User groups are collections of users who perform similar tasks. Use user groups to assign permissions and security policies.
Note: To access the User
groups tab, you need the View user group
permission. To create or duplicate custom user groups, or modify
assigned users, you must have the Manage user group
permission.
There are two types of user groups:
View default user groups
Note: Default groups cannot be deleted or
disabled, and their associated assets, roles, and permissions cannot
be modified. However, users can be added to or removed from the
default user groups.
To view default user groups for a
workspace: Click . The default user groups are marked with a
Default tag. The User
Group list displays all users, their assigned roles, and
their security policies.The following default roles are available. Each role belongs to a default user group and grants a predefined set of permissions, which are listed in the permission matrix below.
- Agent manager: Configures agents that provide communication between your environment and the Precisely Cloud.
- Business owner: Manages business assets and protects company resources.
- Catalog manager: Manages catalog and governance settings.
- Datasource manager: Manages connections between your data and the Data Integrity Suite.
- Data steward: Designs and manages technical assets, business assets, and the relationships between all assets. Defines data governance, policies, standards, and guidelines.
- Observability designer: Manages observers and data profiles. Views data profile results, alerts, and anomalies.
- Observability operator: Views data profile results, alerts, and anomalies.
- Quality designer: Configures data quality pipelines for consistent and accurate data processing.
- Quality operator: Runs data quality pipelines to maintain data accuracy and integrity.
- Replication designer: Configures replication pipelines.
- Replication operator: Manages replication activity to maintain data consistency and reliability.
- Catalog user: Views assets in the restricted data catalog.
- Technical custodian: Manages technical configurations.
| Service | Default user group | Role | Permission area | View | Manage | Operate | Delete | Test | Settings |
|---|---|---|---|---|---|---|---|---|---|
| Data Integration | Agent managers | Agent manager | Agent | ✓ | ✓ | ||||
| Data Governance | Business owners | Business owner | Business Asset | ✓ | ✓ | ✓ | |||
| Data Catalog | Catalog managers | Catalog manager | Catalog | ✓ | ✓ | ||||
| Datasource managers | Datasource manager | Datasource | ✓ | ✓ | |||||
| Runtime Engine | ✓ | ✓ | |||||||
| Data Governance | Data stewards | Data steward | Catalog | ||||||
| Business Asset | ✓ | ✓ | ✓ | ||||||
| Technical Assets | ✓ | ✓ | ✓ | ||||||
| Data Profile | ✓ | ✓ | ✓ | ||||||
| Data Samples | ✓ | ✓ | |||||||
| Relationship | ✓ | ✓ | |||||||
| Data Observability | Observability designers | Observability designer | Observer | ✓ | ✓ | ||||
| Data Profile | ✓ | ✓ | |||||||
| Alert | ✓ | ||||||||
| Observability viewers | Observability operator | Data Profile | ✓ | ||||||
| Alert | ✓ | ||||||||
| Data Quality | Quality designers | Quality designer | Observer | ✓ | ✓ | ||||
| Quality Pipeline | ✓ | ✓ | ✓ | ||||||
| Quality operators | Quality operator | Quality Pipeline | ✓ | ✓ | |||||
| Data Integration | Replication designers | Replication designer | Replication Pipeline | ✓ | ✓ | ✓ | |||
| Replication operators | Replication operator | Runtime Engine | ✓ | ✓ | ✓ | ||||
| Replication Pipeline | ✓ | ✓ | |||||||
| Data Catalog | Restricted catalog users | Catalog user | Catalog User | ✓ | |||||
| Technical custodians | Technical custodian | Workspace | ✓ |
- Each row represents the permissions granted to a default user group within a specific permission area.
- A check mark (✓) means the default user group has that permission for the listed permission area.
- A blank cell means the permission is not included for that permission area.
Note: The Data steward role has granular
Catalog permissions: View Asset, View Metrics, and View
Samples.
The following administration roles are available: Security policy manager, Security role manager, User group manager, Users manager, and Workspace manager. Workspace Admin, Workspace managers, and Workspace owners all include this same set of roles.
| Service | Default user group | Role | Feature | Manage |
|---|---|---|---|---|
| Suite Administration | Workspace managers | Workspace administrator | Security Policies | ✓ |
| Security Roles | ✓ | |||
| User Groups | ✓ | |||
| Users | ✓ | |||
| Workspace Settings | ✓ | |||
| Suite Administration | Workspace owners | Workspace administrator | Security Policies | ✓ |
| Security Roles | ✓ | |||
| User Groups | ✓ | |||
| Users | ✓ | |||
| Workspace Settings | ✓ |
Configure custom user groups
Create a custom user group to assign users, roles, and security
policies based on business needs or user attributes.
To create a custom user group:
- Click .
- Click + Create User Group to open the Create User Group dialog.
- Enter a group name and description.
- Add users by using one of these methods:
- Manually: Select users from the list.
- Using a filter: Build a filter with
<attribute><operator><value>and then click Update Preview.- Select an attribute in the first field.
- Select an operator in the second field. Available
operators:
- is: Matches records where the attribute value equals the specified value.
- is not: Matches records where the attribute value does not equal the specified value.
- in: Matches records where the attribute value is in a specified list.
- not in: Matches records where the attribute value is not in a specified list.
- contains: Matches records where the attribute value contains the specified text.
- does not contain: Matches records where the attribute value does not contain the specified text.
- starts with: Matches records where the attribute value starts with the specified text.
- ends with: Matches records where the attribute value ends with the specified text.
- Select or enter a value in the third field. Available input values can change based on the selected operator.
- To add more criteria, click Add filter.
- When you add multiple filters, select Match all filters or Match any filters.
Note: A filter-based group is updated automatically when users are added to the workspace or when user attributes change. - Click Create.
After you create a custom user group, you can complete these actions:
- View user group details: Click the user group name to open the User Group Details dialog. Review the associated Users, Roles, and Security Policies. Click Save.
- Modify an existing custom user group: Click the user group
name. Modify the group name, description, associated users, roles,
and security policies. Click Save. Warning: The name and email address cannot be edited. If this information has changed, record the user's current roles and create a new user with the updated information and identical roles.
- Duplicate an existing custom user group: Click the ellipsis
next to the user group name and select
Duplicate. In the Duplicate User
Group dialog that opens, modify the group name and
description and click Duplicate.Note: To modify users in the new group, re-select the required users.
- Delete a custom user group: Click the ellipsis next to the user group name and select Delete. In the Delete User Group dialog that opens, click Delete.
Tip: Duplicating a user group
duplicates the selected users. Roles and Security Policies are not
duplicated and can be configured only through Security
Policies.