Skip to main content
DataGenie uses a three-tier access model — Global, Tenant, and Dataset — to give the right people the right permissions without overexposing sensitive data.

When to use each role

RoleBest for
ReaderBusiness users who consume autonomous insights — VPs of Analytics, directors, managers. View-only, no dataset or detection changes.
EditorAnalysts and data operators who tune detection — add panels, save Wisdom queries, adjust KPI definitions within their scope.
AdminDataset owners responsible for schedules, AD Groups, and access control for their datasets.
Global AdminPlatform administrators managing users, tenants, and workspace defaults.
Be deliberate about who receives Editor and Admin access. Changes to KPI definitions, processing schedules, or AD Group assignments cascade across all stories and analyses downstream.

How to map roles and assign permissions

1

Open the Users and Mapping screen

Navigate to Configuration from the sidebar and open Users and Mapping. This screen shows all users in your organization and their current role assignments across the three access tiers.
Navigating to Configuration and opening the Users and Mapping screen showing all organization users
2

Find the user and click Manage Roles

Locate the user whose permissions you want to update, then click Manage Roles next to their name. Their role management panel opens, showing the full three-tier structure — Global, Tenant, and Dataset — ready to configure.
Finding a user in the list and clicking Manage Roles to open their role management panel
3

Assign a Global Role

Select a Global Role to set the user’s organization-wide baseline permissions. The Global Role is the broadest tier — Global Admin grants full platform control, while Reader restricts the user to view-only access across all workspaces.
Selecting a Global Role from the dropdown to set the user's organization-wide baseline permissions
4

Set Tenant-level permissions

Select the user’s Tenant-level permissions — Reader or Editor — for specific workspaces. Tenant-level access governs how the user interacts with the datasets and features within that workspace, narrowing the scope set by their Global Role.
Selecting Reader or Editor Tenant-level permissions for specific workspaces in the role panel
5

Assign Dataset-level access

For granular control, assign Reader, Editor, or Admin access per dataset. Dataset-level permissions are the most specific tier — use them to restrict access to sensitive datasets or grant elevated rights on a single dataset without changing the user’s workspace-wide role.
Assigning Reader, Editor, or Admin access to individual datasets in the dataset-level permissions panel
6

Create or modify Custom Roles

If the built-in roles don’t match your organization’s structure, admins can define and modify Custom Roles in the advanced settings. Custom roles let you combine specific capabilities — for example, a role that can view all datasets but only edit one specific KPI group.
Admins opening the advanced settings to define and modify custom roles for organization-specific needs
7

Review all role assignments across tiers

After configuring each tier, review the complete role summary to verify assignments at Global, Tenant, and Dataset levels. Check that each tier reflects the intended permissions before saving — changes to Editor and Admin access cascade across stories, analyses, and downstream features.
Reviewing the complete role assignment summary showing Global, Tenant, and Dataset tier permissions for a user
8

Confirm the complete three-tier access setup

Do a final check of the full role structure — Global baseline, Tenant workspace access, and Dataset-level permissions — to confirm everything is configured correctly. Once saved, the user’s access updates immediately across the platform.
Final overview of the complete three-tier role structure showing Global, Tenant, and Dataset permissions all configured

Role types

Full access to all features, datasets, users, and workspace configuration. Can create and customize roles.
Interact with and modify content — add dashboard panels, save Wisdom queries, edit dataset configurations within permitted scope.
View-only access to assigned features and datasets. Ideal for insight consumers who shouldn’t change detection logic.
Admins create and customize roles for organization-specific needs.
Keep roles simple. Use the smallest number of roles that still matches how your teams work, then apply dataset-level access where necessary.

What’s next

User addition & SSO

Add users manually or via SSO — enterprise identity provider configuration.

Datasets

The datasets access control applies to.

Security & Trust

SSO, audit, data residency, and Trust Center.