System Built-in Role Permission List

A Singdata Lakehouse account provides various system preset roles after creation. Different preset roles have different operation permission restrictions across various functional pages within the product. The specific permission list is as follows:

Preset Role Permission Function List

Role / MenuHomeWorkspaceDevelopTask OpsMonitoring & AlertingData CatalogData QualityData SharingClusterJob HistorySecurityApprovalWorkspaceData SourcePrivate Link
instance_adminYYYYYYYYYY
instance_userY
instance_datasource_admin (formerly datasource_admin)YY
instance_datamap_admin (formerly datacatalog_admin)YYY
instance_datamap_user (formerly datacatalog_user)YYY
instance_sreYYYYYYY
instance_sensitivedata_viewerY
system_admin (to be deprecated)Y
workspace_adminYYYYYYYYYYYYY
workspace_analystYYYYYYYYYYY
workspace_devYYYYYYYYYYY
workspace_sreYYYYYYYYYYY
workspace_user (to be deprecated)Y

Development & Operations

CategoryFunction Operationinstance_sreworkspace_adminworkspace_analystworkspace_devworkspace_sre
Ops CenterOps operations (series)YYY
EditYY
Development > Task GroupCreate task groupYYY
Submit task groupYYY
Modify task groupYYY
Delete task groupYYY
Create task group parameterYYY
Add task node to task groupYYY
Remove from task groupYYY
View task groupYYYYY
View task group contentYYYYY
Development > FolderCreate folderYYY
Delete folderYYY
Modify folderYYY
View folder infoYYYYY
Development > Task NodeCreate scriptYYY
Delete scriptYYY
Modify scriptYYY
Save scriptYYY
View script contentYYYYY
Run scriptYYY
View result infoYYY
Download data resultYYY
Copy data resultYYY
Configure schedule infoYY
Submit taskYY

Data Integration

Function Operationinstance_sredatasource_adminworkspace_adminworkspace_analystworkspace_devworkspace_sre
Create source data sourceY
Preview source data sourceYYYYY
Create target data sourceYYY
Preview target data sourceYYYYY

Data Assets

Function Operationinstance_datamap_admininstance_datamap_userworkspace_adminworkspace_analystworkspace_dev
Data Assets home pageNo permission restriction; all roles can open
Data ManagementNo permission restriction; all roles can open; content displayed according to data permissions
Data Management / Detail pageYYYYY
Asset OverviewY
Data SearchYY

Clusters

Function Operationworkspace_adminworkspace_analystworkspace_devworkspace_sreworkspace_user (deprecated)
View VCYYYY
Use VCYYY
CreateY
ModifyY
Start/StopY
DeleteY
Set as defaultY

Data Sources

Function Operationinstance_datasource_admininstance_admininstance_userinstance_datamap_admininstance_datamap_userinstance_sreinstance_sensitivedata_viewerworkspace_adminworkspace_devworkspace_sreworkspace_user
ViewYYYYYYYYYYY
CreateYY
ModifyYYY
Test connectivityYYY
DeleteYYY

Data Quality

Function Operationinstance_admininstance_sreworkspace_adminworkspace_devworkspace_sreworkspace_user (to be deprecated)
OverviewYYYYY
Create ruleYY
Dry runYYYYYY
DeleteYYY
EditYY
Mark check result as failedYYYYY
Re-check validation resultYYYYY

Data Permissions

RoleWorkspaceVirtual ClusterSchemaVolumeSynonymFunctionJobTable, Dynamic Table, View, etc.
instance_admincreate workspace drop workspace read metadata///////
instance_sre//////read metadata/
workspace_adminread metadataall [with grant option]all [with grant option]all [with grant option]all [with grant option]all [with grant option]all [with grant option]all [with grant option]
workspace_devread metadataread metadata useallallallcreate read metadataread metadataall
workspace_sreread metadata/////read metadata/
workspace_user (to be deprecated)read metadata///////

For the business meaning of data permission points, refer to: Metadata and Permission Points

Q&A

Question 1: Why can some workspace_dev users in the same account create, modify, delete, start, and stop clusters while others cannot?

Answer: The preset role function permission restrictions listed in this document take effect in the new version (Release 2025.03.05). If a user's role configuration was set before this version, permissions follow the old version's logic. If you encounter detailed issues during use, please contact our technical support team for assistance.