Permission List¶
Guance supports setting permissions for custom roles in the workspace, to meet the permission requirements of different users.
Note
Currently, only feature operation permissions within the workspace can be configured.
Permission List¶
- √: For default roles, the permission is supported; for custom roles, the permission can be granted to the custom role.
- ×: For default roles, the permission is not supported; for custom roles, the permission cannot be granted to the custom role.
Features |
Operation Permissions |
Owner | Administrator | Standard | Read-only | Custom Roles |
|---|---|---|---|---|---|---|
| General | Default Access | √ | √ | √ | √ | √ |
| Explorer > Global Configuration Management | √ | √ | × | × | √ | |
| Export Management | √ | √ | √ | × | √ | |
| Workspace Management | API Key Management | √ | √ | × | × | √ |
| Member Personal API Key Usage Management | √ | √ | × | × | √ | |
| View Token | √ | √ | × | × | √ | |
| Rotate Token | √ | √ | × | × | × | |
| Client Token Management | √ | √ | √ | × | √ | |
| View Member Management | √ | √ | √ | × | √ | |
| Invite Members | √ | √ | √ | × | √ | |
| Member Management | √ | √ | × | × | √ | |
| Transfer Ownership | √ | × | × | × | × | |
| Settings Management | √ | √ | × | × | √ | |
| Disband Workspace | √ | × | × | × | × | |
| Data Storage Policy Management | √ | × | × | × | × | |
| Workspace Status Management | √ | × | × | × | × | |
| Data Permission Management | Configuration Management | √ | √ | × | × | √ |
| Sensitive Data Scanning | Configuration Management | √ | √ | × | × | √ |
| Field Management | Field Configuration Management | √ | √ | √ | × | √ |
| Regular Expressions | Regular Expression Configuration Management | √ | √ | × | × | √ |
| Cloud Account Management | Account Management | √ | √ | × | × | × |
| Integration Configuration Management | √ | √ | × | × | √ | |
| Global Tags | Global Tags Configuration Management | √ | √ | × | × | √ |
| Sharing Management | Sharing Configuration Management | √ | √ | √ | × | √ |
| Snapshot | Create Snapshot | √ | √ | √ | √ | √ |
| Delete Snapshot | √ | √ | √ | × | √ | |
| Plans & Billing | Plans & Billing Read-only Permission | √ | √ | × | × | √ |
| Plans & Billing Read/Write Permission | √ | × | × | × | × | |
| Upgrade Permission | √ | × | × | × | × | |
| Scenes | View Dashboards & Views | √ | √ | √ | √ | √ |
| Dashboard Management | √ | √ | √ | × | √ | |
| Tag Permission Management | √ | √ | × | × | √ | |
| View Management | √ | √ | √ | × | √ | |
| Notes & Explorers Management | √ | √ | √ | × | √ | |
| Chart Configuration Management | √ | √ | √ | × | √ | |
| View Scheduled Reports | √ | √ | √ | × | √ | |
| Scheduled Report Management | √ | √ | √ | × | √ | |
| Events | Manual Recovery | √ | √ | √ | × | √ |
| Event Data Query | √ | √ | √ | √ | √ | |
| Infrastructure | Infrastructure Configuration Management | √ | √ | × | × | √ |
| Infrastructure Data Query | √ | √ | √ | √ | √ | |
| Logs | Log Index Management | √ | √ | × | × | √ |
| External Index Management | √ | √ | × | × | √ | |
| Data Forwarding Management | √ | √ | × | × | √ | |
| Log Data Query | √ | √ | √ | √ | √ | |
| Metrics | Metric Description Management | √ | √ | √ | × | √ |
| Metric Data Query | √ | √ | √ | √ | √ | |
| Application Performance Monitoring (APM) | Log Correlation Management | √ | √ | √ | × | √ |
| APM Data Query | √ | √ | √ | √ | √ | |
| Issue Auto Discovery | √ | √ | √ | × | √ | |
| Service Management | √ | √ | × | × | √ | |
| Real User Monitoring (RUM) | Application Configuration Management | √ | √ | √ | × | √ |
| Trace Configuration Management | √ | √ | √ | × | √ | |
| RUM Data Query | √ | √ | √ | √ | √ | |
| View Session Replay | √ | √ | √ | √ | √ | |
| Issue Auto Discovery | √ | √ | √ | × | √ | |
| LLM Monitoring | Application Configuration Management | √ | √ | √ | × | √ |
| LLM Data Query | √ | √ | √ | √ | √ | |
| Synthetic Monitoring | Test Configuration Management | √ | √ | √ | × | √ |
| Self-hosted Node Configuration Management | √ | √ | √ | × | √ | |
| Monitoring | View Monitors | √ | √ | √ | √ | √ |
| Monitor Configuration Management | √ | √ | √ | × | √ | |
| External Event Configuration Management | √ | √ | × | × | √ | |
| Intelligent Inspection Configuration Management | √ | √ | √ | × | √ | |
| SLO Configuration Management | √ | √ | √ | × | √ | |
| Mute Configuration Management | √ | √ | √ | × | √ | |
| Alert Policy Configuration Management | √ | √ | √ | × | √ | |
| Notification Targets Configuration Management | √ | √ | × | × | √ | |
| Incident | Channel Management | √ | √ | √ | × | √ |
| Channel Subscription | √ | √ | √ | √ | √ | |
| View Channels | √ | √ | √ | √ | √ | |
| Issue Management | √ | √ | √ | × | √ | |
| View Issues | √ | √ | √ | √ | √ | |
| Reply Management | √ | √ | √ | × | √ | |
| View Replies | √ | √ | √ | √ | √ | |
| Severity Configuration | √ | √ | × | × | √ | |
| Notification Policy | √ | √ | √ | × | √ | |
| Schedule | √ | √ | √ | × | √ | |
| Issue Discovery | √ | √ | √ | × | √ | |
| Pipelines | Pipelines Management | √ | √ | √ | × | √ |
| Blacklist | Blacklist: Create/Edit | √ | √ | √ | × | √ |
| Blacklist: Enable/Disable | √ | √ | √ | × | √ | |
| Blacklist: Delete | √ | √ | √ | × | √ | |
| Generate Metrics | Generate Metrics Configuration Management | √ | √ | √ | × | √ |
| DCA | DCA Configuration Management | √ | √ | × | × | × |
| DataFlux Func (Automata) | Activate/Configure Func | √ | × | × | × | × |
| Managed RUM | Activate/Configure RUM | √ | × | × | × | × |
| RUM Administrator | √ | √ | × | × | × | |
| Cloud Billing | Cloud Billing Data Query | √ | √ | √ | √ | √ |
| External Data Sources | Data Source Configuration Management | √ | √ | × | × | √ |
| Data Source Query Permission | √ | √ | √ | √ | √ | |
| Environment Variables | Environment Variable Configuration Management | √ | √ | × | × | √ |
| Operation Audit | View Operation Audit | √ | √ | √ | √ | √ |
| Ticket Management | Ticket Management Configuration | √ | √ | × | × | √ |
| Security Monitoring | CSPM Configuration Management | √ | √ | √ | × | √ |
| SIEM Configuration Management | √ | √ | √ | × | √ | |
| Incident Center | View Incidents | √ | √ | √ | √ | √ |
| Incident Management | √ | √ | √ | × | √ | |
| Incident Collaboration | √ | √ | √ | × | √ | |
| Incident Severity Management | √ | √ | × | × | √ | |
| On-Call Management | √ | √ | √ | × | √ | |
| Error Center | View Errors | √ | √ | √ | √ | √ |
| Error Management | √ | √ | √ | × | √ | |
| Error Collaboration | √ | √ | √ | × | √ | |
| Error Delivery Rule Management | √ | √ | × | × | √ | |
| View Error Delivery Rules | √ | √ | √ | × | √ | |
| Unified Catalog | Entity Classification Configuration | √ | √ | √ | × | √ |
| Entity Configuration | √ | √ | √ | × | √ | |
| View Entities | √ | √ | √ | √ | √ |
Permission Descriptions¶
Detailed descriptions of each permission item in the list above.
Features |
Operation Permissions |
Description |
|---|---|---|
| General | Default Access Permission | The default view and operation permissions users have when entering a workspace. Includes the following permissions. |
| Explorer > Global Configuration Management | ||
| Export Management | Management of data export permissions in the workspace. Includes the following scope: |
|
| Workspace Management | API Key Management | Operations such as creating, viewing, and deleting API Keys |
| Member Personal API Key Usage Management | Enable or disable a member's eligibility to use personal API Keys in the current workspace; does not provide personal API Key plaintext, secret content, or credential lifecycle management capabilities | |
| View Token | Retrieve the workspace Token | |
| Rotate Token | Rotate the workspace Token. Users with this permission must also have the "View Token" permission | |
| Client Token Management | Create and delete Client Tokens | |
| View Member Management | Includes view (read-only) permission for the following pages: |
|
| Invite Members | ||
| Member Management | Operations related to workspace member management and SSO management, including: - SSO login (enable, disable, delete) - SAML mappings (create, delete, modify, enable, disable) - Custom mappings (create, delete, modify) |
|
| Transfer Ownership | Transfer the current workspace owner role to another member | |
| Settings Management | Edit operations on the workspace settings page, including the following permissions | |
| Disband Workspace | Disband the workspace, including unbinding a Commercial Plan workspace from the Billing Center account and deleting the workspace |
|
| Data Storage Policy Management | ||
| Workspace Status Management | Includes some operations when the workspace is locked: |
|
| Data Permission Management | Configuration Management | |
| Sensitive Data Scanning | Configuration Management | Create, edit, enable, disable, delete |
| Field Management | Field Configuration Management | Create, edit, delete |
| Regular Expressions | Regular Expression Configuration Management | Create, edit, clone, delete |
| Cloud Account Management | Account Management | Create, edit, delete |
| Integration Configuration Management | Install, uninstall, modify configuration | |
| Global Tags | Global Tags Configuration Management | Create, edit, delete |
| Sharing Management | Sharing Configuration Management | Share charts, unshare charts, share snapshots, unshare snapshots |
| Snapshot | Create Snapshot | Create snapshots. Includes: |
| Delete Snapshot | Delete snapshots (read-only members can only delete snapshots created by their own account). Includes: |
|
| Plans & Billing | Plans & Billing Read-only Permission | |
| Plans & Billing Read/Write Permission | Includes viewing account balance, recharging, changing payment methods, changing the Billing Center account, and accessing the Billing Center. Only members with the Owner role of the current workspace can view and initiate related operations | |
| Upgrade Permission | Entry point for initiating the upgrade from the Free Plan to the Commercial Plan. Only members with the Owner role of the current workspace can initiate it | |
| Scenes | View Dashboards & Views | Includes visibility of the Dashboard and View modules, querying dashboards and views (viewing dashboard list and details pages), setting the refresh frequency, changing the query time, and permission to view carousels |
| Dashboard Management | ||
| Tag Permission Management | Management of dashboard tag permissions: add, edit, delete tags | |
| View Management | ||
| Notes & Explorers Management | ||
| Chart Configuration Management | ||
| View Scheduled Reports | View | |
| Scheduled Report Management | Create, edit, delete, enable/disable | |
| Events | Manual Recovery | Includes manual recovery operations for Unrecovered Events |
| Event Data Query | Query all event data in the workspace, including all data for Events and Unrecovered Events | |
| Infrastructure | Infrastructure Configuration Management | Includes operations such as editing Host labels, editing object classifications, adding object classifications, adding tags, and deleting objects |
| Infrastructure Data Query | Query all infrastructure object data in the workspace, including Host, Container, K8s, Process, and Resource Catalog data, historical data from the last 48 hours, and L4/L7 network data reported to the workspace | |
| Logs | Log Index Management | Read/write permission. Includes create, delete, modify, enable, disable, and drag-and-drop operations |
| External Index Management | Read/write permission. Includes bind and delete operations | |
| Data Forwarding Management | Read/write permission. Includes create, edit, delete, enable, and disable operations | |
| Log Data Query | Permission to query all log data in the current workspace, including Guance Logs (L) default index, custom index, bound external index (ES, Opensearch, SLS standard logstore) data, and backup logs (BL) data | |
| Metrics | Metric Description Management | Edit and modify metric descriptions |
| Metric Data Query | Query all metric data in the current workspace | |
| APM | Log Correlation Management | Edit log correlation field configuration |
| APM Data Query | Query all Trace and Profile data in the current workspace | |
| Issue Auto Discovery | Automatically discover and generate Incident Issues from Error Tracking data based on service, version, resource, and error type dimensions | |
| Service Management | Service List management and custom service filter field configuration | |
| RUM | Application Configuration Management | Create, modify, and delete applications |
| Trace Configuration Management | Create, modify, and delete trace configurations | |
| RUM Data Query | Query all RUM data in the current workspace, including session, session replay, view, resource, error, long task, action, and other data |
|
| View Session Replay | Permission to view all Session Replay data in the current workspace | |
| Issue Auto Discovery | Automatically discover and generate Incident Issues from error data based on application name, environment, version, and error type dimensions | |
| LLM Monitoring | Application Configuration Management | Create, modify, and delete applications |
| LLM Data Query | Query all LLM data in the current workspace | |
| Synthetic Monitoring | Test Configuration Management | Create, delete, modify, enable, disable, test |
| Self-hosted Node Configuration Management | Create, modify, delete, retrieve configurations | |
| Monitoring | View Monitors | View the Monitor list page and Monitor configuration details pages |
| Monitor Configuration Management | Create, delete, test, modify, enable, disable, import, batch export, batch delete, edit alert configurations, create from templates | |
| External Event Configuration Management | View the Webhook address generated by the "External Event Detection" monitor | |
| SLO Configuration Management | Create, delete, modify, enable, disable | |
| Mute Configuration Management | Create, delete, modify, enable, disable |
|
| Alert Policy Configuration Management | Create, delete, edit alert configurations | |
| Notification Targets Configuration Management | Create, delete, modify | |
| Incident | Channel Management | |
| Channel Subscription | ||
| View Channels | ||
| Issue Management | Create, modify, and delete Issues; upload attachments | |
| View Issues | ||
| Reply Management | ||
| View Replies | ||
| Severity Configuration | ||
| Notification Policy | Create, modify, delete | |
| Schedule | Create, modify, delete | |
| Issue Discovery | Create, modify, delete, enable, disable | |
| Pipelines | Pipelines Management | Read/write permission. Includes create, modify, delete, enable, disable, import, batch export, batch delete, and clone from the official library |
| Blacklist | Blacklist: Create/Edit | Includes create, modify, import, and export |
| Blacklist: Enable/Disable | Includes enable and disable |
|
| Blacklist: Delete | Permission to delete blacklists |
|
| Generate Metrics | Generate Metrics Configuration Management | Includes create, modify, delete, enable, and disable operations |
| DCA | DCA Configuration Management | |
| DataFlux Func (Automata) | Activate/Configure Func | Activate the application, modify domain/specifications, upgrade the version, reset the password, deactivate the application |
| Managed RUM | Activate/Configure RUM | Activate the application, modify the service address and specifications, upgrade the version, deactivate the application |
| RUM Administrator Permission | View configuration information; modify service address, specifications, version, status, and configuration | |
| Cloud Billing | Cloud Billing Data Query | |
| External Data Sources | Data Source Configuration Management | Create, edit, and delete operations |
| Data Source Query Permission | Query external data sources | |
| Environment Variables | Environment Variable Configuration Management | Create, import, export, edit, delete |
| Operation Audit | View Operation Audit | Permission to view operation audit data |
| Ticket Management | Ticket Management Configuration | Delete submitted tickets. The delete entry is located in the "More" menu at the top of the ticket details page |
| Security Monitoring | CSPM Configuration Management | Create, delete, test, modify, enable, disable, import, batch export, batch delete, edit alert configurations |
| SIEM Configuration Management | Create, delete, modify, enable, disable, import, batch export, batch delete, edit alert configurations | |
| Incident Center | View Incidents | Permission to view incidents |
| Incident Management | Change incident severity, claim incidents, comment, upload attachments | |
| Incident Collaboration | Comment on incidents, upload attachments | |
| Incident Severity Management | ||
| On-Call Management | Create, modify, and delete on-call schedules | |
| Error Center | View Errors | View error lists, error details, error distribution, and associated context information |
| Error Management | Change error status, claim errors, assign owners, comment, upload attachments | |
| Error Collaboration | Comment on errors, upload attachments | |
| Error Delivery Rule Management | Create, modify, and delete error delivery rules | |
| View Error Delivery Rules | View error delivery rules and their configuration scope | |
| Unified Catalog | Entity Classification Configuration | Includes create, edit, and delete operations for entity classifications, and editing associated views |
| Entity Configuration | Includes create, edit, and delete operations for entities | |
| View Entities | View entity lists and the Topology View |
Default Access¶
- Dashboards, Notes, Explorers, built-in views: read-only permission
- Dashboard carousels: read-only permission
- Charts: read-only permission, duplicate
- Dashboards, Notes, Explorers: favorite
- All Explorers: read-only permission
- Personal quick filters in all Explorers: edit permission
- Displayed columns in all Explorers: configuration permission
- Creators of Dashboards, Notes, Explorers: edit permission
- APM > Service List: read-only permission
- RUM > Application Configuration: read-only permission
- RUM > Trace Configuration: read-only permission
- Synthetic Monitoring > Test Configuration: read-only permission
- Synthetic Monitoring > Self-hosted Node Configuration: read-only permission
- Monitors, Intelligent Inspection, SLO, Mute Management, Alert Policies, Notification Targets: read-only permission
- Pipelines configuration: read-only permission for user pipelines and official pipelines
- Blacklist configuration: read-only permission
- Basic workspace information: read-only permission
- Member Management: read-only permission
- SSO Management: read-only permission
- Role Management: read-only permission
- Field Management: read-only permission
- Data Permission Management: read-only permission
- Regular Expressions: read-only permission
- Sharing Management: read-only permission
- Snapshots: read-only permission (view/copy)
- DQL Query Tool
- Integrations
- Obs Assistant
- Experience Demo Workspace
- Ticket Management
- Workspace remarks (personal account level)
- Onboarding Guide
- Automatically show the Onboarding Guide
- Avatar > View Onboarding Guide
- Log data access configuration view: read-only
- Incident: channels read-only, Issues read-only, replies read-only, notification policies read-only, schedules read-only
Settings Management¶
- Modify the workspace name
- Modify the description
- Configuration migration (import, export)
- Advanced settings
- Add or delete key metrics
- Feature menu management
- View operation audit
- IP whitelist settings
- Enable data access scope restriction
- Set the daily Metrics reporting limit
-
Manual data deletion operations in the workspace, including:
- Delete data of a specific Measurement
- Delete a custom object
- A single custom object (Custom Object Details page)
- All custom objects (Manage > Settings > Risky Operations)
- Custom objects under a specific object classification (Manage > Settings > Risky Operations)
- Enable approval-based joining