Permissions matrix
Admin roles are billed at the developer rate.
Restricting data downloads
By default, all roles can download query results as CSV from workbooks, Analytics Chat, and published dashboards. Two controls restrict this:- Account-wide — the Allow data downloads switch on the Admin → Settings page. Turning it off hides export controls everywhere, for all users — including admins and embeds.
- Per user — the Download data action in custom roles. Built-in roles grant it by default; to remove download access for a group of users, assign them a custom role without it. Admins and anonymous embed viewers bypass it.
Agent Permissions
Agents are connected to Semantic Model Deployments and inherit the permission level of the user they are operating under. Each agent can be configured to use the Restrict Views feature which allows to select the views that are visible to the agent. This feature should not be used as a security measure. Configure access policies instead.Typical Usage Scenarios
- Viewers: Business users who consume published dashboards, use Analytics Chat, and query data through external tools like Tableau or Power BI
- Explorers: Typically data consumers and analysts
- Developers: Usually data stewards and data engineers
- Admins: Typically assigned to data engineers managing the entire Cube instance (billed at the developer rate with additional privileges)