Manage Custom Roles

Overview

Analytics Plus allows you to create custom user roles, beyond the predefined ones, to control what users can access and do within a workspace. Custom roles let you create permission sets that match the responsibilities of specific users or teams, without changing their organization-level roles.

With custom roles, you can:

  • Grant fine-grained permissions instead of the broader permission set bundled in a predefined role.
  • Give users access to all views of a selected entity in a shared workspace, without sharing each view individually.
  • Allow users to create reports and dashboards without granting administrator privileges.

The Server Administrator and Managers can create and manage custom roles.

What is in this page

How custom roles differ from predefined roles

CapabilityCustom roleViewerManagerWorkspace Administrator
Access to existing viewsAll views in the workspace based on the selected permissionsOnly views explicitly shared with themOnly views explicitly shared with themAll views in the workspace
Access to new viewsAutomatic for the selected entityNo, until sharedNo, until sharedAutomatic
Create or modify reportsYes, if grantedNoNoYes
Add or modify dataYes, if grantedNoYes, in shared tables.Yes
Administrative privilegesNoneNoneNoneAll, except renaming, deleting, or backing up the workspace

Create a custom role

  1. Click the Settings icon at the top right of your account.
  2. In the left panel, click Manage Workspace Roles under User Management.
  3. Click Add New Role. The Create Role dialog opens.

  4. In the Role Name field, enter a name for the role.
  5. In the Access Permissions section, select the entities the role can access: All Dashboards, All Reports And Dashboards, or All Data, Reports And Dashboards. The remaining options vary based on this selection.
  6. Select the other permissions the role requires.
  7. Click Add. The role is created and listed in the Manage Roles page. You can now assign it to your users.

Custom role permissions

A custom role's permissions are broadly categorized into Access permissions, Create permissions, Data permissions, Desgin permissions, Interaction permissions, Sharing and collaboration permissions and Publishing permissions. The overarching scope of a custom role is set by the Access permissions you select when you create the role. Selecting a broader option automatically includes the narrower ones; for example, selecting All Reports And Dashboards also selects All Dashboards.

Access permissions

  • All Dashboards: Gives access to all dashboards in the shared workspace. This suits users such as a CIO who views dashboards for analysis but does not work with reports or data.
  • All Reports And Dashboards: Gives access to all reports and dashboards in the shared workspace. Users with this permission can also create dashboards and folders. Creating reports requires access to data, so it is available only with the All Data, Reports And Dashboards permission.
  • All Data, Reports And Dashboards: Gives access to the data, reports, and dashboards in the shared workspace. Users with this permission can create tables and import data, create query tables, use formula columns and aggregate formulas, and create reports and dashboards.

The remaining permissions all depend on the Access permission selected for the custom role.

Create Permissions

PermissionDescriptionAll Dashboards access permissionAll Reports And Dashboards access permissionAll Data Reports And Dashboards access permission
Create DashboardsAllows users to create dashboards.-YesYes
Create ReportsAllows users to create and edit reports.--Yes
Create Table Import DataAllows users to create tables and import data.--Yes
Create Query TableAllows users to create query tables.--Yes
Formula Column Aggregate Formula Bucket ColumnAllows users to add formulas and bucket columns.--Yes
Create FolderAllows users to create folders.YesYesYes

Data Permissions

Available only with the All Data Reports And Dashboards access permission.

PermissionDescription
Add RowUsers can add rows to the table.
Delete RowUsers can delete rows in the table.
Modify RowUsers can modify rows in the table.
Only Append RowsUsers can only append rows in the table while importing.
Delete All Rows And Add New RowsUsers can delete all rows and append rows in the table while importing.
Add Or Update RowsUsers can append and modify rows in the table while importing.
Add New Replace Existing And Delete Missing RowsUsers can add, update, and delete rows in the table while importing.
Create Modify And Delete Data ArchivesUsers can create, modify, and delete data archives.

Note:

  • Archive permissions can be enabled only when all other data permissions are enabled.

Design Permission

Users can edit the structure of tables, reports, and dashboards, including adding and deleting columns, lookup columns, and accessing report settings.

Interaction Permissions

These permissions are available for every access permission type.

PermissionDescription
Read AccessGrants read access. Selected by default and cannot be cleared.
View Underlying DataUsers can view the underlying data of reports.
Drill DownUsers can drill down reports.
Drill ThroughUsers can drill through reports.
Drill ActionsUsers can use drill actions in reports.
Zia InsightsUsers can use Zia Insights to get narrative analysis.
GenAI SkillsUsers can use GenAI skills.

Sharing & Collaboration Permissions

Available for all access permission types.

PermissionDescription
Share Views / Child ReportsUsers can re-share views and child views.
Commenting ActionsUsers can comment on shared views.
Private LinksUsers can generate private links of tables, reports and dashboards for easy collaboration.
Access Admin/Owner PresetsUsers can access presets (saved combinations of dashboard user filters) created by admins and owners.
Allow Preset Creation

Users can create presets (saved combinations of dashboard user filters).

Publishing Permissions

PermissionDescriptionAll Dashboards access permissionAll Reports And Dashboards access permissionAll Data, Reports And Dashboards access permission
ExportUsers can export and email data.YesYesYes
Manage Email SchedulesUsers can create and manage email schedules. The ManageEmailSchedulecreatedbythem link allows you to restrict which schedules can be managed.YesYesYes
Manage Data AlertsUsers can create and manage data alerts. The ManageAlertscreatedbythem link allows you to restrict which alerts can be managed.-YesYes
Create SlideshowUsers can create slideshow links for views.YesYesYes

Manage custom roles

The Server Administrator and Manager can manage custom roles from Settings >>User Management >> Manage Roles.

Assign users to a custom role

Users can be assigned a custom role either from the Manage Workspace Roles in the Settings page or from the Manage Users section of a workspace's settings.

From the Settings page:

  1. Open Settings >> User Management >> Manage Workspace Roles.
  2. Navigate to the required custom role, and click the Select a workspace to assign users icon that appears on mouse over.
  3. Select the required workspace and users.
  4. Click Save.

From a Workspace:

  1. Open the required workspace.
  2. Go to Settings >> Manage Users.
  3. Click Add Users or select an existing user.
  4. Assign the required custom role.
  5. Save the changes.

Change an existing user to a custom user role

You can change a user’s role either from the Manage Users page within a workspace or from the Manage Workspace Roles page from the Settings page.

From Manage Users within a workspace:

  1. Open the required workspace and go to Settings >>Manage Users.
  2. Select the required user.
  3. Click Change role.
  4. Choose the required custom role.
  5. Click Apply.

From Manage Workspace Roles:

  1. Go to Settings >>User Management >> Manage Workspace Roles.
  2. Select the required custom role.
  3. Select the workspace.
  4. Select the user to whom you want to assign the role.
  5. Click Save.

Change a workspace administrator to a custom role

  1. Open Workspace Settings >> Manage Users.
  2. Select the required user.
  3. Change the user from Workspace Administrator to the required custom role.
  4. Click Apply.

Note:

  • If a user assigned to a custom role is removed from a workspace, the role assignment for that workspace is also removed. The user retains any organization-level predefined role, such as Manager, but no longer has access to that workspace through the custom role.

A user can be assigned different custom roles across workspaces, but only one role can be assigned within workspace.

Edit a custom role

  1. Hover over the role and click Edit.
  2. Update the required permissions.
  3. Click OK.

Duplicate a custom role

  1. Hover over the role and click Duplicate.
  2. Update the role name, if needed.
  3. Click OK.

Delete a custom role

  1. Select one or more custom roles.
  2. Click Delete Roles.
  3. Confirm the deletion.

Before deleting a role, reassign its users to another appropriate role so they retain the access they need.

Frequently asked questions

1. Who can create custom roles? 

The Server Administrator and Manager user roles can create, edit, duplicate, and delete custom roles.

2. How many custom roles can I create?

You can create any number of custom roles in your organization. A user can be assigned different custom roles across multiple workspaces, with a maximum of one role per workspace. Licensing is calculated based on the number of users, not the number of roles assigned to them.

3. How many users can I assign to a custom role?

You can assign a custom role to any number of users. Each user can have different custom roles across different workspaces, but only one role can be assigned per workspace. Licensing is calculated based on the number of users in your organization, not the roles assigned to them.

4. Can users with a custom role share views?

Yes. Users with a custom role can share the views they have access to if the role includes the Share Views / Child Reports permission under Sharing & Collaboration Permissions.

5. What happens to custom roles if I downgrade my plan?

All users who were assigned a custom role are changed to the predefined User role. Their custom roles are restored when you upgrade again.