Atlan allows you to define granular access controls and delegate administrative functions with admin subroles. Atlan currently supports the following built-in admin subroles:
-
Workflow admin — the workflow admin subrole allows Atlan admins to:
- Grant administrative access to users to manage connectors and connection workflows only.
- Restrict access to admin capabilities in the admin center and governance capabilities in the governance center.
-
Governance admin — the governance admin subrole allows Atlan admins to:
- Grant administrative access to users to manage governance capabilities only.
- Restrict access to admin capabilities in the admin center and connectors and connection workflows in the workflow center.
Assign a subrole
To assign an admin subrole:
- From the left menu of any screen in Atlan, click Admin.
- Under Workspace, click Users.
- To assign an admin subrole, you can either:
- To assign the subrole to an existing user, navigate to any user and click the Role dropdown. In the Select Role dialog, click Workflow Admin or Governance Admin and then click Update.
- To assign the subrole to a new user, follow the steps in How to invite new users without SSO. Change the role of the user to Workflow Admin or Governance Admin and then click the Send Invite button.
Workflow admin
The workflow admin role is a subcategory of the admin role in Atlan. This admin subrole grants specific permissions for creating and managing connection workflows.
Permissions
A workflow admin has the following permissions and capabilities:
-
Connections:
- Create a new connection for supported sources
- View all connections
- Manage all connections from the Connections tab in the Governance center
- Edit an existing connection — the user must also be a connection admin for that specific connection or have a policy granting them access to the connection.
-
Workflows:
- Create and manage workflows from the Workflow center
- View all workflows and workflow runs
- Edit or delete any workflow credentials — connection admin access not required
- Run any workflow
- Add, remove, or edit schedules for any workflow
- The following capabilities work exactly as that of a member user:
- Asset search and discovery — can update metadata for assets in a connection that the workflow admin either created or was added to as a connection admin.
- Glossary — can view all glossaries but will require edit access through glossary policies. If glossary restrictions are in place, then the workflow admin will only be able to view the glossaries as per their glossary policies.
- Insights — requires data policies to query data and preview sample data.
- Reporting center — if enabled by admins, can view the assets, glossary, Insights, and usage and cost dashboards.
- Data products — requires domain policies to access domains and products.
Restrictions
A workflow admin has the following explicit restrictions:
- Can only access the Connections tab in the Governance center.
- Cannot delete any existing connections using the Connection Delete workflow.
- Cannot access or perform any actions in the Admin center.
- Is excluded from the default All Admins group in any workflow configuration.
Governance admin
The governance admin role is a subcategory of the admin role in Atlan. This admin subrole grants specific permissions for managing the governance center.
Permissions
A governance admin has the following permissions and capabilities:
-
Personas:
- Create and manage personas from the Governance center
- View all personas
- Edit users and policies for existing personas — the user must either also be a connection admin or have a policy granting them access to the persona.
-
Purposes:
- Create and manage purposes from the Governance center
- View all purposes
- Edit users and policies for existing purposes — the user must either also be a connection admin or have a policy granting them access to the purpose.
- Governance workflows — create and manage governance workflows
- Playbooks — create and run playbooks
- Policy center — create and manage data governance policies
- README templates — create and manage README templates
- Tags — create and manage tags
- Domains — only manage domains, cannot create them
- Custom metadata, badges, and options — create and manage custom metadata and associated properties
- The following capabilities work exactly as that of a member user:
- Asset search and discovery — can update metadata for assets in a connection that the governance admin was added to as a connection admin.
- Glossary — can view all glossaries but will require edit access through glossary policies. If glossary restrictions are in place, then the governance admin will only be able to view the glossaries as per their glossary policies.
- Insights — requires data policies to query data and preview sample data.
- Reporting center — if enabled by admins, can view the assets, glossary, Insights, and usage and cost dashboards.
- Data products — requires domain policies to access domains and products.
Restrictions
A governance admin has the following explicit restrictions:
- Cannot access or perform any actions in the Admin center or Workflow center.
- Cannot access metadata and data policies if the user is neither a connection admin nor has a policy granting them access to a persona or purpose.
- Cannot access the Connections tab in the Governance center.
- Is excluded from the default All Admins group in any workflow configuration.