user with the superuser_user role. |
support_logs_view | View and download support logs. |
tableau_admin | View, add, edit, delete, and publish to any Tableau Server definition, regardless of its permissions; access the Tableau tab of the Settings page. |
tableau_manage | View, add, edit, delete, and publish to Tableau Server definitions the user has access to; access the Tableau tab of the Settings page. |
uma_authorization | For system use only. |