Skip to content

Permission List


Guance supports setting permissions for custom roles in the workspace, to meet the permission requirements of different users.

Note

Currently, only feature operation permissions within the workspace can be configured.

Permission List

  • √: For default roles, the permission is supported; for custom roles, the permission can be granted to the custom role.
  • ×: For default roles, the permission is not supported; for custom roles, the permission cannot be granted to the custom role.
Features
Operation Permissions
Owner Administrator Standard Read-only Custom Roles
General Default Access
Explorer > Global Configuration Management × ×
Export Management ×
Workspace Management API Key Management × ×
Member Personal API Key Usage Management × ×
View Token × ×
Rotate Token × × ×
Client Token Management ×
View Member Management ×
Invite Members ×
Member Management × ×
Transfer Ownership × × × ×
Settings Management × ×
Disband Workspace × × × ×
Data Storage Policy Management × × × ×
Workspace Status Management × × × ×
Data Permission Management Configuration Management × ×
Sensitive Data Scanning Configuration Management × ×
Field Management Field Configuration Management ×
Regular Expressions Regular Expression Configuration Management × ×
Cloud Account Management Account Management × × ×
Integration Configuration Management × ×
Global Tags Global Tags Configuration Management × ×
Sharing Management Sharing Configuration Management ×
Snapshot Create Snapshot
Delete Snapshot ×
Plans & Billing Plans & Billing Read-only Permission × ×
Plans & Billing Read/Write Permission × × × ×
Upgrade Permission × × × ×
Scenes View Dashboards & Views
Dashboard Management ×
Tag Permission Management × ×
View Management ×
Notes & Explorers Management ×
Chart Configuration Management ×
View Scheduled Reports ×
Scheduled Report Management ×
Events Manual Recovery ×
Event Data Query
Infrastructure Infrastructure Configuration Management × ×
Infrastructure Data Query
Logs Log Index Management × ×
External Index Management × ×
Data Forwarding Management × ×
Log Data Query
Metrics Metric Description Management ×
Metric Data Query
Application Performance Monitoring (APM) Log Correlation Management ×
APM Data Query
Issue Auto Discovery ×
Service Management × ×
Real User Monitoring (RUM) Application Configuration Management ×
Trace Configuration Management ×
RUM Data Query
View Session Replay
Issue Auto Discovery ×
LLM Monitoring Application Configuration Management ×
LLM Data Query
Synthetic Monitoring Test Configuration Management ×
Self-hosted Node Configuration Management ×
Monitoring View Monitors
Monitor Configuration Management ×
External Event Configuration Management × ×
Intelligent Inspection Configuration Management ×
SLO Configuration Management ×
Mute Configuration Management ×
Alert Policy Configuration Management ×
Notification Targets Configuration Management × ×
Incident Channel Management ×
Channel Subscription
View Channels
Issue Management ×
View Issues
Reply Management ×
View Replies
Severity Configuration × ×
Notification Policy ×
Schedule ×
Issue Discovery ×
Pipelines Pipelines Management ×
Blacklist Blacklist: Create/Edit ×
Blacklist: Enable/Disable ×
Blacklist: Delete ×
Generate Metrics Generate Metrics Configuration Management ×
DCA DCA Configuration Management × × ×
DataFlux Func (Automata) Activate/Configure Func × × × ×
Managed RUM Activate/Configure RUM × × × ×
RUM Administrator × × ×
Cloud Billing Cloud Billing Data Query
External Data Sources Data Source Configuration Management × ×
Data Source Query Permission
Environment Variables Environment Variable Configuration Management × ×
Operation Audit View Operation Audit
Ticket Management Ticket Management Configuration × ×
Security Monitoring CSPM Configuration Management ×
SIEM Configuration Management ×
Incident Center View Incidents
Incident Management ×
Incident Collaboration ×
Incident Severity Management × ×
On-Call Management ×
Error Center View Errors
Error Management ×
Error Collaboration ×
Error Delivery Rule Management × ×
View Error Delivery Rules ×
Unified Catalog Entity Classification Configuration ×
Entity Configuration ×
View Entities

Permission Descriptions

Detailed descriptions of each permission item in the list above.

Features
Operation Permissions
Description
General Default Access Permission The default view and operation permissions users have when entering a workspace. Includes the following permissions.
Explorer > Global Configuration Management
  • Management of default visible quick filters and accelerated field configuration at the workspace level
  • Log Explorer formatting configuration management
  • Export Management Management of data export permissions in the workspace. Includes the following scope:
  • Explorers: export CSV files, copy as cURL
  • Metrics Management: export CSV files
  • Event details page: export JSON, PDF
  • Workspace Management API Key Management Operations such as creating, viewing, and deleting API Keys
    Member Personal API Key Usage Management Enable or disable a member's eligibility to use personal API Keys in the current workspace; does not provide personal API Key plaintext, secret content, or credential lifecycle management capabilities
    View Token Retrieve the workspace Token
    Rotate Token Rotate the workspace Token. Users with this permission must also have the "View Token" permission
    Client Token Management Create and delete Client Tokens
    View Member Management Includes view (read-only) permission for the following pages:
  • Member Management and Member Details pages
  • SSO Management and SAML mappings
  • Invite Members
    Member Management Operations related to workspace member management and SSO management, including:
  • Member group management (add, delete, modify)
  • Member information management (delete, modify)
  • Role management (create, delete, modify)
  • Invitation records
  • Batch permission changes
  • SSO management
        - SSO login (enable, disable, delete)
        - SAML mappings (create, delete, modify, enable, disable)
        - Custom mappings (create, delete, modify)
  • Transfer Ownership Transfer the current workspace owner role to another member
    Settings Management Edit operations on the workspace settings page, including the following permissions
    Disband Workspace Disband the workspace, including unbinding a Commercial Plan workspace from the Billing Center account and deleting the workspace
  • Disband entry when the workspace is locked
  • Data Storage Policy Management
  • Modify Measurement storage policies (Metrics Management page)
  • Modify general storage policies (Manage > Settings page)
  • Workspace Status Management Includes some operations when the workspace is locked:
  • Go to the Billing Center to resolve billing issues
  • Data Permission Management Configuration Management
  • Sensitive fields: disable, enable, configure (add, delete)
  • Data authorization: configure (add, delete)
  • Data access rules: add or remove rules associated with roles in Role Management
  • Sensitive Data Scanning Configuration Management Create, edit, enable, disable, delete
    Field Management Field Configuration Management Create, edit, delete
    Regular Expressions Regular Expression Configuration Management Create, edit, clone, delete
    Cloud Account Management Account Management Create, edit, delete
    Integration Configuration Management Install, uninstall, modify configuration
    Global Tags Global Tags Configuration Management Create, edit, delete
    Sharing Management Sharing Configuration Management Share charts, unshare charts, share snapshots, unshare snapshots
    Snapshot Create Snapshot Create snapshots. Includes:
  • Scenes: Dashboards, Notes, Explorers
  • Events: Unrecovered Events, Events
  • Infrastructure: Hosts, Containers, Processes, Network, Custom
  • Logs: All Logs, Patterns
  • APM: Services, Overview, Traces, Error Tracking, Profile
  • RUM: Views, Explorers, Traces
  • Synthetic Monitoring: Overview, Explorers
  • CI Visualization: Overview, Explorers
  • Delete Snapshot Delete snapshots (read-only members can only delete snapshots created by their own account). Includes:
  • Scenes: Dashboards, Notes, Explorers
  • Events: Unrecovered Events, Events
  • Infrastructure: Hosts, Containers, Processes, Network, Custom
  • Logs: All Logs, Patterns
  • APM: Services, Overview, Traces, Error Tracking, Profile
  • RUM: Views, Explorers, Traces
  • Synthetic Monitoring: Overview, Explorers
  • CI Visualization: Overview, Explorers
  • Plans & Billing Plans & Billing Read-only Permission
  • View current workspace usage statistics and billing charges
  • Set high spending alerts
  • Plans & Billing Read/Write Permission Includes viewing account balance, recharging, changing payment methods, changing the Billing Center account, and accessing the Billing Center. Only members with the Owner role of the current workspace can view and initiate related operations
    Upgrade Permission Entry point for initiating the upgrade from the Free Plan to the Commercial Plan. Only members with the Owner role of the current workspace can initiate it
    Scenes View Dashboards & Views Includes visibility of the Dashboard and View modules, querying dashboards and views (viewing dashboard list and details pages), setting the refresh frequency, changing the query time, and permission to view carousels
    Dashboard Management
  • Dashboards: create, delete, modify (with this permission, Explorers can export list data to dashboards), import, export, duplicate, save to built-in views
  • Carousels: create, modify, delete
  • Tag Permission Management Management of dashboard tag permissions: add, edit, delete tags
    View Management
  • Built-in views > System views: export, clone
  • Built-in views > User views: create, delete, modify, export, clone
  • Notes & Explorers Management
  • Notes: create, delete, modify (with this permission, Explorers can export list data to notes), import, export (JSON/PDF)
  • Explorers: create, delete, modify, export, import, duplicate, add to menu
  • Chart Configuration Management
  • View variables: add, edit, delete
  • Charts: add, modify, combine, clone, delete
  • Chart groups: add, modify, delete
  • View Scheduled Reports View
    Scheduled Report Management Create, edit, delete, enable/disable
    Events Manual Recovery Includes manual recovery operations for Unrecovered Events
    Event Data Query Query all event data in the workspace, including all data for Events and Unrecovered Events
    Infrastructure Infrastructure Configuration Management Includes operations such as editing Host labels, editing object classifications, adding object classifications, adding tags, and deleting objects
    Infrastructure Data Query Query all infrastructure object data in the workspace, including Host, Container, K8s, Process, and Resource Catalog data, historical data from the last 48 hours, and L4/L7 network data reported to the workspace
    Logs Log Index Management Read/write permission. Includes create, delete, modify, enable, disable, and drag-and-drop operations
    External Index Management Read/write permission. Includes bind and delete operations
    Data Forwarding Management Read/write permission. Includes create, edit, delete, enable, and disable operations
    Log Data Query Permission to query all log data in the current workspace, including Guance Logs (L) default index, custom index, bound external index (ES, Opensearch, SLS standard logstore) data, and backup logs (BL) data
    Metrics Metric Description Management Edit and modify metric descriptions
    Metric Data Query Query all metric data in the current workspace
    APM Log Correlation Management Edit log correlation field configuration
    APM Data Query Query all Trace and Profile data in the current workspace
    Issue Auto Discovery Automatically discover and generate Incident Issues from Error Tracking data based on service, version, resource, and error type dimensions
    Service Management Service List management and custom service filter field configuration
    RUM Application Configuration Management Create, modify, and delete applications
    Trace Configuration Management Create, modify, and delete trace configurations
    RUM Data Query Query all RUM data in the current workspace, including session, session replay, view, resource, error, long task, action, and other data
    View Session Replay Permission to view all Session Replay data in the current workspace
    Issue Auto Discovery Automatically discover and generate Incident Issues from error data based on application name, environment, version, and error type dimensions
    LLM Monitoring Application Configuration Management Create, modify, and delete applications
    LLM Data Query Query all LLM data in the current workspace
    Synthetic Monitoring Test Configuration Management Create, delete, modify, enable, disable, test
    Self-hosted Node Configuration Management Create, modify, delete, retrieve configurations
    Monitoring View Monitors View the Monitor list page and Monitor configuration details pages
    Monitor Configuration Management Create, delete, test, modify, enable, disable, import, batch export, batch delete, edit alert configurations, create from templates
    External Event Configuration Management View the Webhook address generated by the "External Event Detection" monitor
    SLO Configuration Management Create, delete, modify, enable, disable
    Mute Configuration Management Create, delete, modify, enable, disable
  • Monitoring > Mute Management
  • Infrastructure > Host Details page > Mute Host
  • Alert Policy Configuration Management Create, delete, edit alert configurations
    Notification Targets Configuration Management Create, delete, modify
    Incident Channel Management
  • Channels: create, modify, delete
  • Notification targets: add, modify
  • Channel Subscription
    View Channels
    Issue Management Create, modify, and delete Issues; upload attachments
    View Issues
    Reply Management
    View Replies
    Severity Configuration
  • Default severity levels: enable, disable
  • Custom severity levels: create, edit, delete
  • Notification Policy Create, modify, delete
    Schedule Create, modify, delete
    Issue Discovery Create, modify, delete, enable, disable
    Pipelines Pipelines Management Read/write permission. Includes create, modify, delete, enable, disable, import, batch export, batch delete, and clone from the official library
  • Logs > Pipelines
  • Manage > Pipelines
  • Blacklist Blacklist: Create/Edit Includes create, modify, import, and export
  • Logs > Blacklist
  • Manage > Blacklist
  • Blacklist: Enable/Disable Includes enable and disable
  • Logs > Blacklist
  • Manage > Blacklist
  • Blacklist: Delete Permission to delete blacklists
  • Logs > Blacklist
  • Manage > Blacklist
  • Generate Metrics Generate Metrics Configuration Management Includes create, modify, delete, enable, and disable operations
  • Logs > Generate Metrics
  • APM > Generate Metrics
  • RUM > Generate Metrics
  • DCA DCA Configuration Management
  • Restart DataKit; create, delete, and modify Collectors, Pipelines, and Blacklists
  • Configure the DCA address
  • DataFlux Func (Automata) Activate/Configure Func Activate the application, modify domain/specifications, upgrade the version, reset the password, deactivate the application
    Managed RUM Activate/Configure RUM Activate the application, modify the service address and specifications, upgrade the version, deactivate the application
    RUM Administrator Permission View configuration information; modify service address, specifications, version, status, and configuration
    Cloud Billing Cloud Billing Data Query
    External Data Sources Data Source Configuration Management Create, edit, and delete operations
    Data Source Query Permission Query external data sources
    Environment Variables Environment Variable Configuration Management Create, import, export, edit, delete
    Operation Audit View Operation Audit Permission to view operation audit data
    Ticket Management Ticket Management Configuration Delete submitted tickets. The delete entry is located in the "More" menu at the top of the ticket details page
    Security Monitoring CSPM Configuration Management Create, delete, test, modify, enable, disable, import, batch export, batch delete, edit alert configurations
    SIEM Configuration Management Create, delete, modify, enable, disable, import, batch export, batch delete, edit alert configurations
    Incident Center View Incidents Permission to view incidents
    Incident Management Change incident severity, claim incidents, comment, upload attachments
    Incident Collaboration Comment on incidents, upload attachments
    Incident Severity Management
  • Enable or disable default severity levels
  • Custom severity levels: create, edit, delete
  • On-Call Management Create, modify, and delete on-call schedules
    Error Center View Errors View error lists, error details, error distribution, and associated context information
    Error Management Change error status, claim errors, assign owners, comment, upload attachments
    Error Collaboration Comment on errors, upload attachments
    Error Delivery Rule Management Create, modify, and delete error delivery rules
    View Error Delivery Rules View error delivery rules and their configuration scope
    Unified Catalog Entity Classification Configuration Includes create, edit, and delete operations for entity classifications, and editing associated views
    Entity Configuration Includes create, edit, and delete operations for entities
    View Entities View entity lists and the Topology View

    Default Access

    • Dashboards, Notes, Explorers, built-in views: read-only permission
    • Dashboard carousels: read-only permission
    • Charts: read-only permission, duplicate
    • Dashboards, Notes, Explorers: favorite
    • All Explorers: read-only permission
    • Personal quick filters in all Explorers: edit permission
    • Displayed columns in all Explorers: configuration permission
    • Creators of Dashboards, Notes, Explorers: edit permission
    • APM > Service List: read-only permission
    • RUM > Application Configuration: read-only permission
    • RUM > Trace Configuration: read-only permission
    • Synthetic Monitoring > Test Configuration: read-only permission
    • Synthetic Monitoring > Self-hosted Node Configuration: read-only permission
    • Monitors, Intelligent Inspection, SLO, Mute Management, Alert Policies, Notification Targets: read-only permission
    • Pipelines configuration: read-only permission for user pipelines and official pipelines
    • Blacklist configuration: read-only permission
    • Basic workspace information: read-only permission
    • Member Management: read-only permission
    • SSO Management: read-only permission
    • Role Management: read-only permission
    • Field Management: read-only permission
    • Data Permission Management: read-only permission
    • Regular Expressions: read-only permission
    • Sharing Management: read-only permission
    • Snapshots: read-only permission (view/copy)
    • DQL Query Tool
    • Integrations
    • Obs Assistant
    • Experience Demo Workspace
    • Ticket Management
    • Workspace remarks (personal account level)
    • Onboarding Guide
    • Automatically show the Onboarding Guide
    • Avatar > View Onboarding Guide
    • Log data access configuration view: read-only
    • Incident: channels read-only, Issues read-only, replies read-only, notification policies read-only, schedules read-only

    Settings Management

    • Modify the workspace name
    • Modify the description
    • Configuration migration (import, export)
    • Advanced settings
    • Add or delete key metrics
    • Feature menu management
    • View operation audit
    • IP whitelist settings
    • Enable data access scope restriction
    • Set the daily Metrics reporting limit
    • Manual data deletion operations in the workspace, including:

      • Delete data of a specific Measurement
      • Delete a custom object
      • A single custom object (Custom Object Details page)
      • All custom objects (Manage > Settings > Risky Operations)
      • Custom objects under a specific object classification (Manage > Settings > Risky Operations)
      • Enable approval-based joining

    Feedback

    Is this page helpful?