View Permissions Granted to Application Roles

You can see a list of permissions granted to each user-defined application role as well as permissions granted to the predefined application roles from the Application Roles page.

While you can view, add, and remove permissions for user-defined application roles, each predefined application role includes a fixed set of permissions that you can't change. Specifically, each predefined application role has a set of role-based permissions built into it which aren't listed individually, plus zero or more regular permissions which are listed individually but you can't remove them. For example, the predefined application role BI Consumer has built-in, role-based permissions plus the permission Export Workbook to Document.

  1. Click Console.
  2. Click Roles and Permissions.
  3. Click Application Roles.
  4. Click the name of an application role.
    To filter the list by name, enter all or part of a name in the Search filter and press enter. The search is case-insensitive, and searches both name and display name. For example, enter admin to search for any application role that includes the letters admin.
  5. Click Permissions to see a list of permissions directly granted to the application role.

    When you select an application role that you created from scratch, you see a list of permissions granted to the role on the right. In this example, several permissions (Create and Edit Workbooks, Export Workbook to Document, and so on) are granted to an application role you created (Finance Analyst).

    You can add and delete permissions, as required.

    Permissions tab for a user-defined application role

    When you select one of the predefined application roles, such as BI Data Model Author, you see a message indicating that the role contains a set of built-in, role-based permissions and both the Add Permissions and Copy Permissions options are greyed out. You can't change the permissions granted to a predefined application role.

    Permissions tab for a predefined application role

    When you select a user-defined application role containing permissions copied from one of the predefined application roles, such as BI Data Model Author, you see a message indicating that the role contains the set of built-in, role-based permissions, plus any additional permissions assigned to the predefined application role, as well as any permissions that you granted the role. In this example, you created an application role called Data Modelers that has the same permissions of the predefined application role BI Data Model Author, plus additional permissions to connect to various data sources.

    Permissions tab for an application copied from a predefined application role