Welcome to InsightFinder AI Observability Docs!

Roles and Permissions Guide

AI Observability Roles & Permissions

Role-Based Access Reference

Super Admin • Admin • Data Scientist • Regular User

Access model

The source defines four standard user roles. Each user is assigned exactly one role within their organization. Role permission sets are customizable, allowing administrators to create additional roles with tailored permissions.

External/API integrations authenticate with API keys or license keys and are governed separately from user roles.

Standard role overview

The standard roles progress from deployment-wide administration to read-oriented access. Resource ownership matters for Data Scientist and Regular User permissions in several product areas.

Super Admin

Deployment-wide administration

  • Full control across the deployment.
  • Visibility and administration across all organizations.
  • Tenant management and cross-organization usage visibility.
  • Full access to product configuration and organization administration.

Admin

Full control within one organization

  • Manages users, roles, models, monitors, dashboards, and product features.
  • Can administer the user’s own organization.
  • Can configure organization-level AI Gateway and monitor notifications.
  • Does not receive the source-defined cross-organization scope of Super Admin.

Data Scientist

Hands-on builder

  • Can view organization resources broadly.
  • Can create models, monitors, workflows, dashboards, prompts, datasets, and other supported resources.
  • For ownership-scoped areas, can edit/delete only resources they own.
  • Can perform model feedback, evaluation, fine-tuning, and monitor configuration within source-defined limits.

Regular User

Read-oriented user with selected self-service capabilities

  • Can view models and monitors across the organization.
  • Can create and manage own dashboards and workflows.
  • Can use AI Gateway and view its usage/logs/models.
  • Cannot create or modify models and monitors under the standard role.

 

Definition of “Own”

In the source, “Own” resources are resources created by that user. Ownership determines edit/delete or feedback scope for several Data Scientist and Regular User permissions.

Permissions matrix: product experience

Product Area Super Admin Admin Data Scientist Regular User
Dashboards View/create/edit/delete all View/create/edit/delete all View all; create; edit/delete own View all; create; edit/delete own
Workbench Full; feedback on any model Full; feedback on any model Full; feedback on any org model Full for own models; feedback own only
Models View/create/edit/delete all View/create/edit/delete all View all; create; edit/delete own View only
Workflows View/create/edit/delete all View/create/edit/delete all View all; create; edit/delete own View all; create; edit/delete own
AI Trace Full read: traces + RCA Full read: traces + RCA Full read: traces + RCA Full read: traces + RCA
AI Gateway Full configure: models/groups/providers Full configure: models/groups/providers Use; view usage/logs/models Use; view usage/logs/models

Interpretation notes

  • AI Trace is read-access oriented for all four standard roles in the source.
  • Regular User is read-only for Models and Monitors, but can create and manage their own Dashboards and Workflows.
  • Data Scientist combines broad visibility with ownership-based modification rights.
  • AI Gateway configuration is restricted to Super Admin and Admin; Data Scientist and Regular User can use the gateway and view source-defined operational information.

 

Permissions matrix: AI Eval, fine-tuning & monitors

Product Area Super Admin Admin Data Scientist Regular User
AI Eval — Sessions & Chat View/chat all org session models View/chat all org session models View/chat own session models View/chat own session models
AI Eval — Prompt Library & Datasets View/create/edit/delete all View/create/edit/delete all View shared; create; edit/delete own View shared
AI Eval — Results & Leaderboard View all results + org leaderboard View all results + org leaderboard View own results + org leaderboard View own results + org leaderboard
LLM Fine-Tuning Create/manage own datasets/jobs/models Create/manage own datasets/jobs/models Create/manage own datasets/jobs/models View datasets/jobs/models
Monitors View/create/edit/delete all View/create/edit/delete all View all; create; edit/delete own View only

Key access boundaries

  • AI Eval visibility differs by resource: Sessions are organization-wide only for Super Admin/Admin, while Data Scientist and Regular User are limited to their own session models.
  • Prompt Library and Dataset editing is ownership-scoped for Data Scientist; Regular User can view shared content but cannot create or edit it under the standard role.
  • Evaluation Results are ownership-scoped for Data Scientist and Regular User, but both retain access to the organization leaderboard.
  • LLM Fine-Tuning is unusual in the source: Super Admin, Admin, and Data Scientist each create/manage their own fine-tuning datasets, jobs, and trained models rather than all fine-tuning resources.
  • Regular User can view fine-tuning datasets, jobs, and models but cannot create/manage them.

 

Permissions matrix: administration & settings

Roles & Permissions

Product Area Super Admin Admin Data Scientist Regular User
User Management Invite/edit/remove; assign roles Invite/edit/remove; assign roles Edit own profile only Edit own profile only

Create/customize roles + permission setsCreate/customize roles + permission setsNo accessNo accessOrganizationView/manage all organizationsManage own organizationNo accessNo accessNotificationsConfigure for all monitorsConfigure for all monitorsConfigure notifications for monitorsNo accessUsage & TokensOwn + org-wide + cross-org usageView own usageView own usageView own usage

Administrative separation

  • User and role administration is limited to Super Admin and Admin.
  • Only Super Admin has source-defined visibility and management across all organizations.
  • Admin manages only the Admin’s own organization.
  • Data Scientist and Regular User have no access to Organization or Roles & Permissions settings.
  • The source grants organization-wide and cross-organization usage visibility only to Super Admin; Admin, Data Scientist, and Regular User are listed as viewing their own usage.

Custom roles

The source explicitly states that role permission sets are customizable and administrators can create additional roles with tailored permissions. This guide documents the four standard roles only; it does not define the underlying permission-key schema for custom roles

Role assignment reference

The source defines permissions, not organizational policy. The following role-fit summaries simply restate the intended access posture of each standard role without adding permissions beyond the source.

Role Best aligned to Access posture from source
Super Admin Deployment / tenant administrators Cross-organization control, organization management, full product access, broad usage visibility.
Admin Organization administrators Full control within the user’s organization, including users, roles, resources, gateway configuration, and monitor notifications.
Data Scientist Builders and practitioners Broad read access plus resource creation; ownership-scoped edit/delete rights in several areas.
Regular User Consumers / collaborators Broad viewing with limited creation in dashboards/workflows; read-only models/monitors; own-session/evaluation scope.

Access design considerations directly supported by the source

  • Each user receives exactly one role within the organization.
  • Ownership matters for editing/deleting resources under Data Scientist and, in selected areas, Regular User.
  • External/API integrations are not governed by these user roles; they use API keys or license keys.
  • Administrators can create additional roles with tailored permission sets.
  • Cross-organization administration is reserved for Super Admin in the standard role model.

Source limitation

The source does not specify approval workflows for role changes, SSO/SCIM behavior, group-to-role mapping, MFA requirements, audit-log permissions, API-key lifecycle controls, or individual permission-key names. Those topics should be documented separately if product configuration material becomes available.

See how InsightFinder helps your team deliver reliable services across every layer of the stack

Take InsightFinder AI for a no-obligation test drive. We’ll provide you with a detailed report on your outages to uncover what could have been prevented.