Built-in Roles

Monte Carlo provides several built-in roles that cover most common access patterns.
The comparison table below provides high-level information about each role to help select between them.

For detailed information on each role, including allowed and denied permissions, jump to the Roles Detail section below. You can also click the role name in the table to go directly to the role's details. We deny by default, so only the explicitly listed allowed permissions will be granted for a role.

Comparing Roles

The roles are ordered by least to most restrictive.

RoleDescription
Account OwnerFull access--able to do anything customers are allowed to do with their Monte Carlo account.

Recommended for: Those responsible for configuring and managing all aspects of the Monte Carlo account (including integrations, billing, security, etc.).

Restrictions: None.
Domains ManagerAllows access to all data + AI workflow features as well as managing personal API keys, data products, and domain-related settings such as domains, domain groups/users, ingestion, and notifications.

Recommended for: Data/team/product leads who will assist in administration of domains and users.

Restrictions: Cannot edit most account settings except for domain-related settings. No billing or secret value access.
EditorAllows access to all data + AI workflow features, as well as managing personal API keys, their own data products, and ingestion and notifications settings.

Recommended for: Data engineers that manage pipelines and data as a part of their job duties.

Restrictions: Cannot edit most account settings except for ingestion and notifications settings. No billing or secret value access.
Monitor EditorAllows access to most data + AI workflow features, as well as managing personal API keys, their own data products, and notifications settings.

Recommended for: Those who will add metric and validation monitors to key tables and pipelines.

Restrictions: Monitor-focused settings onlyβ€”no catalog editing, account management, or billing/secret value access.
ResponderAllows read-only access to data + AI workflow features plus alert response actions. May also draft monitors.

Recommended for: Those who triage and respond to alerts but will not manage Monte Carlo configuration/settings.

Restrictions: Only able to respond to alerts. No changing account settings and no billing or secrets access.
ViewerAllows read-only access to data + AI workflow features. May also draft monitors.

Recommended for: Those who may benefit from understanding data + AI quality issues but who are not responsible for fixing them.

Restrictions: Mostly read only. No changing account settings, no billing access, and no access to secret values.

Roles Detail

In the Permission list for each role, only the permissions specifically allowed (βœ…) or denied (❌) for the role are listed.
If a permission is not listed, a user with only that role would be denied. Note that a user's
effective permissions are a combination of all the roles assigned to the authorization groups they are a member of.

You can hover over the βœ… or ❌ icon to see which policy statement allows or denies the permission.
You can use the Definition tab to see the complete role definition with all of its policy statements.

Deprecated permissions are omitted from these lists.

Account Owner

Full access--able to do anything customers are allowed to do with their Monte Carlo account.

Restrictions: None.

Recommended for: Those responsible for configuring and managing all aspects of the Monte Carlo account (including integrations, billing, security, etc.).

Role name: mcd/owner

Built-in authorization group: Account Owners

Permission Description
βœ… Alerts β†’ Access Allow viewing alerts and their details.
βœ… Alerts β†’ Edit Allow editing alerts, including merging, splitting, and updating properties.
βœ… Alerts β†’ Update Status Allow updating alert status (e.g., acknowledging, resolving) and providing feedback on anomaly detections.
βœ… Assets β†’ Access Allow viewing the assets catalog and asset metadata.
βœ… Assets β†’ Edit Allow editing asset metadata in the catalog.
βœ… Dashboard β†’ Access Allow viewing dashboards.
βœ… Dashboard β†’ Edit Allow creating and editing all dashboards in the account.
βœ… Dashboard β†’ Edit Their Own Allow creating and editing only dashboards the current user created. Those with `dashboard/edit` permission can also edit these dashboards.
βœ… Data Exports β†’ Access Allow accessing and downloading data exports.
βœ… Data Products β†’ Access Allow viewing data products.
βœ… Data Products β†’ Edit Allow creating and editing all data products in the account.
βœ… Data Products β†’ Edit Their Own Allow creating and editing only data products the current user created. Those with `data-products/edit` permission can also edit these data products.
βœ… GraphQL β†’ Mutate Allow making modifications (executing mutations) via the GraphQL API. This is required for any writes. This is always asserted in addition to any more specific permissions.
βœ… GraphQL β†’ Query Allow reading data (executing queries) via the GraphQL API. This is required for baseline read-only access to the system, and is always asserted in addition to any more specific permissions.
βœ… Lineage β†’ Access Allow viewing lineage graphs and their metadata.
βœ… Lineage β†’ Edit Allow creating and editing lineage metadata (nodes, edges, etc.).
βœ… MCP β†’ Access Allow authenticating to MCP and using read-only MCP tools.
βœ… MCP β†’ Edit Allow authenticating to MCP and using tools that modify account data or configuration.
βœ… Monitors β†’ Aggregates Allow viewing monitor metrics and aggregate summaries without full monitor access. Used for dashboards and reporting.
βœ… Monitors β†’ Data Sampling β†’ Access Allow accessing sampled data from tables. Required to view sample data in the UI.
βœ… Monitors β†’ Data Sampling β†’ Download Allow downloading sampled data from tables.
βœ… Monitors β†’ Exceptions β†’ Access Allow viewing monitor exception activity logs.
βœ… Monitors β†’ Exceptions β†’ Edit Allow editing monitor exceptions, including updating attributes and adding comments.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Access Allow viewing agent evaluation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Draft Allow creating and editing draft agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Edit Allow creating, updating, and deleting agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Access Allow viewing agent metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Draft Allow creating and editing draft agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Edit Allow creating, updating, and deleting agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Access Allow viewing agent trajectory monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Draft Allow creating and editing draft agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Edit Allow creating, updating, and deleting agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Access Allow viewing agent validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Draft Allow creating and editing draft agent validation monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Edit Allow creating, updating, and deleting agent validation monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Access Allow viewing comparison monitors and their configurations.
βœ… Monitors β†’ Management β†’ Comparison β†’ Draft Allow creating and editing draft comparison monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Edit Allow creating, updating, and deleting comparison monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Access Allow viewing custom SQL monitors and their configurations.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Draft Allow creating and editing draft custom SQL monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Edit Allow creating, updating, and deleting custom SQL monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Access Allow viewing JSON schema monitors and their configurations.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Draft Allow creating and editing draft JSON schema monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Edit Allow creating, updating, and deleting JSON schema monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Access Allow viewing metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Metric β†’ Draft Allow creating and editing draft metric monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Edit Allow creating, updating, and deleting metric monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Access Allow viewing query performance monitors and their configurations.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Draft Allow creating and editing draft query performance monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Edit Allow creating, updating, and deleting query performance monitors.
βœ… Monitors β†’ Management β†’ Table β†’ Access Allow viewing table monitors and their configurations.
βœ… Monitors β†’ Management β†’ Table β†’ Draft Allow creating and editing draft table monitors before they are published.
βœ… Monitors β†’ Management β†’ Table β†’ Edit Allow creating, updating, and deleting table monitors.
βœ… Monitors β†’ Management β†’ Validation β†’ Access Allow viewing validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Validation β†’ Draft Allow creating and editing draft validation monitors.
βœ… Monitors β†’ Management β†’ Validation β†’ Edit Allow creating, updating, and deleting validation monitors.
βœ… Performance β†’ Access Allow accessing the performance dashboard and query analytics.
βœ… Settings β†’ Access Top-level permission for viewing account settings. This is used where there is not a more specific permission for a given setting.
βœ… Settings β†’ Edit Top-level permission for editing account settings. This is used where there is not a more specific permission for a given setting.
βœ… Settings β†’ List Iam Resources Allow listing IAM resource and permission definitions. Required for managing users, authorization groups, or roles, since these operations need to display available permissions.
βœ… Settings β†’ Set Account Name Allow changing the account display name.
βœ… Settings β†’ Agents β†’ Access Allow viewing agent details, logs, and reachability information.
βœ… Settings β†’ Agents β†’ Edit Allow creating, updating, deleting, and managing data collection agents.
βœ… Settings β†’ API β†’ Access Allow accessing API settings and the API explorer.
βœ… Settings β†’ API β†’ Edit Allow managing personal API tokens.
βœ… Settings β†’ API β†’ Manage Tokens Allow managing account-level service tokens and integration tokens.
βœ… Settings β†’ Authorization Groups β†’ Access Allow viewing authorization groups and their members. Also required for user management, since group membership is displayed when managing users.
βœ… Settings β†’ Authorization Groups β†’ Edit Allow creating, editing, and deleting authorization groups.
βœ… Settings β†’ Authorization Groups β†’ Manage Domains Managers Allow managing members of the built-in Domains Managers authorization group.
βœ… Settings β†’ Authorization Groups β†’ Manage Owners Allow managing members of the built-in Account Owners authorization group.
βœ… Settings β†’ Billing β†’ Access Allow viewing billing information and invoices.
βœ… Settings β†’ Billing β†’ Edit Allow modifying billing plan and contract settings.
βœ… Settings β†’ Domains β†’ Access Allow viewing domain settings.
βœ… Settings β†’ Domains β†’ Edit Allow creating, editing, and deleting domains and related settings.
βœ… Settings β†’ Domains β†’ List Allow listing available domains.
βœ… Settings β†’ Domains β†’ View Detail Allow viewing detailed domain information and their assets.
βœ… Settings β†’ Ingestion β†’ Access Allow viewing data ingestion settings and metrics.
βœ… Settings β†’ Ingestion β†’ Edit Allow editing data ingestion settings.
βœ… Settings β†’ Ingestion β†’ Manage Collection Allow managing data collection settings, including upgrades and collection preferences.
βœ… Settings β†’ Integrations β†’ Access Allow viewing integrations and their configurations.
βœ… Settings β†’ Integrations β†’ Edit Allow creating, editing, and deleting integrations.
βœ… Settings β†’ Network β†’ Access Allow viewing network access control settings.
βœ… Settings β†’ Network β†’ Edit Allow managing network access control settings.
βœ… Settings β†’ Notifications β†’ Access Allow viewing notification settings, audiences, and channels.
βœ… Settings β†’ Notifications β†’ Edit Allow creating, editing, and deleting notification settings, audiences, and channels.
βœ… Settings β†’ OAuth Clients β†’ Access Allow viewing OAuth clients and their configurations.
βœ… Settings β†’ OAuth Clients β†’ Edit Allow creating and deleting OAuth clients.
βœ… Settings β†’ PII Filters β†’ Edit Allow creating, editing, and deleting PII filters.
βœ… Settings β†’ PII Filters β†’ List Allow listing PII filters.
βœ… Settings β†’ PII Filters β†’ View Metrics Allow viewing PII filter detection metrics.
βœ… Settings β†’ Roles β†’ Access Allow viewing account roles and their permission definitions. Also required for managing authorization groups, since role assignment requires listing available roles.
βœ… Settings β†’ Roles β†’ Edit Allow creating, editing, and deleting custom account roles.
βœ… Settings β†’ Secrets β†’ Access Allow viewing secrets (names/metadata only, not values). Use `settings/secrets/view-values` to view secret values.
βœ… Settings β†’ Secrets β†’ Edit Allow creating, editing, and deleting secrets.
βœ… Settings β†’ Secrets β†’ View Values Allow viewing secret values. This grants access to sensitive credential data.
βœ… Settings β†’ Session β†’ Access Allow viewing session timeout settings.
βœ… Settings β†’ Session β†’ Edit Allow managing session timeout settings.
βœ… Settings β†’ SSO β†’ Access Allow viewing SSO configuration settings.
βœ… Settings β†’ SSO β†’ Edit Allow configuring single sign-on (SSO) settings.
βœ… Settings β†’ User β†’ Subscribe Weekly Digest Allow subscribing to or unsubscribing from the weekly digest email notification.
βœ… Settings β†’ Users β†’ Access Allow viewing authentication and authorization settings.
βœ… Settings β†’ Users β†’ Edit Allow managing users, authorization groups, SSO, and authorization provisioning (SCIM) settings.
βœ… Users β†’ Account Owners Allow viewing the list of Account Owners in the account.
βœ… Users β†’ List Allow listing users in the account for features like assignee selection and @mentions.
*If a permission is not listed here, it is denied for this role.*

Domains Manager

Allows access to all data + AI workflow features as well as managing personal API keys, data products, and domain-related settings such as domains, domain groups/users, ingestion, and notifications.

Restrictions: Cannot edit most account settings except for domain-related settings. No billing or secret value access.

Recommended for: Data/team/product leads who will assist in administration of domains and users.

Role name: mcd/domains-manager

Built-in authorization group: Domains Managers (All)

Permission Description
βœ… Alerts β†’ Access Allow viewing alerts and their details.
βœ… Alerts β†’ Edit Allow editing alerts, including merging, splitting, and updating properties.
βœ… Alerts β†’ Update Status Allow updating alert status (e.g., acknowledging, resolving) and providing feedback on anomaly detections.
βœ… Assets β†’ Access Allow viewing the assets catalog and asset metadata.
βœ… Assets β†’ Edit Allow editing asset metadata in the catalog.
βœ… Dashboard β†’ Access Allow viewing dashboards.
βœ… Dashboard β†’ Edit Allow creating and editing all dashboards in the account.
βœ… Dashboard β†’ Edit Their Own Allow creating and editing only dashboards the current user created. Those with `dashboard/edit` permission can also edit these dashboards.
βœ… Data Exports β†’ Access Allow accessing and downloading data exports.
βœ… Data Products β†’ Access Allow viewing data products.
βœ… Data Products β†’ Edit Allow creating and editing all data products in the account.
βœ… Data Products β†’ Edit Their Own Allow creating and editing only data products the current user created. Those with `data-products/edit` permission can also edit these data products.
βœ… GraphQL β†’ Mutate Allow making modifications (executing mutations) via the GraphQL API. This is required for any writes. This is always asserted in addition to any more specific permissions.
βœ… GraphQL β†’ Query Allow reading data (executing queries) via the GraphQL API. This is required for baseline read-only access to the system, and is always asserted in addition to any more specific permissions.
βœ… Lineage β†’ Access Allow viewing lineage graphs and their metadata.
βœ… Lineage β†’ Edit Allow creating and editing lineage metadata (nodes, edges, etc.).
βœ… MCP β†’ Access Allow authenticating to MCP and using read-only MCP tools.
βœ… MCP β†’ Edit Allow authenticating to MCP and using tools that modify account data or configuration.
βœ… Monitors β†’ Aggregates Allow viewing monitor metrics and aggregate summaries without full monitor access. Used for dashboards and reporting.
βœ… Monitors β†’ Data Sampling β†’ Access Allow accessing sampled data from tables. Required to view sample data in the UI.
βœ… Monitors β†’ Data Sampling β†’ Download Allow downloading sampled data from tables.
βœ… Monitors β†’ Exceptions β†’ Access Allow viewing monitor exception activity logs.
βœ… Monitors β†’ Exceptions β†’ Edit Allow editing monitor exceptions, including updating attributes and adding comments.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Access Allow viewing agent evaluation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Draft Allow creating and editing draft agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Edit Allow creating, updating, and deleting agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Access Allow viewing agent metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Draft Allow creating and editing draft agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Edit Allow creating, updating, and deleting agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Access Allow viewing agent trajectory monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Draft Allow creating and editing draft agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Edit Allow creating, updating, and deleting agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Access Allow viewing agent validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Draft Allow creating and editing draft agent validation monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Edit Allow creating, updating, and deleting agent validation monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Access Allow viewing comparison monitors and their configurations.
βœ… Monitors β†’ Management β†’ Comparison β†’ Draft Allow creating and editing draft comparison monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Edit Allow creating, updating, and deleting comparison monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Access Allow viewing custom SQL monitors and their configurations.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Draft Allow creating and editing draft custom SQL monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Edit Allow creating, updating, and deleting custom SQL monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Access Allow viewing JSON schema monitors and their configurations.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Draft Allow creating and editing draft JSON schema monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Edit Allow creating, updating, and deleting JSON schema monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Access Allow viewing metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Metric β†’ Draft Allow creating and editing draft metric monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Edit Allow creating, updating, and deleting metric monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Access Allow viewing query performance monitors and their configurations.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Draft Allow creating and editing draft query performance monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Edit Allow creating, updating, and deleting query performance monitors.
βœ… Monitors β†’ Management β†’ Table β†’ Access Allow viewing table monitors and their configurations.
βœ… Monitors β†’ Management β†’ Table β†’ Draft Allow creating and editing draft table monitors before they are published.
βœ… Monitors β†’ Management β†’ Table β†’ Edit Allow creating, updating, and deleting table monitors.
βœ… Monitors β†’ Management β†’ Validation β†’ Access Allow viewing validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Validation β†’ Draft Allow creating and editing draft validation monitors.
βœ… Monitors β†’ Management β†’ Validation β†’ Edit Allow creating, updating, and deleting validation monitors.
βœ… Performance β†’ Access Allow accessing the performance dashboard and query analytics.
βœ… Settings β†’ Access Top-level permission for viewing account settings. This is used where there is not a more specific permission for a given setting.
βœ… Settings β†’ Edit Top-level permission for editing account settings. This is used where there is not a more specific permission for a given setting.
βœ… Settings β†’ List Iam Resources Allow listing IAM resource and permission definitions. Required for managing users, authorization groups, or roles, since these operations need to display available permissions.
βœ… Settings β†’ Agents β†’ Access Allow viewing agent details, logs, and reachability information.
βœ… Settings β†’ API β†’ Access Allow accessing API settings and the API explorer.
βœ… Settings β†’ API β†’ Edit Allow managing personal API tokens.
βœ… Settings β†’ Authorization Groups β†’ Access Allow viewing authorization groups and their members. Also required for user management, since group membership is displayed when managing users.
βœ… Settings β†’ Authorization Groups β†’ Edit Allow creating, editing, and deleting authorization groups.
βœ… Settings β†’ Domains β†’ Access Allow viewing domain settings.
βœ… Settings β†’ Domains β†’ Edit Allow creating, editing, and deleting domains and related settings.
βœ… Settings β†’ Domains β†’ List Allow listing available domains.
βœ… Settings β†’ Domains β†’ View Detail Allow viewing detailed domain information and their assets.
βœ… Settings β†’ Ingestion β†’ Access Allow viewing data ingestion settings and metrics.
βœ… Settings β†’ Ingestion β†’ Edit Allow editing data ingestion settings.
βœ… Settings β†’ Integrations β†’ Access Allow viewing integrations and their configurations.
βœ… Settings β†’ Notifications β†’ Access Allow viewing notification settings, audiences, and channels.
βœ… Settings β†’ Notifications β†’ Edit Allow creating, editing, and deleting notification settings, audiences, and channels.
βœ… Settings β†’ PII Filters β†’ Edit Allow creating, editing, and deleting PII filters.
βœ… Settings β†’ PII Filters β†’ List Allow listing PII filters.
βœ… Settings β†’ PII Filters β†’ View Metrics Allow viewing PII filter detection metrics.
βœ… Settings β†’ Roles β†’ Access Allow viewing account roles and their permission definitions. Also required for managing authorization groups, since role assignment requires listing available roles.
βœ… Settings β†’ Secrets β†’ Access Allow viewing secrets (names/metadata only, not values). Use `settings/secrets/view-values` to view secret values.
βœ… Settings β†’ Secrets β†’ Edit Allow creating, editing, and deleting secrets.
❌ Settings β†’ Secrets β†’ View Values Allow viewing secret values. This grants access to sensitive credential data.
βœ… Settings β†’ User β†’ Subscribe Weekly Digest Allow subscribing to or unsubscribing from the weekly digest email notification.
βœ… Settings β†’ Users β†’ Access Allow viewing authentication and authorization settings.
βœ… Settings β†’ Users β†’ Edit Allow managing users, authorization groups, SSO, and authorization provisioning (SCIM) settings.
βœ… Users β†’ Account Owners Allow viewing the list of Account Owners in the account.
βœ… Users β†’ List Allow listing users in the account for features like assignee selection and @mentions.
*If a permission is not listed here, it is denied for this role.*

Editor

Allows access to all data + AI workflow features, as well as managing personal API keys, their own data products, and ingestion and notifications settings.

Restrictions: Cannot edit most account settings except for ingestion and notifications settings. No billing or secret value access.

Recommended for: Data engineers that manage pipelines and data as a part of their job duties.

Role name: mcd/editor

Built-in authorization group: Editors (All)

Permission Description
βœ… Alerts β†’ Access Allow viewing alerts and their details.
βœ… Alerts β†’ Edit Allow editing alerts, including merging, splitting, and updating properties.
βœ… Alerts β†’ Update Status Allow updating alert status (e.g., acknowledging, resolving) and providing feedback on anomaly detections.
βœ… Assets β†’ Access Allow viewing the assets catalog and asset metadata.
βœ… Assets β†’ Edit Allow editing asset metadata in the catalog.
βœ… Dashboard β†’ Access Allow viewing dashboards.
βœ… Dashboard β†’ Edit Allow creating and editing all dashboards in the account.
βœ… Dashboard β†’ Edit Their Own Allow creating and editing only dashboards the current user created. Those with `dashboard/edit` permission can also edit these dashboards.
βœ… Data Exports β†’ Access Allow accessing and downloading data exports.
βœ… Data Products β†’ Access Allow viewing data products.
βœ… Data Products β†’ Edit Their Own Allow creating and editing only data products the current user created. Those with `data-products/edit` permission can also edit these data products.
βœ… GraphQL β†’ Mutate Allow making modifications (executing mutations) via the GraphQL API. This is required for any writes. This is always asserted in addition to any more specific permissions.
βœ… GraphQL β†’ Query Allow reading data (executing queries) via the GraphQL API. This is required for baseline read-only access to the system, and is always asserted in addition to any more specific permissions.
βœ… Lineage β†’ Access Allow viewing lineage graphs and their metadata.
βœ… Lineage β†’ Edit Allow creating and editing lineage metadata (nodes, edges, etc.).
βœ… MCP β†’ Access Allow authenticating to MCP and using read-only MCP tools.
βœ… MCP β†’ Edit Allow authenticating to MCP and using tools that modify account data or configuration.
βœ… Monitors β†’ Aggregates Allow viewing monitor metrics and aggregate summaries without full monitor access. Used for dashboards and reporting.
βœ… Monitors β†’ Data Sampling β†’ Access Allow accessing sampled data from tables. Required to view sample data in the UI.
βœ… Monitors β†’ Data Sampling β†’ Download Allow downloading sampled data from tables.
βœ… Monitors β†’ Exceptions β†’ Access Allow viewing monitor exception activity logs.
βœ… Monitors β†’ Exceptions β†’ Edit Allow editing monitor exceptions, including updating attributes and adding comments.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Access Allow viewing agent evaluation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Draft Allow creating and editing draft agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Edit Allow creating, updating, and deleting agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Access Allow viewing agent metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Draft Allow creating and editing draft agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Edit Allow creating, updating, and deleting agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Access Allow viewing agent trajectory monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Draft Allow creating and editing draft agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Edit Allow creating, updating, and deleting agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Access Allow viewing agent validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Draft Allow creating and editing draft agent validation monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Edit Allow creating, updating, and deleting agent validation monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Access Allow viewing comparison monitors and their configurations.
βœ… Monitors β†’ Management β†’ Comparison β†’ Draft Allow creating and editing draft comparison monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Edit Allow creating, updating, and deleting comparison monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Access Allow viewing custom SQL monitors and their configurations.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Draft Allow creating and editing draft custom SQL monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Edit Allow creating, updating, and deleting custom SQL monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Access Allow viewing JSON schema monitors and their configurations.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Draft Allow creating and editing draft JSON schema monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Edit Allow creating, updating, and deleting JSON schema monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Access Allow viewing metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Metric β†’ Draft Allow creating and editing draft metric monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Edit Allow creating, updating, and deleting metric monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Access Allow viewing query performance monitors and their configurations.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Draft Allow creating and editing draft query performance monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Edit Allow creating, updating, and deleting query performance monitors.
βœ… Monitors β†’ Management β†’ Table β†’ Access Allow viewing table monitors and their configurations.
βœ… Monitors β†’ Management β†’ Table β†’ Draft Allow creating and editing draft table monitors before they are published.
βœ… Monitors β†’ Management β†’ Table β†’ Edit Allow creating, updating, and deleting table monitors.
βœ… Monitors β†’ Management β†’ Validation β†’ Access Allow viewing validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Validation β†’ Draft Allow creating and editing draft validation monitors.
βœ… Monitors β†’ Management β†’ Validation β†’ Edit Allow creating, updating, and deleting validation monitors.
βœ… Performance β†’ Access Allow accessing the performance dashboard and query analytics.
βœ… Settings β†’ Access Top-level permission for viewing account settings. This is used where there is not a more specific permission for a given setting.
βœ… Settings β†’ Agents β†’ Access Allow viewing agent details, logs, and reachability information.
βœ… Settings β†’ API β†’ Access Allow accessing API settings and the API explorer.
βœ… Settings β†’ API β†’ Edit Allow managing personal API tokens.
βœ… Settings β†’ Domains β†’ List Allow listing available domains.
βœ… Settings β†’ Domains β†’ View Detail Allow viewing detailed domain information and their assets.
βœ… Settings β†’ Ingestion β†’ Access Allow viewing data ingestion settings and metrics.
βœ… Settings β†’ Ingestion β†’ Edit Allow editing data ingestion settings.
βœ… Settings β†’ Integrations β†’ Access Allow viewing integrations and their configurations.
βœ… Settings β†’ Notifications β†’ Access Allow viewing notification settings, audiences, and channels.
βœ… Settings β†’ Notifications β†’ Edit Allow creating, editing, and deleting notification settings, audiences, and channels.
βœ… Settings β†’ PII Filters β†’ List Allow listing PII filters.
βœ… Settings β†’ PII Filters β†’ View Metrics Allow viewing PII filter detection metrics.
βœ… Settings β†’ Secrets β†’ Access Allow viewing secrets (names/metadata only, not values). Use `settings/secrets/view-values` to view secret values.
βœ… Settings β†’ Secrets β†’ Edit Allow creating, editing, and deleting secrets.
❌ Settings β†’ Secrets β†’ View Values Allow viewing secret values. This grants access to sensitive credential data.
βœ… Settings β†’ User β†’ Subscribe Weekly Digest Allow subscribing to or unsubscribing from the weekly digest email notification.
βœ… Users β†’ Account Owners Allow viewing the list of Account Owners in the account.
βœ… Users β†’ List Allow listing users in the account for features like assignee selection and @mentions.
*If a permission is not listed here, it is denied for this role.*

Monitor Editor

Allows access to most data + AI workflow features, as well as managing personal API keys, their own data products, and notifications settings.

Restrictions: Monitor-focused settings onlyβ€”no catalog editing, account management, or billing/secret value access.

Recommended for: Those who will add metric and validation monitors to key tables and pipelines.

Role name: mcd/monitor-editor

Built-in authorization group: Monitor Editors (All)

Permission Description
βœ… Alerts β†’ Access Allow viewing alerts and their details.
βœ… Alerts β†’ Edit Allow editing alerts, including merging, splitting, and updating properties.
βœ… Alerts β†’ Update Status Allow updating alert status (e.g., acknowledging, resolving) and providing feedback on anomaly detections.
βœ… Assets β†’ Access Allow viewing the assets catalog and asset metadata.
βœ… Dashboard β†’ Access Allow viewing dashboards.
βœ… Dashboard β†’ Edit Allow creating and editing all dashboards in the account.
βœ… Dashboard β†’ Edit Their Own Allow creating and editing only dashboards the current user created. Those with `dashboard/edit` permission can also edit these dashboards.
βœ… Data Exports β†’ Access Allow accessing and downloading data exports.
βœ… Data Products β†’ Access Allow viewing data products.
βœ… Data Products β†’ Edit Their Own Allow creating and editing only data products the current user created. Those with `data-products/edit` permission can also edit these data products.
βœ… GraphQL β†’ Mutate Allow making modifications (executing mutations) via the GraphQL API. This is required for any writes. This is always asserted in addition to any more specific permissions.
βœ… GraphQL β†’ Query Allow reading data (executing queries) via the GraphQL API. This is required for baseline read-only access to the system, and is always asserted in addition to any more specific permissions.
βœ… Lineage β†’ Access Allow viewing lineage graphs and their metadata.
βœ… Lineage β†’ Edit Allow creating and editing lineage metadata (nodes, edges, etc.).
βœ… MCP β†’ Access Allow authenticating to MCP and using read-only MCP tools.
βœ… MCP β†’ Edit Allow authenticating to MCP and using tools that modify account data or configuration.
βœ… Monitors β†’ Aggregates Allow viewing monitor metrics and aggregate summaries without full monitor access. Used for dashboards and reporting.
βœ… Monitors β†’ Data Sampling β†’ Access Allow accessing sampled data from tables. Required to view sample data in the UI.
βœ… Monitors β†’ Data Sampling β†’ Download Allow downloading sampled data from tables.
βœ… Monitors β†’ Exceptions β†’ Access Allow viewing monitor exception activity logs.
βœ… Monitors β†’ Exceptions β†’ Edit Allow editing monitor exceptions, including updating attributes and adding comments.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Access Allow viewing agent evaluation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Draft Allow creating and editing draft agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Edit Allow creating, updating, and deleting agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Access Allow viewing agent metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Draft Allow creating and editing draft agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Edit Allow creating, updating, and deleting agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Access Allow viewing agent trajectory monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Draft Allow creating and editing draft agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Edit Allow creating, updating, and deleting agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Access Allow viewing agent validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Draft Allow creating and editing draft agent validation monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Edit Allow creating, updating, and deleting agent validation monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Access Allow viewing comparison monitors and their configurations.
βœ… Monitors β†’ Management β†’ Comparison β†’ Draft Allow creating and editing draft comparison monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Edit Allow creating, updating, and deleting comparison monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Access Allow viewing custom SQL monitors and their configurations.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Draft Allow creating and editing draft custom SQL monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Edit Allow creating, updating, and deleting custom SQL monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Access Allow viewing JSON schema monitors and their configurations.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Draft Allow creating and editing draft JSON schema monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Edit Allow creating, updating, and deleting JSON schema monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Access Allow viewing metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Metric β†’ Draft Allow creating and editing draft metric monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Edit Allow creating, updating, and deleting metric monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Access Allow viewing query performance monitors and their configurations.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Draft Allow creating and editing draft query performance monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Edit Allow creating, updating, and deleting query performance monitors.
βœ… Monitors β†’ Management β†’ Table β†’ Access Allow viewing table monitors and their configurations.
βœ… Monitors β†’ Management β†’ Table β†’ Draft Allow creating and editing draft table monitors before they are published.
βœ… Monitors β†’ Management β†’ Table β†’ Edit Allow creating, updating, and deleting table monitors.
βœ… Monitors β†’ Management β†’ Validation β†’ Access Allow viewing validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Validation β†’ Draft Allow creating and editing draft validation monitors.
βœ… Monitors β†’ Management β†’ Validation β†’ Edit Allow creating, updating, and deleting validation monitors.
βœ… Performance β†’ Access Allow accessing the performance dashboard and query analytics.
βœ… Settings β†’ Access Top-level permission for viewing account settings. This is used where there is not a more specific permission for a given setting.
βœ… Settings β†’ Agents β†’ Access Allow viewing agent details, logs, and reachability information.
βœ… Settings β†’ API β†’ Access Allow accessing API settings and the API explorer.
βœ… Settings β†’ API β†’ Edit Allow managing personal API tokens.
βœ… Settings β†’ Domains β†’ List Allow listing available domains.
βœ… Settings β†’ Domains β†’ View Detail Allow viewing detailed domain information and their assets.
βœ… Settings β†’ Integrations β†’ Access Allow viewing integrations and their configurations.
βœ… Settings β†’ Notifications β†’ Access Allow viewing notification settings, audiences, and channels.
βœ… Settings β†’ Notifications β†’ Edit Allow creating, editing, and deleting notification settings, audiences, and channels.
βœ… Settings β†’ PII Filters β†’ List Allow listing PII filters.
βœ… Settings β†’ PII Filters β†’ View Metrics Allow viewing PII filter detection metrics.
βœ… Settings β†’ Secrets β†’ Access Allow viewing secrets (names/metadata only, not values). Use `settings/secrets/view-values` to view secret values.
βœ… Settings β†’ Secrets β†’ Edit Allow creating, editing, and deleting secrets.
❌ Settings β†’ Secrets β†’ View Values Allow viewing secret values. This grants access to sensitive credential data.
βœ… Settings β†’ User β†’ Subscribe Weekly Digest Allow subscribing to or unsubscribing from the weekly digest email notification.
βœ… Users β†’ Account Owners Allow viewing the list of Account Owners in the account.
βœ… Users β†’ List Allow listing users in the account for features like assignee selection and @mentions.
*If a permission is not listed here, it is denied for this role.*

Responder

Allows read-only access to data + AI workflow features plus alert response actions. May also draft monitors.

Restrictions: Only able to respond to alerts. No changing account settings and no billing or secrets access.

Recommended for: Those who triage and respond to alerts but will not manage Monte Carlo configuration/settings.

Role name: mcd/responder

Built-in authorization group: Responders (All)

Permission Description
βœ… Alerts β†’ Access Allow viewing alerts and their details.
βœ… Alerts β†’ Edit Allow editing alerts, including merging, splitting, and updating properties.
βœ… Alerts β†’ Update Status Allow updating alert status (e.g., acknowledging, resolving) and providing feedback on anomaly detections.
βœ… Assets β†’ Access Allow viewing the assets catalog and asset metadata.
βœ… Dashboard β†’ Access Allow viewing dashboards.
βœ… Data Exports β†’ Access Allow accessing and downloading data exports.
βœ… Data Products β†’ Access Allow viewing data products.
βœ… GraphQL β†’ Mutate Allow making modifications (executing mutations) via the GraphQL API. This is required for any writes. This is always asserted in addition to any more specific permissions.
βœ… GraphQL β†’ Query Allow reading data (executing queries) via the GraphQL API. This is required for baseline read-only access to the system, and is always asserted in addition to any more specific permissions.
βœ… Lineage β†’ Access Allow viewing lineage graphs and their metadata.
βœ… MCP β†’ Access Allow authenticating to MCP and using read-only MCP tools.
βœ… MCP β†’ Edit Allow authenticating to MCP and using tools that modify account data or configuration.
βœ… Monitors β†’ Aggregates Allow viewing monitor metrics and aggregate summaries without full monitor access. Used for dashboards and reporting.
βœ… Monitors β†’ Data Sampling β†’ Access Allow accessing sampled data from tables. Required to view sample data in the UI.
βœ… Monitors β†’ Data Sampling β†’ Download Allow downloading sampled data from tables.
βœ… Monitors β†’ Exceptions β†’ Access Allow viewing monitor exception activity logs.
βœ… Monitors β†’ Exceptions β†’ Edit Allow editing monitor exceptions, including updating attributes and adding comments.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Access Allow viewing agent evaluation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Draft Allow creating and editing draft agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Access Allow viewing agent metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Draft Allow creating and editing draft agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Access Allow viewing agent trajectory monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Draft Allow creating and editing draft agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Access Allow viewing agent validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Draft Allow creating and editing draft agent validation monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Access Allow viewing comparison monitors and their configurations.
βœ… Monitors β†’ Management β†’ Comparison β†’ Draft Allow creating and editing draft comparison monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Access Allow viewing custom SQL monitors and their configurations.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Draft Allow creating and editing draft custom SQL monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Access Allow viewing JSON schema monitors and their configurations.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Draft Allow creating and editing draft JSON schema monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Access Allow viewing metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Metric β†’ Draft Allow creating and editing draft metric monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Access Allow viewing query performance monitors and their configurations.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Draft Allow creating and editing draft query performance monitors.
βœ… Monitors β†’ Management β†’ Table β†’ Access Allow viewing table monitors and their configurations.
βœ… Monitors β†’ Management β†’ Table β†’ Draft Allow creating and editing draft table monitors before they are published.
βœ… Monitors β†’ Management β†’ Validation β†’ Access Allow viewing validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Validation β†’ Draft Allow creating and editing draft validation monitors.
βœ… Performance β†’ Access Allow accessing the performance dashboard and query analytics.
βœ… Settings β†’ Domains β†’ List Allow listing available domains.
βœ… Settings β†’ Domains β†’ View Detail Allow viewing detailed domain information and their assets.
βœ… Settings β†’ Integrations β†’ Access Allow viewing integrations and their configurations.
βœ… Settings β†’ Notifications β†’ Access Allow viewing notification settings, audiences, and channels.
βœ… Settings β†’ PII Filters β†’ View Metrics Allow viewing PII filter detection metrics.
βœ… Users β†’ Account Owners Allow viewing the list of Account Owners in the account.
βœ… Users β†’ List Allow listing users in the account for features like assignee selection and @mentions.
*If a permission is not listed here, it is denied for this role.*

Viewer

Allows read-only access to data + AI workflow features. May also draft monitors.

Restrictions: Mostly read only. No changing account settings, no billing access, and no access to secret values.

Recommended for: Those who may benefit from understanding data + AI quality issues but who are not responsible for fixing them.

Role name: mcd/viewer

Built-in authorization group: Viewers (All)

Permission Description
βœ… Alerts β†’ Access Allow viewing alerts and their details.
βœ… Assets β†’ Access Allow viewing the assets catalog and asset metadata.
βœ… Dashboard β†’ Access Allow viewing dashboards.
βœ… Data Exports β†’ Access Allow accessing and downloading data exports.
βœ… Data Products β†’ Access Allow viewing data products.
βœ… GraphQL β†’ Query Allow reading data (executing queries) via the GraphQL API. This is required for baseline read-only access to the system, and is always asserted in addition to any more specific permissions.
βœ… Lineage β†’ Access Allow viewing lineage graphs and their metadata.
βœ… MCP β†’ Access Allow authenticating to MCP and using read-only MCP tools.
βœ… Monitors β†’ Aggregates Allow viewing monitor metrics and aggregate summaries without full monitor access. Used for dashboards and reporting.
βœ… Monitors β†’ Data Sampling β†’ Access Allow accessing sampled data from tables. Required to view sample data in the UI.
βœ… Monitors β†’ Data Sampling β†’ Download Allow downloading sampled data from tables.
βœ… Monitors β†’ Exceptions β†’ Access Allow viewing monitor exception activity logs.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Access Allow viewing agent evaluation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Evaluation β†’ Draft Allow creating and editing draft agent evaluation monitors.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Access Allow viewing agent metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Metric β†’ Draft Allow creating and editing draft agent metric monitors.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Access Allow viewing agent trajectory monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Trajectory β†’ Draft Allow creating and editing draft agent trajectory monitors.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Access Allow viewing agent validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Agent Validation β†’ Draft Allow creating and editing draft agent validation monitors.
βœ… Monitors β†’ Management β†’ Comparison β†’ Access Allow viewing comparison monitors and their configurations.
βœ… Monitors β†’ Management β†’ Comparison β†’ Draft Allow creating and editing draft comparison monitors.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Access Allow viewing custom SQL monitors and their configurations.
βœ… Monitors β†’ Management β†’ Custom Sql β†’ Draft Allow creating and editing draft custom SQL monitors.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Access Allow viewing JSON schema monitors and their configurations.
βœ… Monitors β†’ Management β†’ Json Schema β†’ Draft Allow creating and editing draft JSON schema monitors.
βœ… Monitors β†’ Management β†’ Metric β†’ Access Allow viewing metric monitors and their configurations.
βœ… Monitors β†’ Management β†’ Metric β†’ Draft Allow creating and editing draft metric monitors.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Access Allow viewing query performance monitors and their configurations.
βœ… Monitors β†’ Management β†’ Query Performance β†’ Draft Allow creating and editing draft query performance monitors.
βœ… Monitors β†’ Management β†’ Table β†’ Access Allow viewing table monitors and their configurations.
βœ… Monitors β†’ Management β†’ Table β†’ Draft Allow creating and editing draft table monitors before they are published.
βœ… Monitors β†’ Management β†’ Validation β†’ Access Allow viewing validation monitors and their configurations.
βœ… Monitors β†’ Management β†’ Validation β†’ Draft Allow creating and editing draft validation monitors.
βœ… Performance β†’ Access Allow accessing the performance dashboard and query analytics.
βœ… Settings β†’ Domains β†’ List Allow listing available domains.
βœ… Settings β†’ Domains β†’ View Detail Allow viewing detailed domain information and their assets.
βœ… Settings β†’ Integrations β†’ Access Allow viewing integrations and their configurations.
βœ… Settings β†’ Notifications β†’ Access Allow viewing notification settings, audiences, and channels.
βœ… Settings β†’ PII Filters β†’ View Metrics Allow viewing PII filter detection metrics.
βœ… Settings β†’ Secrets β†’ Access Allow viewing secrets (names/metadata only, not values). Use `settings/secrets/view-values` to view secret values.
❌ Settings β†’ Secrets β†’ View Values Allow viewing secret values. This grants access to sensitive credential data.
βœ… Settings β†’ User β†’ Subscribe Weekly Digest Allow subscribing to or unsubscribing from the weekly digest email notification.
βœ… Users β†’ Account Owners Allow viewing the list of Account Owners in the account.
βœ… Users β†’ List Allow listing users in the account for features like assignee selection and @mentions.
*If a permission is not listed here, it is denied for this role.*