Teams and RBAC
Group members into teams and use role-based access control to decide who can build, edit, and administer content and data.
Teams group members so you can assign access once and manage it as your organization grows. Combined with organization roles, they give you role-based access control (RBAC) across content and data. Admins manage teams under /app/settings/people.
#Organization roles and seats
Every member has an organization-wide role and seat, set on the Members page:
- Role —
adminormember. Admins manage the org, including teams, entitlements, SSO, and billing. - Seat —
editororviewer. Editors create and change content; viewers consume it.
#Team roles
Within a team, each member holds one team role:
| Team role | Can do |
|---|---|
lead |
Manage the team's content and share the team's dashboards, charts, and sheets. |
member |
Work with the team's content according to their org seat. |
viewer |
View the team's content only. |
Team roles scope permission to a team's resources; org role governs org-wide administration. For example, a team lead can share resources their team owns, while only an org admin can grant a team access to a new data source.
#Managing teams
Admins can:
- Create, rename, and delete teams.
- Add and remove team members, setting each member's team role.
- Grant the team access to data sources — see Data entitlements.
Content is owned by a team, and its visibility and grants are evaluated against team membership.