Skip to Content
GovernanceRBACPermissions

Permissions Reference

Zeotap has 120 permissions across 43 resource categories. Every API call that reads or changes something checks one of them. This page is the complete list, what each one allows, and which built-in roles carry it.

Permission Format

Permissions are dotted keys — a resource category, then the action:

sources.read sources.write syncs.trigger events.contracts.write workspace.settings.edit

Most categories pair exactly two permissions. read views the resource; write covers creating, editing and deleting it. Where one action needs to be grantable on its own, it gets its own key: syncs.trigger runs a sync without being able to change it, stores.trigger refreshes a store feed, deletion_rules.execute runs a deletion rule against the warehouse, warehouse_users.rotate rotates a stored credential, workspace_audit.export emails or downloads the audit log, and events.debug opens the live event debugger.

A category with sub-resources nests them before the action. Events split this way into six pairs — events.contracts.*, events.keys.*, events.forwarding.*, events.schemas.*, events.transformations.* and events.enrichments.* — so a team can be given event contracts without being given write keys.

How Permissions Are Granted

Permissions reach an account only through groups. A group is granted one or more roles — built-in or custom — on each workspace it should reach, and an account’s effective permissions in a workspace are the union of the roles held there by every group it belongs to. There is no per-person role and no permission granted directly to a group.

Grants are additive. A second group or a second role only ever adds; nothing narrows what another grant allows. To restrict which rows a member can see, use access policies, which are a separate mechanism.

The seeded Organization admins group holds the Owner role on every workspace in its organization, and Organization viewers holds Member.

Platform administrators sit outside this: they hold the Admin role’s permissions in every workspace, plus whatever their own groups grant there. Because Admin withholds workspace.delete, a platform administrator can delete a workspace only where one of their own groups grants it, for example through the Owner role.

A REST API key is capped rather than granted. The key declares its scopes when it is created, and a request made with it is denied anything outside them — even where the account that created it is an Owner.

To see the effective set for the current caller:

curl "$API_BASE_URL/api/v1/workspaces/$WORKSPACE_ID/permissions/me" \ -H "Authorization: Bearer $API_TOKEN"

GET /api/v1/permissions returns the full catalog of permission keys with their categories and descriptions.

Organization settings → Roles shows the same thing the table below does, live for your organization, with a column per role:

The Roles tab: a permission matrix with a column per role, system roles marked, and a column per custom role

Complete Permission Table

Warehouses and modelling

PermissionWhat it allowsOwnerAdminMember
sources.readView sourcesYesYesYes
sources.writeCreate/edit/delete sourcesYesYesNo
connections.readView connectionsYesYesYes
connections.writeCreate/edit/delete connectionsYesYesNo
models.readView modelsYesYesYes
models.writeCreate/edit/delete modelsYesYesNo
dataprep.readView prepared tables, their recipes and their build history (Data Prep, where enabled for the workspace)YesYesYes
dataprep.writeCreate, edit and delete prepared tablesYesYesNo
dataprep.runTrigger and cancel prepared-table buildsYesYesNo
traits.readView traitsYesYesYes
traits.writeCreate/edit/delete traitsYesYesNo
loaders.readView loaders and their run historyYesYesYes
loaders.writeCreate, update, delete, and trigger loadersYesYesNo
folders.readView foldersYesYesYes
folders.writeCreate, rename, move, and delete foldersYesYesNo
tags.readView tagsYesYesYes
tags.writeCreate, rename, and delete tagsYesYesYes
field_mapping_presets.readView saved field mappingsYesYesYes
field_mapping_presets.writeCreate, edit, and delete saved field mappingsYesYesNo
subsets.readView subsets and assignmentsYesYesYes
subsets.writeManage subset categories, subsets, and assignmentsYesYesNo
cdp_working_datasets.deleteDelete an unreferenced working dataset containerYesYesNo
cdp_working_datasets.readView where the platform’s working data is storedYesYesNo
cdp_working_datasets.writeCreate, rename and bind working dataset containersYesYesNo
execution_environments.deleteDelete an unreferenced execution environmentYesYesNo
execution_environments.readView which compute runs queriesYesYesNo
execution_environments.writeCreate, rename and bind execution environmentsYesYesNo
warehouse_users.deleteDelete an unreferenced warehouse userYesYesNo
warehouse_users.readView warehouse users and their principalsYesYesNo
warehouse_users.rotateRotate a warehouse user’s stored credentialYesYesNo
warehouse_users.writeCreate, rename, disable and bind warehouse usersYesYesNo

Identity

PermissionWhat it allowsOwnerAdminMember
identity_graphs.readView identity graphsYesYesYes
identity_graphs.writeCreate/edit/delete identity graphsYesYesNo

Audiences and orchestration

PermissionWhat it allowsOwnerAdminMember
audience_canvases.readView audience canvasesYesYesYes
audience_canvases.writeCreate/edit/publish/delete audience canvasesYesYesNo
audiences.readView audiencesYesYesYes
audiences.writeCreate/edit/delete audiencesYesYesNo
audience_templates.readView audience templatesYesYesYes
audience_templates.writeCreate/edit/delete audience templatesYesYesNo
audience_syncs.readView audience syncsYesYesYes
audience_syncs.writeCreate/edit/delete audience syncsYesYesNo
splits.readView splitsYesYesYes
splits.writeCreate/edit/delete splitsYesYesNo
priority_lists.readView priority listsYesYesYes
priority_lists.writeCreate/edit/delete priority listsYesYesNo
frequency_caps.readView frequency capsYesYesYes
frequency_caps.writeCreate and manage frequency capsYesYesNo
journeys.readView journeysYesYesYes
journeys.writeCreate/edit/delete journeysYesYesNo

Destinations and syncs

PermissionWhat it allowsOwnerAdminMember
destinations.configure_syncConfigure models and syncs on a destinationYesYesNo
destinations.manageFull management of destination settingsYesYesNo
destinations.readView destinationsYesYesYes
destinations.writeCreate/edit/delete destinationsYesYesNo
destination_rules.readView destination rulesYesYesYes
destination_rules.writeCreate/edit/delete destination rules, and choose which groups may manage oneYesYesNo
syncs.readView syncsYesYesYes
syncs.triggerTrigger sync runs manuallyYesYesNo
syncs.writeCreate/edit/delete syncsYesYesNo

Events

PermissionWhat it allowsOwnerAdminMember
events.contracts.readView event contracts and violationsYesYesYes
events.contracts.writeCreate, update, and archive event contractsYesYesNo
events.debugAccess live event debuggerYesYesYes
events.enrichments.readView event enrichmentsYesYesYes
events.enrichments.writeCreate and manage event enrichmentsYesYesNo
events.forwarding.readView event forwarding rules and delivery logsYesYesYes
events.forwarding.writeCreate and manage event forwarding rulesYesYesNo
events.keys.readView event write keysYesYesYes
events.keys.writeCreate and revoke event write keysYesYesNo
events.readView events, volume metrics, and live streamYesYesYes
events.schemas.readView event schemas and discovered schemasYesYesYes
events.schemas.writeCreate, update, and archive event schemasYesYesNo
events.transformations.readView event transformationsYesYesYes
events.transformations.writeCreate and manage event transformationsYesYesNo
events.writeConfigure event settingsYesYesNo

Personalization

PermissionWhat it allowsOwnerAdminMember
stores.readView stores and their feedsYesYesYes
stores.triggerTrigger, cancel and resume store feed refreshesYesYesNo
stores.writeCreate/edit/delete stores and store feedsYesYesNo
realtime_events.readView realtime eventsYesYesYes
realtime_events.writeCreate/edit/delete realtime eventsYesYesNo

Monitoring

PermissionWhat it allowsOwnerAdminMember
alerting.readView alert rules, channels, and incidentsYesYesYes
alerting.writeCreate and manage alert rules and channelsYesYesNo
observability.readView external observability exportsYesYesYes
observability.writeCreate and manage external observability exportsYesYesNo

Governance

PermissionWhat it allowsOwnerAdminMember
policies.readView guardrail policiesYesYesYes
policies.writeCreate/edit/delete guardrail policiesYesYesNo
approvals.readView approval requestsYesYesYes
approvals.writeApprove/reject approval requestsYesYesNo
deletion_rules.executeTrigger deletion rule runs against the warehouseYesYesNo
deletion_rules.readView deletion rules and deletion logsYesYesYes
deletion_rules.writeCreate, edit, and delete deletion rulesYesYesNo
audit_log.readView the AI agent audit logYesYesYes
workspace_audit.exportExport or email the workspace audit logYesYesNo
workspace_audit.readView the workspace audit logYesYesNo
agent.readView agent sessions and historyYesYesYes
agent.usage.readView workspace-wide agent token usage and costYesYesNo
agent.writeCreate/end agent sessionsYesYesYes

Workspace hierarchy and sharing

PermissionWhat it allowsOwnerAdminMember
workspace_hierarchy.readSee a workspace’s parent and childrenYesYesYes
workspace_hierarchy.writeAssign, replace or remove a workspace’s parentYesYesNo
model_shares.deleteRevoke a share, in the owner workspaceYesYesNo
model_shares.readList shares a workspace owns, and shares granted to itYesYesYes
model_shares.writeCreate shares and add or remove blocks, in the owner workspaceYesYesNo
destination_shares.deleteRevoke a destination share, in the owner workspaceYesYesNo
destination_shares.readList destination shares a workspace owns, and destinations shared with itYesYesYes
destination_shares.writeShare destinations with a child workspace, and block or unblock individual destinationsYesYesNo

Workspace administration

PermissionWhat it allowsOwnerAdminMember
workspace.deleteDelete the workspaceYesNoNo
workspace.settings.editEdit workspace settingsYesYesNo
workspace.settings.readView workspace settingsYesYesYes
members.inviteInvite new membersYesYesNo
members.listList workspace membersYesYesYes
members.removeRemove membersYesYesNo
members.role.changeChange member rolesYesYesNo
groups.createCreate groupsYesYesNo
groups.deleteDelete groupsYesYesNo
groups.editEdit groupsYesYesNo
groups.listList groupsYesYesYes
groups.members.manageAdd/remove group membersYesYesNo
roles.readView custom roles and their permissionsYesYesYes
roles.writeCreate, edit, and delete custom rolesYesYesNo
api_keys.readView API keysYesYesYes
api_keys.writeCreate/revoke API keysYesYesNo
demo.seedSeed demo activation outcomes in a demo workspaceNoNoNo

Summary by Role

Owner — 119 of 120

Owner carries every permission but demo.seed, which is granted to no built-in role and reaches only demo workspaces. workspace.delete is the one Owner holds that no other built-in role does.

Admin — 118 of 120

Admin matches Owner everywhere except workspace.delete (and demo.seed, which no built-in role carries). Admins configure warehouses and destinations, manage members, groups and custom roles, and run every part of the platform.

Member — 49 of 120

Member is a read role. It carries the read permission in every category except five, plus members.list, groups.list, events.debug for the live event debugger, agent.write so a member can hold a conversation with the AI agent, and tags.write so a member can tag the resources they browse.

The five reads that belong to Owner and Admin:

PermissionWhy
agent.usage.readWorkspace-wide agent token spend
workspace_audit.readThe workspace audit log is administrative
warehouse_users.readCredentials and compute are infrastructure a platform or security owner administers. A Member can act on none of it — every write, rotate and delete is Owner and Admin — so the pages would be navigation to a place where nothing they do is possible
execution_environments.readAs above
cdp_working_datasets.readAs above; it also shares the source form’s placement picker with execution environments, so granting one without the other buys a Member nothing

All five stay in the catalog and any of them can be granted to a custom role — that is how a workspace that disagrees with the default expresses it.

Anything that creates, edits, deletes or triggers belongs to Owner and Admin. A team that needs a member to build models or audiences is served by a custom role: start from the read permissions and add the write keys for the categories that team owns.

audit_log.read, which covers the separate AI agent audit log, is available to Members as well.

Permission Denials

A request that fails a permission check returns 403 with the key that was missing:

{ "error": "permission denied: sources.write" }

401 means the request was not authenticated at all — a missing, expired or malformed token.

Next Steps

  • Roles — the built-in roles and how to build a custom one
  • Groups — grant permissions to a team rather than a person
  • Access policies — restrict which rows a member can see
Last updated on