Roles And Permissions

Map groups to xDP tenant roles and review the permissions each role grants.

For group and user setup steps, see Users and Groups.

Group-to-role mapping

Group

Tenant role

Access summary

Admin

Tenant Admin

Full xDP capabilities, including user and role management

Contributor

Editor

View and modify workloads; cannot delete infrastructure resources

Viewer

Viewer

Read-only access across xDP features

Assign these roles under Management → Groups → Tenant Roles on the xDP tab.

Built-in xDP tenant roles are listed under Management → Tenant roles.


How permissions apply

  • Users receive the tenant roles assigned to their groups.

  • Users in multiple groups receive the combined permissions from all assigned roles.

  • Permissions take effect after the user refreshes xDP or signs in again.

Permission actions

Most xDP permissions expose one or more of the following actions:

Action

Meaning

View

See the feature and existing resources

Modify

Create and edit resources

Delete

Remove resources

Create

Add users, roles, or groups (User Management only)


Role

Description

Typical tier

tenant_admin

Full privileges across all xDP capabilities.

Admin

editor

Can view and modify xDP resources but cannot delete them.

Contributor

viewer

Read-only access across xDP features, excluding identity and credential management.

Viewer

data_engineer

Builds and operates jobs, workflows, and pipelines; can modify the data catalog and file storage.

Contributor (data engineering)

data_scientist

Works in AI Studio, notebooks, and SQL editor; can run jobs and manage files for experiments.

Contributor (data science)

data_analyst

Queries data via SQL editor and browses the data catalog and run history, read-only.

Viewer / Analyst

platform_engineer

Manages xDP infrastructure: clusters, apps, file storage, services, and xStore credentials.

Platform admin

governance_admin

Administers governance: access policies, identity, and services; read-only view of users and the catalog.

Governance admin

userXdp

Default baseline role assigned to every xDP user: home, own access, appearance and help, plus read-only cluster and app visibility.

Baseline (all users)

xdp_service_user

Service-account role with the cluster permissions required for dataplane-to-control-plane communication.

Service accounts (not for people)

Permission reference

This section defines every permission available when creating or editing an xDP tenant role in Admin Central. Permissions are grouped into the same categories shown in the Permissions panel on the Create xDP Tenant Role form.

Home

Permission

Description

Actions available

Home

Access the xDP home page

View, Modify, Delete

Infrastructure

Permission

Description

Actions available

Clusters

Manage xCentral, xStore, and xCompute clusters

View, Modify, Delete

Apps

Manage applications deployed on clusters

View, Modify, Delete

File Storage

Manage file storage resources

View, Modify, Delete

xObserve

View xObserve observability data

View

Dataplane Resources

View a dataplane's Kubernetes resources relayed from the dataplane helper

View

Data Catalog

Permission

Description

Actions available

Data Catalog

Browse and manage data catalog assets

View, Modify, Delete

Develop

Permission

Description

Actions available

SQL Editor

Access the SQL Editor

View

Notebooks

Access notebooks

View

Orchestrate

Permission

Description

Actions available

Jobs

Manage Spark and batch jobs

View, Modify, Delete

Workflow

Manage Airflow workflows

View, Modify, Delete

Settings

Permission

Description

Actions available

Appearance

Customize xDP UI appearance

View

Admin Central

Open Admin Central from xDP Settings

View

User Management

Create and manage users, groups, and roles

Create, Modify, View, Delete

API Keys

Manage platform API keys

View, Modify, Delete

xStore Credentials

Manage xStore credentials

View, Modify, Delete

User Auth Credentials

Manage user authentication credentials

View, Modify, Delete

Release Versions

View xDP release versions

View

API Explorer

Browse xDP APIs in the API Explorer

View

Downloads

Download CLI artifacts and assets

View, Modify, Delete

Help

Access help and support resources

View

Platform Access

Permission

Description

Actions available

XDP Access

Entitlement to sign in to the xDP application

View


Built-in roles used in this guide

The following built-in tenant roles cover the standard Admin, Contributor, and Viewer group mapping. The default dataplane-service-user uses Tenant Admin on the xDP tab — see Users and Groups.

Role

Description

Tenant Admin

Full privileges across all xDP capabilities, including user management

Editor

View and modify resources; no delete on infrastructure

Viewer

Read-only access; excludes identity and credential management

XDP Service User

Cluster view and modify only — optional role for custom service accounts

Tenant Admin

Full access across all permission categories listed above, including User Management with Create, Modify, View, and Delete.

Editor

Category

Permissions granted

Home

View, Modify

Infrastructure

Clusters, Apps, File Storage, xObserve, Dataplane Resources — View; Clusters, Apps, File Storage — Modify

Data Catalog

View, Modify

Develop

SQL Editor, Notebooks — View

Orchestrate

Jobs, Workflow — View, Modify

Settings

Appearance, Admin Central, Release Versions, API Explorer, Help — View; API Keys, xStore Credentials, User Auth Credentials, Downloads — View, Modify; User Management — View only

Viewer

View-only access across Home, Infrastructure, Data Catalog, Develop, Orchestrate, and selected Settings features. Does not include User Management, Admin Central, API Keys, or credential management.

Default service user for cluster creation

The tenant-provided dataplane-service-user uses Tenant Admin on the xDP tab plus minimum ADOC Administration permissions. See Users and Groups.

XDP Service User (optional)

Permission

Actions

Clusters

View, Modify

Use this role for custom service accounts that need cluster access only. The default dataplane-service-user uses Tenant Admin instead.

Troubleshooting

Group has the wrong access level

  1. Open Management → Groups and select the group.

  2. Under Tenant Roles on the xDP tab, confirm the role matches the group-to-role mapping table.

  3. Save and ask affected users to refresh xDP.

Role missing from the xDP tab

  1. Open Management → Tenant roles and select the xDP tab (not ADOC).

  2. Confirm the built-in role exists before assigning it to a group.