Understanding roles and permissions
Use roles and permissions to ensure the right people have appropriate access to features and data within your account, and protect sensitive data from unauthorized access.
Role types
There are three basic roles that determine levels of access across all of UpMetrics settings - Org Admin, Editor and Viewer. This includes permissions to manage team access and organization settings, to edit data sets and dashboards, and to view different data sets and dashboards.
Org Admin
- Controls your organization's settings.
- Can edit permissions for team members.
- Can add new users.
- Manages individual role settings in Collect and Analyze features.
- Can access any dataset and dashboard they have created and any dataset and dashboard that is shared with the entire organization.
Limits on Org Admin access:
-
Org Admins cannot access private data sets or dashboards that are owned by other users.
-
Org Admins can edit every user's permissions except their own. If you need to edit your own permissions as an Org Admin, then you need another Org Admin to do so for you.
Editor
- Can view and edit all datasets and dashboards shared with the organization.
- Can access datasets and dashboards they own in a private state.
- Default access is set to Edit for all modules.
Viewer
- Can view all datasets and dashboards that they have access to.
Permissions specific to datasets, charts, and dashboards
UpMetrics allows users to set additional permissions for specific data sets, charts and dashboards. This includes the options to set these objects to Private or Share with organization on an object by object basis.
Private
- Can only be accessed, edited, managed, or deleted by the owner.
- Cannot be shared with other team members.
Org Admins will not have access to see or edit private data sets, charts, or dashboards unless granted specific access by the owner.
Share with organization
- Both owners and Org Admins can manage the data set or dashboard.
- Access rights to dashboards and datasets depend on the role and associated user rights.
- Creators and Org Admins can customize permissions in this access level.
Compare roles and permissions across features
The tables below describe the actions each role in UpMetrics can perform related to specific features.
User roles and actions for System Settings
|
Action |
Org Admin |
Editor |
Viewer |
|
Manage team members |
✔️ |
❌ | ❌ |
|
View or edit your own profile |
✔️ |
✔️ |
✔️ |
|
Change your own password |
✔️ |
✔️ |
✔️ |
User roles and actions for Data Sets
Org Admins and the user who created a dataset can override the permissions of Viewers and Editors for a specific data set.
|
Action |
Org Admin |
Editor |
Viewer |
|
Add Data Table |
✔️ |
✔️ |
❌ |
|
View Data Table |
✔️ |
✔️ |
✔️ |
|
Create Data Collector |
✔️ |
✔️ |
❌ |
|
View Data Collector responses |
✔️ |
✔️ |
❌ |
|
Edit Data Collector Responses (when Data Collector is disabled) |
✔️ |
✔️ |
❌ |
|
Delete Data Collector Responses (when Data Collector is disabled) |
✔️ |
✔️ |
❌ |
|
Data Collector Options |
✔️ |
✔️ |
❌ |
|
Create new Data Set |
✔️ |
✔️ |
❌ |
|
Delete Data Table |
✔️ |
✔️ |
❌ |
|
Delete Data Set |
✔️ |
✔️ |
❌ |
|
Manage/Edit Data Set |
✔️ |
✔️ |
❌ |
|
Google Sheets Edit - add/remove fields, change data types |
✔️ |
✔️ |
❌ |
|
Google Sheets trigger synchronization |
✔️ |
✔️ |
❌ |
|
CSV Edit - add/remove rows and columns |
✔️ |
✔️ |
❌ |
|
CSV Edit - Individual cells |
✔️ |
✔️ |
❌ |
|
Create Dashboard from Template |
✔️ |
✔️ |
❌ |
|
Create relationships |
✔️ |
✔️ |
❌ |
|
Lookups |
✔️ |
✔️ |
❌ |
|
Generated Columns |
✔️ |
✔️ |
❌ |
|
Rename Values |
✔️ |
✔️ |
❌ |
|
Pin/Resize/Reset Columns |
✔️ |
✔️ |
❌ |
|
Download data as a CSV |
✔️ |
✔️ |
❌ |
User roles and actions for Basic Dashboards
|
Permissions |
Org Admin |
Editor |
Viewer |
|
Set Global Filters/Filter Permissions |
✔️ |
❌ |
❌ |
|
User Filters |
✔️ |
✔️ |
✔️ |
|
Enable/Disable external sharing |
✔️ |
✔️ |
❌ |
|
Lock/Unlock Dashboard |
✔️ |
✔️ |
❌ |
|
Manage Dashboard Folder |
✔️ |
✔️ |
❌ |
|
Manage Dashboard |
✔️ |
✔️ |
❌ |
|
Change or Create Color Palette |
✔️ |
✔️ |
❌ |
|
Add Widget from scratch or import Widget |
✔️ |
✔️ |
❌ |
|
Manage Widget |
✔️ |
✔️ |
❌ |
|
Export PDF |
✔️ |
✔️ |
✔️ |
|
Download Widget as image/CSV |
✔️ |
✔️ |
❌ |
|
Widget interaction |
✔️ |
✔️ |
✔️ |
User roles and actions for Stories
| Action | Org Admin | Editor | Viewer |
|
View Stories (content, metadata, codes, sentiment, programs, links, attachments) |
✔️ | ✔️ | ✔️ |
| Access Stories Data in Advanced Analytics | ✔️ | ✔️ | ✔️ |
| Download Story Attachments | ✔️ | ✔️ | ✔️ |
| Download Story Data from Advanced Analytics | ✔️ | ✔️ | ✔️ |
| View Codes and Categories | ✔️ | ✔️ | ✔️ |
| Create / Edit / Delete Stories | ✔️ | ✔️ | ❌ |
| Bulk Operations (Bulk Create / Edit / Delete Stories) | ✔️ | ✔️ | ❌ |
| Create / Manage / Delete Codes and Categories | ✔️ | ✔️ | ❌ |
User roles and actions for Programs
Program Admin is an additional role specific to Programs that layers on top of a user's existing platform role, letting them manage their designated program (or programs) and associate program data across Stories and Impact Reporting. It supplements rather than replaces the base role: users keep all their base permissions and gain program-management rights only for assigned programs, but cannot create programs, since creation is reserved for Org Admins.
| Action | Org Admin | Program Admin | Editor | Viewer |
| View programs and program details | ✔️ | ✔️ | ✔️ | ✔️ |
| Create new programs | ✔️ | ❌ | ❌ | ❌ |
| Edit any program | ✔️ | ❌ | ❌ | ❌ |
| Edit designated programs | ✔️ | ✔️ | ❌ | ❌ |
| Assign a Program Admin to any program | ✔️ | ❌ | ❌ | ❌ |
| Assign a Program Admin to designated programs | ✔️ | ✔️ | ❌ | ❌ |
| Delete or archive any programs | ✔️ |
❌ |
❌ | ❌ |
| Delete or archive designated programs | ✔️ | ✔️ | ❌ | ❌ |
🎉 You're all set to manage your permissions in UpMetrics!