How to delegate administration

Atlan allows you to define granular access controls and delegate administrative functions with admin subroles. Atlan currently supports the following built-in admin subroles:

  • Workflow admin — the workflow admin subrole allows Atlan admins to:
    • Grant administrative access to users to manage connectors and connection workflows only.
    • Restrict access to admin capabilities in the admin center and governance capabilities in the governance center.
  • Governance admin — the governance admin subrole allows Atlan admins to:
    • Grant administrative access to users to manage governance capabilities only.
    • Restrict access to admin capabilities in the admin center and connectors and connection workflows in the workflow center.

Assign a subrole

🤓 Who can do this? You will need to be an admin user in Atlan to assign an admin subrole.

 

To assign an admin subrole:

  1. From the left menu of any screen in Atlan, click Admin.
  2. Under Workspace, click Users.
  3. To assign an admin subrole, you can either:
    • To assign the subrole to an existing user, navigate to any user and click the Role dropdown. In the Select Role dialog, click Workflow Admin or Governance Admin and then click Update.
    • To assign the subrole to a new user, follow the steps in How to invite new users without SSO. Change the role of the user to Workflow Admin or Governance Admin and then click the Send Invite button.

Workflow admin

The workflow admin role is a subcategory of the admin role in Atlan. This admin subrole grants specific permissions for creating and managing connection workflows.

Permissions

A workflow admin has the following permissions and capabilities:

  • Connections:
    • Create a new connection for supported sources
    • View all connections
    • Manage all connections from the Connections tab in the Governance center
    • Edit an existing connection — the user must also be a connection admin for that specific connection or have a policy granting them access to the connection.
  • Workflows:
    • Create and manage workflows from the Workflow center
    • View all workflows and workflow runs
    • Edit or delete any workflow credentials — connection admin access not required
    • Run any workflow
    • Add, remove, or edit schedules for any workflow
  • The following capabilities work exactly as that of a member user:

Restrictions

A workflow admin has the following explicit restrictions:

  • Can only access the Connections tab in the Governance center.
  • Cannot delete any existing connections using the Connection Delete workflow.
  • Cannot access or perform any actions in the Admin center.
  • Is excluded from the default All Admins group in any workflow configuration.

Governance admin

The governance admin role is a subcategory of the admin role in Atlan. This admin subrole grants specific permissions for managing the governance center.

Permissions

A governance admin has the following permissions and capabilities:

Restrictions

A governance admin has the following explicit restrictions:

  • Cannot access or perform any actions in the Admin center or Workflow center.
  • Cannot access metadata and data policies if the user is neither a connection admin nor has a policy granting them access to a persona or purpose.
  • Cannot access the Connections tab in the Governance center.
  • Is excluded from the default All Admins group in any workflow configuration.

Related articles

Was this article helpful?
0 out of 0 found this helpful