The following table shows the list of all permissions associated with the pre-configured User Roles in TrustArc Integrations. You may want to use this page as a reference.
Admin | Non-Admin | |
|---|---|---|
| User & Role Management | Yes | No |
| Recipe Start/Stop (All) | Yes | Depends on specific role and folder permissions |
| Recipe Creation/Edit | Yes | Yes |
| Access Shared Connections | Yes | Depends on specific role and folder permissions |
| Manage Workspace Settings | Yes | No |
| View Audit Logs | Yes | No |
| Access All Folders | Yes | Depends on specific role and folder permissions |
Here's a more detailed breakdown of each role’s access:
Admin
Admins have full control over the workspace. Their capabilities include:
- User Management
- Add/remove users
- Assign roles and permissions
- Manage team workspaces and folders
- Recipe Management
- Create, edit, and delete any recipe
- Start, stop, or schedule any recipe
- Access and manage shared folders
- Connections & Accounts
- Create and manage connections
- View and update credentials for all connectors
- Workspace Features
- Use all enterprise features, including:
- On-prem agents
- Lookup tables
- Admin API access
- Custom roles and policies (if enabled)
- Use all enterprise features, including:
- Audit & Governance
- View full activity logs
- Access integration insights and usage data
- Configure workspace-level settings like environment properties or IP whitelisting
Non-Admin
Non-admins have limited access, depending on the role assigned (e.g., Analyst, Operator, Recipe Editor). Capabilities vary but often include:
- Recipe Interaction
- View or edit only specific recipes, depending on folder permissions
- May start or stop recipes they created or have access to
- Connections
- Create or manage only their own connections
- Cannot view or modify workspace-level shared connections unless permissions are granted
- Limited Governance Access
- Cannot access workspace settings, user management, or audit logs
- Environment Access
- Limited to the environments or folders they are granted access to (e.g., Dev but not Prod)