Configure sharing permissions
Use Sharing and Permissions to assign roles on a collection and its child assets to users and groups. Grant use permission on connectors and secrets separately from read and edit roles. Collection roles are inherited by child assets, and you can grant a higher role separately on a specific asset.
Roles
The following table lists the three roles, their on-screen descriptions, and their primary allowed actions.
| Role | Description | Primary permissions |
|---|---|---|
| Owner | Full management permission | Change settings, grant or revoke permissions, delete |
| Editor | Can edit contents | Add or edit items, create versions |
| Viewer | Read only | View and query (SELECT) |
Use permission
Use permission (use) is separate from the Owner, Editor, and Viewer roles. It allows a subject to execute a resource or consume a stored value. Because it does not define read or edit access, an Editor or Viewer does not automatically receive use permission. Use permission alone does not allow the subject to list the resource or change its settings. An Owner can use a resource that supports use permission without a separate grant.
| Target | What use permission allows | Additional condition |
|---|---|---|
| Connector | Run the connection with its saved connection details and credentials. | Some features, such as connection testing and Query Console, also check the account type or connector settings. |
| Secret | Allow a data connection or tool to reference the stored value at runtime. | The value is never displayed, even to a subject with use permission. |
| Parent collection | Act as the prerequisite for granting use permission on a collection-scoped connector or secret. | A target that does not own the collection needs use permission on the parent collection. |
In the current portal, manage use permission directly from the edit screen of a saved connector or secret. The resource Owner or an Administrator can search for users and groups and grant or revoke permission. Search for a service account as a user target. Use permission cannot be granted to the public All users target.
Before granting use permission on a collection-scoped connector or secret, the target must own the parent collection or have use permission on it. If the current account can also manage collection permissions, the portal first adds use permission on the parent collection automatically. Otherwise, resource use permission can be granted only to targets that already meet the prerequisite.
Revoking use permission prevents the target from executing or referencing the selected resource. It does not change the target's Owner, Editor, or Viewer role. Conversely, changing a hierarchy role does not revoke a directly granted use permission.
- See Usage Permissions tab while editing to grant permission on a connector.
- See Manage use permissions to grant permission on a secret.
Permission inheritance
A role granted on a collection is inherited as the minimum permission on its child assets. You can grant a higher role separately on a specific child asset.
- A Viewer on a collection can view all child assets. Grant Editor or Owner separately on a specific asset when needed.
- On a child asset's permission screen, the inherited role appears as a read-only Inherited · {role} badge. Hover over it to see “Inherited from the collection role. Change it on the Collection tab.” Manage inheritance at the collection level, not on this screen.
- To grant a role above the inherited permission, select a higher role in the asset's Elevate selector. It shows only roles above the inherited role and No elevation. A lower role cannot be selected. Select No elevation to remove the direct asset permission and retain only the inherited permission.
- Lowering or removing a collection member's role also changes the inherited permissions. A confirmation dialog explains the impact before the change.
Actions without permission
Buttons and menus for actions you cannot perform are disabled. Hover over the control to see the required permission. The same permission criteria apply to creation, editing, deletion, and import in lists, trees, and detail screens.
The decision criteria vary by action.
| Action | Decision criterion | Tooltip when disabled |
|---|---|---|
| Create | Account role | Only Administrators or Managers can perform this action. Contact an administrator. |
| Edit | Edit permission on the asset | You do not have permission to edit this item. Contact an administrator. |
| Delete | Delete permission on the asset | You do not have permission to delete this item. Contact an administrator. |
| Import | Administrator or Manager | Only Administrators or Managers can perform this action. Contact an administrator. |
- The role required for Create depends on the asset type. Only Administrators or Managers can create collections and connectors or run imports. Any signed-in user can create a dataset, code asset, pipeline, knowledge, dashboard, or agent within a collection.
- Edit and Delete are determined by the permission granted on the asset. The action is disabled without the required permission.
- Administrator: An Administrator account can perform all actions.
- Controls are temporarily disabled while permissions are being checked.
Open Sharing and Permissions
Open Sharing and Permissions from any of these locations.
- Select an asset in the tree, click the right mouse button, and select Share.
- Select Share from the
⋯action menu in a list row. - Select Share in the detail screen header.
- Open the Sharing and Permissions tab on an asset detail page, such as a dataset or code asset.
Collections, datasets, code, knowledge, agents, tools, actors, connectors, pipelines, dashboards, and prompts use the same permission dialog.
| Target | Screen layout |
|---|---|
| Collection | Shows Members and Child Resources tabs, with an item count beside each tab name. |
| Folder | Shows a form for configuring folder permissions in bulk without tabs. |
| General assets such as datasets, code, knowledge, agents, tools, actors, pipelines, dashboards, and prompts | Shows one role table for managing Owner, Editor, and Viewer. |
Members tab
- Invite: Enter at least two characters in Invite people or groups to search. If an administrator has restricted the search scope, only users in the same group or already-shared members appear.
- Select a role: Choose Owner, Editor, or Viewer.
- Member list: Shows Users with access. Direct grants and access inherited through a group are distinguished.
- Public permission: Grant or remove public read access for All users.
- Change or remove a role: A confirmation dialog shows the impact on child assets.
- Confirm permission downgrade: Lowering a collection role also lowers inherited permissions on child assets. Higher permissions granted directly on an asset remain.
- Confirm access removal: Removing a member from the collection removes inherited access and permissions granted directly on child assets.
Child Resources tab
- Manage permissions for every asset in the collection from one screen.
- Find assets with search and filters, then manage permissions by asset. Each member row shows the minimum permission inherited from the collection as an Inherited · {role} badge. Under Elevate, grant only roles above the inherited permission. Targets are limited to users and groups that have collection permission.
- Permissions granted on the collection and passed down to an asset are labeled Inherited. Manage them at the collection level.
Permission tab in the asset editor
For a saved asset, review and change permissions on the Permissions tab in its edit screen. This tab shows the same contents as the Sharing and Permissions dialog opened from a list.
- Tabbed editors such as the tool and actor editors, knowledge editor, and agent builder show a Permissions tab at the top.
- Canvas builders such as pipelines and dashboards provide the Permissions tab in Settings.
- The Permissions tab appears only for saved assets. It is not shown before the asset has been saved.
The Permissions tab contains a table for managing Owner, Editor, and Viewer roles. Connector and secret edit screens also show a Usage Permissions panel for execution and value-consumption targets. Collections and other assets do not show this panel. See Use permission for the difference between the two permission systems and the collection prerequisite.
Owner preview
Hover over an owner avatar in a list, tree, or detail panel to open the owner preview.

- User owner: Shows display name, email, avatar, and permission grant path.
- Group owner: Shows the group name and granted role.
- Public target: Shows a target with public permission, such as All users.
The Owner column uses the same display across all asset lists.
Collection scopes
The collection tree groups collections into three scopes by access.
- My Collections: Collections where you have the Owner role.
- Shared Collections: Collections shared with you as Editor or Viewer.
- Other Collections: Visible only to Administrators and contains all remaining collections.
These scopes only group collections in the tree; they do not change access permissions.
Move across collection boundaries
When you move an asset to another collection or folder, the destination collection's role becomes the new inherited permission. An asset you do not have permission to move is reported as failed. When moving multiple assets, only some may move, so review the result.
Configure column and row access
Configure column- and row-level conditions with Data Access Policies.
Limitations
- Copying assets between collections and shortcut links are not supported. You can only move assets.
- A folder itself cannot be moved between collections.
- Manage row-level access within a dataset separately with policies.
Next steps
- Explore collections — Find the asset whose permissions you want to change.
- Add and move items — Review move permissions and failure results.
- Data Access Policies — Configure column- and row-level access.