Permissions

Permissions provides a central location for managing Experience Platform access for your organization. Through Permissions, you can grant groups of users access permissions for various Experience Platform capabilities, such as Manage Datasets, View Datasets, or Manage Profiles.

Roles

In the Roles section, permissions are assigned to users through the use of roles. Roles allow you to grant permissions to one or multiple users, and also contain their access to the scope of the sandboxes that are assigned to them through roles. Users can be assigned to one or multiple roles belonging to your organization.

Default roles

Experience Platform comes with two pre-configured default roles. The following table outlines what is provided in each default profile, including the sandbox they grant access to as well as the permissions they grant within the scope of that sandbox.

RoleSandbox accessPermissions
Default production all accessProductionAll permissions applicable to Experience Platform, except for Sandbox Administration permissions.
Sandbox AdministratorsN/AProvides access only to Sandbox Administration permissions.

Sandboxes and permissions

Non-Production sandboxes are a form of data virtualization that allow you to isolate data from other sandboxes and are typically used for development experiments, testing, or trials. A role’s permissions give the role’s users access to Experience Platform features within the sandbox environments to which they’ve been granted access to. A default Experience Platform license grants you five sandboxes (one production and four non-production). You can add packs of ten non-production sandboxes up to a maximum of 75 sandboxes in total. Please contact your organization’s administrator or your Adobe sales representative for more details.

For more information about sandboxes in Experience Platform, please refer to the sandboxes overview.

Access to sandboxes

Access to sandboxes is managed through roles. For detailed steps on how to enable access to a sandbox for a role, see the attribute based access control roles guide.

Users can be granted access to one or more sandboxes within a role. If one user is included in two or more roles, that user will have access to all sandboxes included in those roles.

The “Sandbox Management” permission allows users to manage, view, or reset sandboxes.

Resource permissions

The resource Permissions tab within a role displays the sandboxes and permissions that are active for that role:

permissions-overview

Permissions that are granted through the resource permissions are sorted by category, with some permissions granting access to several low-level functionalities.

The following table outlines the available permissions for Experience Platform in the role, with descriptions of the specific Experience Platform capabilities they grant access to. For detailed steps on how to add permissions to a role, see the attribute based access control roles guide.

CategoryPermissionDescription
AI AssistantEnable AI AssistantAbility to ask the AI assistant questions.
AI AssistantView Operational InsightsAccess to obtain responses to operational insights queries.
AlertsView Alerts HistoryRead-only access for alerts history.
AlertsResolve AlertsAccess to read, edit, and delete alerts.
AlertsView AlertsRead-only access for alerts.
AlertsManage AlertsAccess to read, create, edit, and delete alerts history.
Computed AttributesView Computed attributesRead-only access for computed attributes tab, inventory, and details.
Computed AttributesManage Computed attributesAccess to read, create, delete drafts, and deactivate computed attributes.
DashboardsView License Usage DashboardRead-only access to view the license usage dashboard.
DashboardsManage Standard DashboardsAdd custom attributes that are not yet in the data warehouse.
Data GovernanceManage Usage LabelsAccess to read, create, and delete usage labels.
Data GovernanceManage Data Usage PoliciesAccess to read, create, edit, and delete data usage policies.
Data GovernanceView Data Usage PoliciesRead-only access for data usage policies belonging to your organization.
Data GovernanceView User Activity LogRead-only access to view recorded audit logs of Platform activities.
Data IngestionManage SourcesAccess to read, create, edit, and disable sources.
Data IngestionView SourcesRead-only access to available sources in the Catalog tab and authenticated sources in the Browse tab.
Data IngestionManage Audience Share ConnectionsAccess to create, accept, and decline partner handshakes to connect two organizations and enable Segment Match flows.
Data IngestionManage Audience ShareAccess to read, create, edit, and publish Segment Match feeds with active partners.
Data LifecycleView Data LifecycleRead-only access for data lifecycle.
Data LifecycleManage Data LifecycleAccess to read, create, edit, and delete data lifecycle.
Data ModelingManage SchemasAccess to read, create, edit, and delete schemas and related resources.
Data ModelingView SchemasRead-only access to schemas and related resources.
Data ModelingManage RelationshipsAccess to read, create, edit, and delete schema relationships.
Data ModelingManage Identity MetadataAccess to read, create, edit, and delete identity metadata for schemas.
Data ManagementManage DatasetsAccess to read, create, edit, and delete datasets. Read-only access for schemas.
Data ManagementView DatasetsRead-only access for datasets and schemas.
Data ManagementData MonitoringRead-only access to monitoring datasets and streams.
Data Science WorkspaceManage Data Science WorkspaceAccess to read, create, edit, and delete in Data Science Workspace.
DestinationsView DestinationsRead-only access to view available destinations in the Catalog tab and authenticated destinations in the Browse tab.
DestinationsManage DestinationsAccess to read, create, and delete destination connections and destination accounts.
DestinationsActivate DestinationsGives users the ability to activate segments to existing destinations. Enables the mapping step in the activation workflow. This permission also requires the View Destinations permission to be granted to the user who will activate data to destinations.
DestinationsActivate Segment without MappingGives users the ability to activate segments to existing destinations, without displaying the mapping step. Users can add and remove segments in activation workflows, but cannot add or remove mapped attributes or identities. This permission also requires the View Destinations permission to be granted to the user who will activate data to destinations.
DestinationsManage and Activate Dataset DestinationsAbility to read, create, edit, and disable dataset export flows. Ability to also activate data to active datasets that have been created. This permission also requires the View Destinations permission to be granted to the user who will activate data to destinations.
DestinationsDestination AuthoringAbility to author destinations using Adobe Experience Platform Destination SDK.
Identity ManagementManage Identity NamespacesAccess to read, create, edit, and delete identity namespaces.
Identity ManagementView Identity NamespacesRead-only access for identity namespaces.
Identity ManagementView Identity GraphRead-only access for identity graphs.
Intelligent ServicesView Attribution AIRead-only access for Attribution AI settings and insights.
Intelligent ServicesManage Attribution AIAccess to read, create, edit, and delete Attribution AI models.
Intelligent ServicesView Customer AIAccess to read or view Customer AI models.
Intelligent ServicesManage Customer AIAccess to create, update, delete, enable, or disable Customer AI models.
Profile ManagementManage ProfilesIngest data from multiple sources, build robust profiles for individual customers, and store profile-enabled data in the data lake and the Real-Time Customer Profile data store.
Profile ManagementView ProfilesRead-only access to available profiles.
Profile ManagementManage SegmentsAccess to read, create, edit, and delete segments.
Profile ManagementView SegmentsRead-only access to available segments.
Profile ManagementManage Merge PoliciesAccess to read, create, edit, and delete merge policies.
Profile ManagementView Merge PoliciesRead-only access to available merge policies.
Profile ManagementImport AudiencesAccess to read, create, edit, and delete imported audiences.
Profile ManagementExport Audience for SegmentAbility to export an evaluated audience segment to a dataset.
Profile ManagementEvaluate a Segment to an AudienceAbility to generate profiles for an audience by evaluating a segment definition.
Profile ManagementView B2B AIRead-only access to settings and configurations for all B2B AI/ML services.
Profile ManagementManage B2B AIAccess to read, create, edit, and delete settings and configurations for all B2B AI/ML services.
Profile ManagementView B2B ProfileRead-only access to B2B entity profiles (such as Account, Opportunity, and so on), settings and configurations for all B2B AI/ML services, and B2B dashboard widgets.
Profile ManagementManage B2B ProfileAccess to read, create, edit, and delete B2B entity profiles (such as Account, Opportunity, and so on). Read-only access for settings and configurations for all B2B AI/ML services, and B2B dashboard widgets.
Query ServiceManage QueriesAccess to read, create, edit, and delete structured SQL queries for Platform data.
Query ServiceManage Query Service IntegrationAccess to create, update, and delete non-expiring credentials for Query Service access.
Sandbox AdministrationManage SandboxesAccess to read, create, edit, and delete sandboxes.
Sandbox AdministrationView SandboxesRead-only access for sandboxes belonging to your organization.
Sandbox AdministrationReset a SandboxAbility to reset a sandbox.

Next steps

By reading this guide, you have been introduced to the main principles of access control in Experience Platform. You can now continue to the attribute based access control user guide for detailed steps on how use Experience Cloud to create roles and assign permissions for Experience Platform.


Elevate and Empower Teams with Agentic AI for Exceptional Experiences

Online | Strategy Keynote | General Audience

Elevate and empower your CX teams with AI that transforms creativity, personalization, and productivity. Discover how Adobe is...

Tue, Mar 18, 1:00 PM PDT (8:00 PM UTC)

Register

Martech Guide to Building a Foundation of Trust

In-person | Session | General Audience

Let’s face it — navigating through the landscape of fragmented regulation can create friction across internal teams and loss of consumer...

Thu, Mar 20, 10:30 AM PDT (5:30 PM UTC)

Register

Connect with Experience League at Summit!

Get front-row access to top sessions, hands-on activities, and networking—wherever you are!

Learn more