Group Privilege Reference

This applies to: Visual Data Discovery

Group privileges are specified on the Privileges tab in a group definition. Privileges allow a member of the Administrator's group to grant permission to perform specific Symphony functions to all members of a group.

use this work area to set privileges for groups of users

The following table describes each privilege and whether it is enabled by default when you create a new group.

UI Privilege Name Assign this privilege to allow group members to... Enabled by Default?
Administer Visuals

ROLE_ADMINISTER_VISUALS

Create, read, update, and delete visuals from dashboards or from the Visual Gallery in the account.

When the Administer Visuals privilege is granted, the privileges Create Visuals and Manage Visual Permissions are automatically granted. In addition, users with the Administer Visuals privilege are automatically granted read, write, and delete permissions to all visuals in the account. However, if they do not also have Data Access permission for the data source associated with a visual, they cannot see any data on the visual.

Only for the Administrators group.
Create Visuals

ROLE_CREATE_VISUALS

Create visuals in Symphony. Users must also have Read permission for the data source selected for the visual.

When the Administer Visuals privilege is granted, this privilege is also granted.

Only for the Administrators group.
Manage Visual Permissions

ROLE_PERMISSION_VISUALS

Assign permissions to a visual. When the Administer Visuals privilege is granted, this privilege is also granted. If this privilege is not granted, the icon and the Permissions column in the Visual Gallery do not appear in the UI. See About Visual Permissions.

 

Only for the Administrators group.
Administer Dashboards

ROLE_ADMINISTER_DASHBOARDS

Add, modify, or remove dashboards in the account, including dashboards created by other users.

When this privilege is granted, the Create Dashboards, Export Dashboards, and Manage Dashboard Permissions privileges are automatically granted.

Only for the Administrators group.
Create Dashboards

ROLE_CREATE_DASHBOARDS

Create dashboards in Symphony. If this privilege is not granted, the Add Dashboard button is not available in the dashboard library. In addition, if this privilege is not granted, you cannot import a dashboard or make of copy a dashboard using the Save As dialog.

When the Administer Dashboards privilege is granted, this privilege is automatically granted.

Yes
Export Dashboards

ROLE_EXPORT_DASHBOARDS

Export dashboard configuration JSON files. If this privilege is not granted, users in the group can still export dashboards as screenshots (PNG) or PDF files, but they cannot export the dashboard configuration.

When the Administer Dashboards privilege is granted, this privilege is automatically granted.

Yes
Manage Dashboard Permissions

ROLE_PERMISSION_DASHBOARDS

Assign permissions to a dashboard. If your user has the Administer Dashboards privilege, they automatically have this privilege as well. If this privilege is not granted, the permissions () icon and the Permissions column on the Library page do not appear in the UI. See About Dashboard Permissions.

Only for the Administrators group.
Administer Scheduled Reports

ROLE_ADMINISTER_DASHBOARD_REPORTS

Create, edit, and delete all scheduled dashboard reports. Grant Read access for dashboards to users who receive reports. Only for the Administrators group.
Create Scheduled Reports

ROLE_CREATE_DASHBOARD_REPORTS

Create, edit, and delete only your own scheduled dashboard reports. Only for the Administrators group.

Administer Tags

ROLE_ADMINISTER_TAGS

Create, assign, remove, and delete all content tags.

Only for the Administrators group.

Create Tags

ROLE_CREATE_TAGS

Create, assign, and remove tags. Delete your own content tags. Only for the Administrators group.
Administer Sources

ROLE_ADMINISTER_SOURCES

Create, import, export, modify, review, and remove data source configurations in the account.

When this privilege is granted, the Create New Data Sources, Manage Source Permissions and Edit Calculations privilege are also granted. In addition, users with the Edit Calculations privilege are automatically granted read, write, and delete permissions to all sources in the account.

Only for the Administrators group.
Create New Data Sources

ROLE_CREATE_SOURCES

Create new data source configurations.

When the Administer Sources privilege is granted, this privilege is also granted.

Only for the Administrators group.
Manage Source Permissions

ROLE_PERMISSION_SOURCES

Assign permissions to a data source configuration and manage data source row and column security filters. If your user has the Administer Sources privilege, they automatically have this privilege as well. If this privilege is not granted, the icon and the Permissions column on the Sources page do not appear in the UI. See About Data Source Permissions.

Only for the Administrators group.
Edit Calculations

ROLE_EDIT_FORMULAS

Add or edit custom metrics and derived fields.

Users with Read permission for a source and Edit Calculations can create and edit custom metrics and derived fields for the source.

Users with Write permission for a source can create and edit custom metrics and derived fields for the source.

Yes
Administer Alerts

ROLE_ADMINISTER_ALERTS

Add, modify, or remove alert definitions in the account, including alerts created by other users.

When this privilege is granted, the Create Alerts privilege is automatically granted.

Only for the Administrator's group
Create Alerts

ROLE_CREATE_ALERTS

Create alert definitions in Symphony.

When the Administer Alerts privilege is granted, this privilege is also granted.

Only for the Administrator's group
Manage Connections

ROLE_MANAGE_CONNECTIONS

Add, modify, or remove the data store connection definitions used by Symphony connectors and the query engine to connect to your data stores.

Only for the Administrators group.
Manage Action Templates

ROLE_MANAGE_ACTION_TEMPLATES

Add, modify, or remove the action templates required to integrate Symphony visual and dashboard data into your third-party applications. Action templates define your third-party application to Symphony. Only for the Administrators group.
Invoke Actions

ROLE_INVOKE_ACTIONS

Invoke an action template from a visual. Only for the Administrators group.
Administer Themes

ROLE_ADMINISTER_THEMES

Create, read, update, delete, list, activate, and otherwise manage themes for the UI. Only for the Administrators group.
Administer Users

ROLE_ADMINISTER_USERS

Administer other Symphony user definitions. When this privilege is granted, group users can:

  • Add, disable, and remove user definitions
  • Reset user passwords
  • Define user custom attributes and regional settings

This privilege does not allow group members to update groups or the groups to which a user is assigned. If your user ID is not assigned the Administer Groups privilege or is not an administrator, you cannot assign groups to a user. In addition, only administrators can assign users to the Administrators group.

Only for the Administrators group.
Administer Groups

ROLE_ADMINISTER_GROUPS

Administer other Symphony group definitions. When this privilege is granted, group users can:

  • Add or remove group definitions
  • Assign and remove users in a group definition
  • Authorize users in the group to perform specific Symphony functions

This privilege does not allow group members to add or otherwise maintain user definitions.

Only for the Administrators group.
Save Filters

ROLE_SAVE_FILTERS

Save (and share) filters created in visuals and dashboards. When this privilege is not granted, the Save Filter privilege does not appear on Filter dialogs in the UI.

Yes
Manage Custom Charts

ROLE_MANAGE_VISUALIZATION_TYPES

When you have this privilege, you can use the CLI to create custom charts, and manage custom charts using the Symphony UI. Only for the Administrators group.
Generate Embed Code

ROLE_GENERATE_EMBED_CODE

Generate an embeddable dashboard or visual gallery snippet for a dashboard in the dashboard library or the visual gallery. See Embed Symphony Components Into Your Application. Only for the Administrators group.
Administer Initial Visuals

ROLE_ADMINISTER_INITIAL_VISUALS

Users with this privilege have permission to update the list of available visualizations for a source. See Available Visual Types. Only for the Administrators group.