Understanding privileges
If you are trying to do something in ThoughtSpot, and cannot access the screens to accomplish it, you may not have the correct privileges. In this case, you should contact your administrator and explain what you want to accomplish. Your administrator may be able to grant you additional privileges.
| Permissions to see and edit Answers and Liveboards are not affected by privileges. They are given when these items are shared with you. |
|
If your ThoughtSpot instance has RBAC v2 object-control privileges enabled, you may also see Can create Liveboards, Can create Answers, Can analyze data, and Can administer schedules in your privilege list. These are described in the following section. |
Here are the privileges that the administrator sets, and the capabilities they enable:
- Can administer ThoughtSpot
-
Can manage users and groups and has view and edit access to all data. Users with this privilege can also download a saved Answer.
- Can administer Org
-
This privilege is only available if your organization is using multi-tenancy with Orgs. Can manage users and groups and has view and edit access to all data. Users with this privilege can also download a saved Answer. If a user has this privilege in the Primary Org, they are also a cluster administrator, and can view and manage users, groups, and data for all Orgs across the cluster. If a user has this privilege in any other Org, they are only an Org administrator, and can only view and manage users, groups, and data for their specific Org(s). Refer to Cluster administrators and Org administrators for more information.
- Can upload user data
-
Can upload their own data from the application’s Data page using Actions > Upload data.
This privilege is only available to Free Trial and Team Edition users. - Can download data
-
Can download data from search results and Liveboards.
- Can share with all users
-
Can see the names of and share with users outside of the groups the user belongs to. Members of groups with this privilege can also share with groups marked as NOT SHAREABLE.
- Can manage data
-
Can create connections. To view or edit other people’s connections, you must have the Can administer ThoughtSpot privilege.
Can create Models and views.
Note that to edit a Model or a view created by another user, you must have the Edit permission on that object, and it must be shared with you.
Can create SQL views.
- Can manage sync
-
Can use ThoughtSpot Sync to set up secure pipelines to external business apps and sync data. Note that users with admin privileges see all pipelines and syncs created by their team through the Sync tab in the Data workspace, while users without admin privileges see only the syncs and pipelines they personally create.
- Can use Spotter
-
Users with this privilege can use ThoughtSpot Spotter features. For more information, see Spotter.
- Can manage Spotter
-
Users with this privilege can manage how Spotter behaves across the organization — global coaching, memory, Spotter instructions, and Spotter Analysts. Implies Can use Spotter. Does not allow editing data models.
- Can access AgentSpot
-
Users with this privilege can access and use AgentSpot to build and run agents.
- Can manage AgentSpot
-
Users with this privilege can manage AgentSpot at the Org level (admin-level configuration), and use AgentSpot to build and run agents.
- Can manage catalog
-
Users with this privilege can set up or edit a connection to a catalog. User setting up the catalog connection can also configure which fields to display or hide on the column and table level knowledge cards.
- Can schedule for others
-
Allows users to create scheduled Liveboard jobs for other users.
If RBAC v2 object-control privileges are enabled on your cluster, Can administer schedules supersedes this privilege and grants broader org-wide schedule management. See RBAC v2 object-control privileges.
- Can create Liveboards Early Access
-
Allows users to create, copy, edit, save, delete, and rename Liveboards; pin Answers; rename pinned Answers; request Liveboard verification; and work with Liveboard TML. When revoked, Liveboard creation and editing options are hidden. This privilege requires Can create Answers to be present in the same role.
- Can create Answers Early Access
-
Allows users to access Search Data, create and edit Answers, use formulas and parameters, create query sets and cohorts, and work with Answer TML. When revoked, Search Data is hidden and the search bar is disabled.
- Can analyze data Early Access
-
Allows users to use Explore, Drill Down, AI Highlights, Change Analysis, and Show Underlying Data. When revoked, all analysis features are hidden from Answers and Liveboards.
- Can administer schedules Early Access
-
Grants CRUD access over all schedules in the Org. Users with this privilege can manage schedules created by other users, view all recipients, and override download-format restrictions in schedule contexts. This privilege is additive — it is not assigned by default.
- Has SpotIQ privilege
-
Can use the SpotIQ feature.
If this privilege is not enabled for the user, they can still see "Did you know" SpotIQ insights on the ThoughtSpot home page.
- Can administer and bypass RLS
-
Users in groups with this privilege (directly or through group inheritance):
-
Are exempt from row-level security (RLS) rules.
-
Can add/edit/delete existing RLS rules.
-
Can check or uncheck Bypass RLS on a Model.
Your installation configuration may enable or disable the availability of this privilege. By default, it is enabled. Administrators or groups with the privilege Can administer ThoughtSpot can grant this privilege.
-
- Has Developer privilege
-
Can access and use the ThoughtSpot Developer Portal to explore the ThoughtSpot APIs and developer tools, and build web applications with ThoughtSpot content.
The following table shows the intersection of user privilege and ability:
|
|
Create/Edit WS
|
Create View
|
Create Connection
|
Modify Col. Props.1
|
Download Data
|
Share within Group
|
Share with all users
|
Manage and bypass RLS rules
|
CrUD Relationships
|
Read Relationships
|
See Hidden Cols
|
Join with Upload Data
|
Schema Viewer
|
Use Scheduler
|
Use Auto-Analyze
|
Access Developer Portal
|
Run Sage queries
|
Access AgentSpot
|
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Can administer ThoughtSpot | Y | Y | Y | Y | Y | Y | Y | Y | Y2 | Y | Y | Y | Y | Y | Y | Y | N | N |
|
Can download data
|
N | N | N | N | Y | Y | N | N | N | Y4 |
N | N | N | N | N | N | N | N |
Can manage data |
Y | Y | Y | Y | N | Y | N | N | Y4 |
Y4 |
Y5 |
Y | N | N | N | N | N | N |
Can share with all users |
N | N | N | N | N | Y | Y | N | N | Y4 |
N | N | N | N | N | N | N | N |
Has SpotIQ privilege |
N | N | N | N | N | N | N | N | N | Y4 |
N | N | N | N | Y | N | N | N |
Can Administer and Bypass RLS |
N | N | N | N | N | Y | N | Y | Y | N | N | N | N | N | N | N | N | N |
| Can manage sync | Y | Y | Y | Y | N | Y | N | N | Y4 |
Y4 |
Y5 |
Y | N | N | N | N | N | N |
| Can use Spotter | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | Y | N |
| Can manage Spotter | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | Y | N |
| Can manage catalog | Y | Y | Y | Y | N | Y | N | N | Y4 |
Y4 |
Y5 |
Y | N | N | N | N | N | N |
| Has Developer privilege | N | N | N | N | N | Y | N | N | N | N | N | N | N | N | N | Y | N | N |
| Can access AgentSpot | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | Y |
| Can manage AgentSpot | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | Y6 |
| None | N | N | N | N | N | Y | N | N | N | Y4 |
N | N | N | N | N | N | N | N |
Table notes:
| ||||||||||||||||||