Role management
DataOps role management controls the scope of features that users can access and the operations they can perform in the DataOps Platform. Admins can assign suitable space roles to different members, and use custom roles to configure feature permissions at a finer granularity.
The DataOps Platform currently provides two preset roles: Space Admin and Data Developer. After custom roles are enabled, admins can create new roles based on how the organization actually divides work, and configure the scope of features that each role can view, edit, and use.
Permission management mainly covers the following scenarios:
- View roles and their permission scopes
- Create, edit, duplicate, and delete custom roles
- Bind roles to workspace members
- Adjust the role permissions of existing members
- Use role permissions to control page entries, action buttons, and feature usage
Prerequisites
Before you use DataOps permission management, make sure that your current account has the required management permissions.
| Scenario | Required permission |
|---|---|
| View Role Management and Member Management | View workspace roles and their permissions; view workspace members and permissions |
| Create or edit roles | Edit workspace roles and their permissions |
| Add, edit, or delete members | Edit workspace members and permissions |
| Maintain system-level DataOps roles in System Settings | Edit system members/roles and their permissions |
If your current account doesn't have the required permissions, page entries, buttons in the Actions column, or the Save button may not be visible. Contact your space/system admin to assign the relevant permissions.
Role types
In the DataOps feature permission system, roles are divided into preset roles and custom roles by effective scope and source.
| Role type | Description | Editable | Effective scope |
|---|---|---|---|
| System preset role | Roles provided by the system by default and maintained by the platform | No | All DataOps spaces |
| System custom role | Roles created by admins at the system level | Yes | All DataOps spaces |
| Space preset role | Roles provided by default in a workspace, such as Space Admin and Data Developer | No | Current workspace |
| Space custom role | Roles created by space admins in a workspace | Yes | Current workspace |
System-level roles affect all DataOps spaces; space-level roles only take effect in the current workspace.
Manage space roles
The Role Management page shows the roles available in a DataOps space and their feature permissions. On this page, admins can create space custom roles, or duplicate an existing role and then adjust its permission scope.
Role management list
The role management list usually groups roles by source, for example:
- System preset role
- System custom role
- Space preset role
- Space custom role
Different types of roles support different operations.
| Role type | Supported operations |
|---|---|
| System preset role | View permissions |
| System custom role | View permissions, duplicate; with system-level management permissions, also edit or delete |
| Space preset role | View permissions, duplicate |
| Space custom role | View permissions, edit, duplicate, delete |
Whether a specific button is shown depends on your current account's permissions and the actual state of the page.
View role permissions
After you select a role in the role list, you can view the feature permissions it has. Permissions are usually organized by feature module, and are divided into operation permissions such as view, edit, and feature usage.
Common permission modules include:
| Module | Permission examples |
|---|---|
| Workspace parameter management | View workspace parameters and settings; edit workspace parameters and settings |
| Space permission management | View role and member permissions; edit role and member permissions |
| Integration | View data sources, manage data sources, manage Offline Sync plans |
| Catalog / Link | View or manage Catalog tables, link views, and batch tasks |
| Development | View Flows, edit Flows, release Flows, manage data tables |
| Operations | View task instances; terminate, pause, and rerun task instances |
| IDE | Query data in the current workspace, and run SQL operations within the allowed scope |
Create a custom role
Admins with permission to edit roles can create custom roles.
- Go to Workspace Settings → Role Management.
- Click + Custom Role. In the dialog that appears, click Confirm (you can select I acknowledge, don't show again) to open the creation page.
- In Basic Information, enter the role name.
- In Access Detail, select the feature permissions that the role can use.
- Click Save.
Configure role permissions
When you create or edit a role, you can select the capabilities that the role has in the permission settings area. Permission settings usually include the following information:
| Field | Description |
|---|---|
| Suite / Module | The feature module that the permission belongs to, such as Integration, Dev, Ops, DataApp, and IDE |
| Feature | The specific feature, such as data sources or Flows |
| Permission | Operation types such as view, edit, and feature usage |
| Details | The page entries, buttons, or operations that the permission actually controls |
When you configure permissions, note the following:
- Edit permissions usually depend on the corresponding view permissions.
- If only view permissions are granted, users can usually only open pages or view details, and can't add, edit, delete, or perform similar operations.
- If the basic view permission for a feature isn't granted, the corresponding entry or detail page may not be visible.
Duplicate a role
If a new role's permissions are close to those of an existing role, you can create it quickly by duplicating the existing role.
- Find the target role in the role list.
- Click Duplicate.
- Change the role name.
- Adjust the permission settings as needed.
- Click Save.
Edit a custom role
After a space custom role is created, you can continue to edit it.
- Find the target custom role in the role list.
- Click Edit in the Actions column.
- Change the role name or permission settings.
- Click Save.
Changes to a role's permissions affect the members bound to the role. Before you make changes, check which members the role is currently bound to.
Assign space roles
You can assign space roles to members on the Member Management page of the space.
Add a space member and bind roles
- Go to Workspace Settings → Member Management.
- Click Add member in the upper-right corner.
- In the dialog, click Member and select the users you want to add.
- In the Role area, select the roles to grant.
- Click Save.
After the member is added, they appear in the member management list and have the feature permissions of the selected roles.
Edit an existing member's roles
To adjust an existing member's permissions, edit the member's roles.
- Go to Workspace Settings → Member Management.
- In the row of the target member, click Edit in the Actions column.
- Select the roles again in the dialog.
- Click Save.
After the role change is saved, the member's permissions are controlled by the new roles the next time they access the platform.
Maintain space members in System Settings
In addition to member management in Workspace Settings, system admins can also maintain DataOps space members from System Settings.
Entry points include:
- System Settings → DataOps Space → Members → Add member
- System Settings → DataOps Space → Members → Edit member
In these entry points, you also need to select DataOps space roles for members when you add or edit them. After custom roles are enabled, the dialog should show the available custom roles.
Permission control effects
Role permissions directly affect the page entries, buttons, and operations that users can see and perform.
| Permission type | Common effects |
|---|---|
| View permissions | Module entries are visible, and users can open list or detail pages |
| Edit permission | Buttons such as add, edit, delete, and batch operations are visible |
| Feature usage permission | Users can perform run or tool operations, such as manual execution, terminate, pause, and rerun |
Example:
- With View workspace roles and their permissions, users can open the role management page to view role permissions.
- With Edit workspace roles and their permissions, users can create, edit, duplicate, or delete space custom roles.
- With View workspace members and permissions, users can open the member management page to view the member list.
- With Edit workspace members and permissions, users can add members, edit member roles, or delete members.
Common configuration tips
Create roles by responsibility
We recommend creating roles based on actual responsibilities, rather than creating temporary roles for individual users. For example:
| Example role name | Intended for | Recommended permissions |
|---|---|---|
| Data Developer | Day-to-day developers | Common development permissions such as Dev, Integration, and IDE |
| Ops Viewer | Operations or support staff | Ops viewing and task instance viewing; grant terminate or rerun with caution |
| Space Permission Admin | Space owner | Member management, role management, workspace parameter management |
Duplicate first, then adjust
If an existing role's permissions are close to the target permissions, we recommend duplicating it first and then making small adjustments. This reduces the risk of missing basic view permissions.
Grant high-impact operations with caution
The following permissions affect online runs or members' access scope. We recommend granting them only to trusted people:
- Edit workspace members and permissions
- Edit workspace roles and their permissions
- Delete a workspace member
- Delete custom roles
- Terminate, pause, and rerun Flow instances
- Manually run sync plans
FAQ
Why can't I see the Workspace Settings entry?
Your current account may not have the view permissions related to space management. Contact your space admin to confirm whether your account's roles include the relevant permissions.
Why is there no button to create a custom role in Role Management?
Your current account may not have the permission to edit workspace roles and their permissions. Contact your space admin to confirm whether your account's roles include the relevant permissions.
When do role permission changes take effect?
After role permissions are saved, they affect the members bound to the role. We recommend that members refresh the page or reopen the relevant module to confirm.

