Welcome to InsightFinder AI Observability Docs!
Categories
Roles and Permissions Guide
AI Observability Roles & Permissions
Role-Based Access Reference
Super Admin • Admin • Data Scientist • Regular User
Access model
The source defines four standard user roles. Each user is assigned exactly one role within their organization. Role permission sets are customizable, allowing administrators to create additional roles with tailored permissions.
External/API integrations authenticate with API keys or license keys and are governed separately from user roles.
Standard role overview
The standard roles progress from deployment-wide administration to read-oriented access. Resource ownership matters for Data Scientist and Regular User permissions in several product areas.
Super Admin
Deployment-wide administration
- Full control across the deployment.
- Visibility and administration across all organizations.
- Tenant management and cross-organization usage visibility.
- Full access to product configuration and organization administration.
Admin
Full control within one organization
- Manages users, roles, models, monitors, dashboards, and product features.
- Can administer the user’s own organization.
- Can configure organization-level AI Gateway and monitor notifications.
- Does not receive the source-defined cross-organization scope of Super Admin.
Data Scientist
Hands-on builder
- Can view organization resources broadly.
- Can create models, monitors, workflows, dashboards, prompts, datasets, and other supported resources.
- For ownership-scoped areas, can edit/delete only resources they own.
- Can perform model feedback, evaluation, fine-tuning, and monitor configuration within source-defined limits.
Regular User
Read-oriented user with selected self-service capabilities
- Can view models and monitors across the organization.
- Can create and manage own dashboards and workflows.
- Can use AI Gateway and view its usage/logs/models.
- Cannot create or modify models and monitors under the standard role.
Definition of “Own”
In the source, “Own” resources are resources created by that user. Ownership determines edit/delete or feedback scope for several Data Scientist and Regular User permissions.
Permissions matrix: product experience
| Product Area | Super Admin | Admin | Data Scientist | Regular User |
|---|---|---|---|---|
| Dashboards | View/create/edit/delete all | View/create/edit/delete all | View all; create; edit/delete own | View all; create; edit/delete own |
| Workbench | Full; feedback on any model | Full; feedback on any model | Full; feedback on any org model | Full for own models; feedback own only |
| Models | View/create/edit/delete all | View/create/edit/delete all | View all; create; edit/delete own | View only |
| Workflows | View/create/edit/delete all | View/create/edit/delete all | View all; create; edit/delete own | View all; create; edit/delete own |
| AI Trace | Full read: traces + RCA | Full read: traces + RCA | Full read: traces + RCA | Full read: traces + RCA |
| AI Gateway | Full configure: models/groups/providers | Full configure: models/groups/providers | Use; view usage/logs/models | Use; view usage/logs/models |
Interpretation notes
- AI Trace is read-access oriented for all four standard roles in the source.
- Regular User is read-only for Models and Monitors, but can create and manage their own Dashboards and Workflows.
- Data Scientist combines broad visibility with ownership-based modification rights.
- AI Gateway configuration is restricted to Super Admin and Admin; Data Scientist and Regular User can use the gateway and view source-defined operational information.
Permissions matrix: AI Eval, fine-tuning & monitors
| Product Area | Super Admin | Admin | Data Scientist | Regular User |
|---|---|---|---|---|
| AI Eval — Sessions & Chat | View/chat all org session models | View/chat all org session models | View/chat own session models | View/chat own session models |
| AI Eval — Prompt Library & Datasets | View/create/edit/delete all | View/create/edit/delete all | View shared; create; edit/delete own | View shared |
| AI Eval — Results & Leaderboard | View all results + org leaderboard | View all results + org leaderboard | View own results + org leaderboard | View own results + org leaderboard |
| LLM Fine-Tuning | Create/manage own datasets/jobs/models | Create/manage own datasets/jobs/models | Create/manage own datasets/jobs/models | View datasets/jobs/models |
| Monitors | View/create/edit/delete all | View/create/edit/delete all | View all; create; edit/delete own | View only |
Key access boundaries
- AI Eval visibility differs by resource: Sessions are organization-wide only for Super Admin/Admin, while Data Scientist and Regular User are limited to their own session models.
- Prompt Library and Dataset editing is ownership-scoped for Data Scientist; Regular User can view shared content but cannot create or edit it under the standard role.
- Evaluation Results are ownership-scoped for Data Scientist and Regular User, but both retain access to the organization leaderboard.
- LLM Fine-Tuning is unusual in the source: Super Admin, Admin, and Data Scientist each create/manage their own fine-tuning datasets, jobs, and trained models rather than all fine-tuning resources.
- Regular User can view fine-tuning datasets, jobs, and models but cannot create/manage them.
Permissions matrix: administration & settings
Roles & Permissions
| Product Area | Super Admin | Admin | Data Scientist | Regular User |
|---|---|---|---|---|
| User Management | Invite/edit/remove; assign roles | Invite/edit/remove; assign roles | Edit own profile only | Edit own profile only |
Create/customize roles + permission setsCreate/customize roles + permission setsNo accessNo accessOrganizationView/manage all organizationsManage own organizationNo accessNo accessNotificationsConfigure for all monitorsConfigure for all monitorsConfigure notifications for monitorsNo accessUsage & TokensOwn + org-wide + cross-org usageView own usageView own usageView own usage
Administrative separation
- User and role administration is limited to Super Admin and Admin.
- Only Super Admin has source-defined visibility and management across all organizations.
- Admin manages only the Admin’s own organization.
- Data Scientist and Regular User have no access to Organization or Roles & Permissions settings.
- The source grants organization-wide and cross-organization usage visibility only to Super Admin; Admin, Data Scientist, and Regular User are listed as viewing their own usage.
Custom roles
The source explicitly states that role permission sets are customizable and administrators can create additional roles with tailored permissions. This guide documents the four standard roles only; it does not define the underlying permission-key schema for custom roles
Role assignment reference
The source defines permissions, not organizational policy. The following role-fit summaries simply restate the intended access posture of each standard role without adding permissions beyond the source.
| Role | Best aligned to | Access posture from source |
|---|---|---|
| Super Admin | Deployment / tenant administrators | Cross-organization control, organization management, full product access, broad usage visibility. |
| Admin | Organization administrators | Full control within the user’s organization, including users, roles, resources, gateway configuration, and monitor notifications. |
| Data Scientist | Builders and practitioners | Broad read access plus resource creation; ownership-scoped edit/delete rights in several areas. |
| Regular User | Consumers / collaborators | Broad viewing with limited creation in dashboards/workflows; read-only models/monitors; own-session/evaluation scope. |
Access design considerations directly supported by the source
- Each user receives exactly one role within the organization.
- Ownership matters for editing/deleting resources under Data Scientist and, in selected areas, Regular User.
- External/API integrations are not governed by these user roles; they use API keys or license keys.
- Administrators can create additional roles with tailored permission sets.
- Cross-organization administration is reserved for Super Admin in the standard role model.
Source limitation
The source does not specify approval workflows for role changes, SSO/SCIM behavior, group-to-role mapping, MFA requirements, audit-log permissions, API-key lifecycle controls, or individual permission-key names. Those topics should be documented separately if product configuration material becomes available.
From the Blog
See how InsightFinder helps your team deliver reliable services across every layer of the stack
Take InsightFinder AI for a no-obligation test drive. We’ll provide you with a detailed report on your outages to uncover what could have been prevented.