Permissions

Permissions provides a central location for managing Experience Platform access for your organization. Through Permissions, you can grant groups of users access permissions for various Experience Platform capabilities, such as Manage Datasets, View Datasets, or Manage Profiles.

Roles

In the Roles section, permissions are assigned to users through the use of roles. Roles allow you to grant permissions to one or multiple users, and also contain their access to the scope of the sandboxes that are assigned to them through roles. Users can be assigned to one or multiple roles belonging to your organization.

Default roles

Experience Platform comes with two pre-configured default roles. The following table outlines what is provided in each default profile, including the sandbox they grant access to as well as the permissions they grant within the scope of that sandbox.

RoleSandbox accessPermissions
Default production all accessProdAll permissions applicable to Experience Platform, except for Sandbox Administration permissions.
Sandbox AdministratorsN/AProvides access to the Prod sandbox and to Sandbox Administration permissions.

Sandboxes and permissions

Non-Production sandboxes are a form of data virtualization that allow you to isolate data from other sandboxes and are typically used for development experiments, testing, or trials. A role’s permissions give the role’s users access to Experience Platform features within the sandbox environments to which they’ve been granted access to. A default Experience Platform license grants you five sandboxes (one production and four non-production). You can add packs of ten non-production sandboxes up to a maximum of 75 sandboxes in total. Please contact your organization’s administrator or your Adobe sales representative for more details.

For more information about sandboxes in Experience Platform, please refer to the sandboxes overview.

Access to sandboxes

Access to sandboxes is managed through roles. For detailed steps on how to enable access to a sandbox for a role, see the attribute based access control roles guide.

Users can be granted access to one or more sandboxes within a role. If one user is included in two or more roles, that user will have access to all sandboxes included in those roles.

The “Sandbox Management” permission allows users to manage, view, or reset sandboxes.

Resource permissions

Resource permissions grant access to specific Experience Platform capabilities. Resources are broken down into categories that contain a set of relevant permissions, which can be individually assigned to roles.

In Permissions, a role’s resources workspace displays the sandboxes and permissions that are active for that role:

A role's resource workspace with a list of selected categories and permissions.

The following table outlines the available resource categories for both Experience Platform and applications managed through Permissions:

CategoryDescription
Adobe Mix ModelerConfigure, manage, and view permissions for Adobe Mix Modeler.
AI AssistantConfigure permissions for AI Assistant.
AlertsConfigure manage, resolve, and view permissions for alerts and alerts history.
B2B Account ListsConfigure manage, view, and publish permissions for B2B account lists, including actions such as add, remove, import, and delete accounts from account lists.
B2B Admin ConfigurationsConfigure manage and view permissions for B2B admin configurations, including digital asset management connections, asset repositories, and events.
B2B AssetsConfigure manage and view permissions for B2B assets, including emails, SMS, landing pages, fragments, templates, and images.
B2B Buying GroupsConfigure manage and view permissions for B2B buying groups, including features such as solution interests, roles templates, and buying group status.
B2B Channel ConfigurationsConfigure manage and view permissions for B2B channel configurations, including settings such as communication limits, API credentials, and security settings.
B2B DashboardsConfigure view permissions for B2B dashboards, including features such as account engagement, buying group stages, surging accounts, and contact coverage.
B2B JourneysConfigure manage, view, and publish permissions for B2B journeys, including features such as account and person actions, event listeners, and split paths.
CampaignsConfigure manage, publish, and view permissions to campaigns in Journey Optimizer.
Channel ConfigurationsConfigure manage, view, and export channel configurations features such as subdomains, IP pools, message presets, PTR records, suppression lists, landing page settings, SMS settings, and file routing.
CollaborationsConfigure manage and view permissions to Real-Time Customer Data Profile Collaboration features.
Computed AttributesConfigure manage and view permissions to draft or published computed attributes.
Customer Managed KeysConfigure manage permissions to customer managed keys.
DashboardsConfigure manage and view permissions to standard, custom, and licensed dashboards.
Data CollectionConfigure manage and view permissions to datastreams.
Data GovernanceConfigure manage, apply, and view permissions to data Ggvernance features such as labels, policies, and activity logs.
Data IngestionConfigure manage and view permissions to data ingestion features such as sources and audience share.
Data LifecycleConfigure manage and view permissions to data hygiene features.
Data ManagementConfigure manage and view permissions to data management features such as datasets and monitoring datasets and streams.
Data ModelingConfigure manage and view permissions to data modeling features such as schemas, relationships, and identity metadata.
Data Science WorkspaceConfigure manage permissions to Data Science Workspace.
Decision ManagementConfigure manage and view permissions to decisions, offers, and ranking strategy features in decision management.
DestinationsConfigure manage and view permissions to destinations, including features such as activation and authoring with Destinations SDK.
Federated DataConfigure manage and view permissions to federated data features.
Identity ManagementConfigure manage and view permissions to Identity Service features such as identity namespaces and the identity graph.
Intelligent ServiceConfigure manage and view permissions to attribution AI and customer AI in intelligent service.
IP Warmup ConfigurationsConfigure manage and view permissions to IP warmup plans and view permissions to view IP warmup reports.
Journey Optimizer LibraryConfigure manage permissions to library items in Adobe Journey Optimizer.
Journey Optimizer RulesConfigure manage and view permissions to frequency rules in Adobe Journey Optimizer.
JourneysConfigure manage, publish, and view permissions to journeys, including features such as journeys report, events, data sources, and actions.
MessagesConfigure manage, publish, and view permissions to messages, including features such as messages preview and test.
Privacy ServiceConfigure manage and view permissions to Privacy Service features.
Profile ManagementConfigure manage, view, export, and evaluation permissions to profile service features such as audiences, profiles, and merge policies.
ProspectsConfigure manage and view permissions to prospects schemas, profiles, and audiences, including features such as seeing the prospect accordion.
Query ServiceConfigure manage permissions to query service features such as non-expiring credential and structured SQL queries.
ReportsConfigure view permissions to channel reports.
Sandbox AdministrationConfigure manage, view, and reset permissions when administering sandboxes.
Traits ConfigurationConfigure manage and view traits via the computed attributes UI.
Translation ServicesConfigure manage and view permissions to translation services for projects, tasks, reviews, inhouse, settings, and providers.

The following table outlines the available permissions for Experience Platform in the role, with descriptions of the specific Experience Platform capabilities they grant access to. For detailed steps on how to add permissions to a role, see the attribute based access control roles guide.

CategoryPermissionDescription
Adobe Mix ModelerManage Adobe Mix Modeler Harmonized DataThe ability to view and modify harmonized data.
Adobe Mix ModelerView Adobe Mix Modeler Harmonized DataRead-only access to harmonized data.
Adobe Mix ModelerManage Adobe Mix Modeler Models ConfigurationsThe ability to view and modify models configurations.
Adobe Mix ModelerView Adobe Mix Modeler Models ConfigurationsRead-only access to models configurations.
Adobe Mix ModelerManage Adobe Mix Modeler Models Plans ConfigurationsThe ability to view and modify plans configurations.
Adobe Mix ModelerView Adobe Mix Modeler Models Plans ConfigurationsRead-only access to plans configurations.
AI AssistantEnable AI AssistantAbility to ask the AI assistant questions.
AI AssistantView Operational InsightsAccess to obtain responses to operational insights queries.
AI AssistantGenerate ContentEnable users to generate content using the AI Assistant.
AI AssistantManage Brand KitEnable users to create brand guidelines using the AI Assistant.
AlertsView Alerts HistoryRead-only access for alerts history.
AlertsResolve AlertsAccess to read, edit, and delete alerts.
AlertsView AlertsRead-only access for alerts.
AlertsManage AlertsAccess to read, create, edit, and delete alerts.
B2B Account ListsManage B2B Account ListsAbility to view and access Account Lists in the left nav. Users with access to Account Lists should have access to all Account Lists CRUD functions: /accounts-list.
B2B Admin ConfigurationsManage B2B Admin ConfigurationsAbility to view and access B2B Admin Configurations in the left nav. Users with access to B2B Admin Configurations should have access to all SMS API Credentials CRUD functions: /admin-configs.
B2B AssetsManage B2B AssetsAbility to view and access Assets in the left nav. Users with access to Assets should have access to all Assets CRUD functions: /assets-listing.
B2B AssetsManage B2B TemplatesAbility to view and access Templates in the left nav. Users with access to Templates should have access to all Templates CRUD functions: /b2b-content-templates.
B2B AssetsManage B2B FragmentsAbility to view and access Fragments in the left nav. Users with access to Fragments should have access to all Fragments CRUD functions: /fragments.
B2B Buying GroupsManage B2B Buying GroupsAbility to view and access Buying Groups in the left nav. Users with access to Buying Groups should have access to all Buying Groups CRUD functions: /buying-groups.
B2B DashboardsManage B2B Engagement DashboardsAbility to view and access Dashboard in the left nav. Users with access to Dashboards should have access to all Dashboards CRUD functions: /insights-dashboard.
B2B Channel ConfigurationsManage B2B Channels ConfigurationsAbility to view and access Channels in the left nav. Users with access to Channels should have access to all Channels CRUD functions: /channels-config.
B2B JourneysManage B2B Account JourneysAbility to view and access Account Journeys in the left nav. Users with access to Account Journeys should have access to all Account Journeys CRUD functions: /account-journeys.
CampaignsManage CampaignsAccess to read, create, edit, and delete campaigns.
CampaignsApprove and Publish CampaignsThe ability to approve and publish campaigns.
CampaignsPublish CampaignsAbility to publish campaigns.
CampaignsView CampaignsRead-only access to campaigns.
CampaignsView Campaigns ReportRead-only access to campaign reports.
Channel ConfigurationsView Messages General SettingsRead-only access to messages general settings.
Channel ConfigurationsManage Subdomains DelegationsAccess to read, create, edit, and delete subdomain delegations.
Channel ConfigurationsManage IP PoolsAccess to read, create, and edit IP pools.
Channel ConfigurationsManage Messages General SettingsAccess to read, create, edit, and delete messages general settings.
Channel ConfigurationsManage Messages PresetsAccess to read, create, edit, and delete messages presets.
Channel ConfigurationsView Messages PresetsRead-only access to messages presets.
Channel ConfigurationsManage PTR RecordsAccess to read and edit PTR records.
Channel ConfigurationsView PTR RecordsRead-only access to PTR records.
Channel ConfigurationsManage SuppressionAccess to read, create, edit, and delete suppression rules.
Channel ConfigurationsView Suppression ListRead-only access to the suppression list.
Channel ConfigurationsExport Suppression ListAccess to export the suppression list as a CSV file.
Channel ConfigurationsManage Landing Page SettingsAccess to read, create, edit, and delete landing page settings.
Channel ConfigurationsManage SMS SettingsAccess to read, create, edit, and delete SMS settings.
Channel ConfigurationsManage SMS SubdomainsAccess to read, create, edit, and delete SMS subdomains.
Channel ConfigurationsManage File RoutingAccess to read, create, edit, and delete file routings.
Channel ConfigurationsView File RoutingRead-only access to file routings.
Channel ConfigurationsManage SeedlistThe ability to create and edit the Seedlist.
Channel ConfigurationsManage Language SettingsThe ability to create and edit the language settings.
Channel ConfigurationsManage Web SubdomainsThe ability to create and edit CJM web subdomains.
Channel ConfigurationsManage Push CredentialsThe ability to create, edit, and delete push credentials.
CollaborationsManage Collaboration InstancesView, create, update, and delete an organization’s collaboration instances. Discover other organizations’ collaboration instances.
CollaborationsRead Collaboration InstancesRead an organization’s collaboration instances and discover other organizations’ collaboration instances.
CollaborationsManage Connection InvitesView, create, and delete connection invites initiated by your organization. Accept and decline connection invite initiated by other organizations.
CollaborationsRead Connection InvitesRead-only access to connection invites.
CollaborationsManage Collaboration ConnectionsAn advertiser can view, create, and update settings as well as submit and delete connections. A publisher can view, accept, or decline connections.
CollaborationsRead Collaboration ConnectionsRead-only access to connections.
CollaborationsManage Audience DataOnboard and discover audiences. Update public, private, and custom audiences and manage Audience Inventory metadata settings.
CollaborationsRead Audience DataRead and discover audiences.
CollaborationsManage Measurement DataOnboard, update, and delete measurement data.
CollaborationsRead Measurement DataRead-only access to measurement data.
CollaborationsManage ProjectsView, create, update, and delete projects for any of the discover, share, activate, and measurement activities.
CollaborationsRead ProjectsView projects for any of the discover, share, activate, and measurement activities.
CollaborationsRead User ActivitiesRead-only access to user activities.
CollaborationsExport User ActivitiesExport user activities.
CollaborationsRead Collaboration Credit MonitoringCredit monitoring at the organization and instance level.
Computed AttributesView Computed attributesRead-only access for computed attributes tab, inventory, and details.
Computed AttributesManage Computed attributesAccess to read, create, delete drafts, and deactivate computed attributes.
Customer Managed KeysManage Customer Managed KeysAccess to view and configure customer managed keys.
DashboardsView License Usage DashboardRead-only access to view the license usage dashboard.
DashboardsManage Standard DashboardsAdd custom attributes that are not yet in the data warehouse.
DashboardsView Standard DashboardsRead-only access to view the license usage dashboard.
DashboardsManage Custom DashboardsAccess to create or edit a dashboard.
DashboardsView Custom DashboardsRead-only access to user defined dashboards.
DashboardsManage Report SchedulesAbility to create schedules.
Data CollectionManage DatastreamsAccess to read, create, and edit datastreams.
Data CollectionView DatastreamsRead-only access to datastreams.
Data GovernanceManage Usage LabelsAccess to read, create, and delete usage labels.
Data GovernanceManage Data Usage PoliciesAccess to read, create, edit, and delete data usage policies.
Data GovernanceView Data Usage PoliciesRead-only access for data usage policies belonging to your organization.
Data GovernanceView User Activity LogRead-only access to view recorded audit logs of Platform activities.
Data GovernanceView Privacy ConsoleRead-only access to privacy consoles.
Data IngestionManage SourcesAccess to read, create, edit, and disable sources.
Data IngestionView SourcesRead-only access to available sources in the Catalog tab and authenticated sources in the Browse tab.
Data IngestionManage Audience Share ConnectionsAccess to create, accept, and decline partner sharing to connect two organizations and enable Segment Match flows.
Data IngestionManage Audience ShareAccess to read, create, edit, and publish Segment Match feeds with active partners.
Data LifecycleView Data LifecycleRead-only access for data lifecycle.
Data LifecycleManage Data LifecycleAccess to read, create, edit, and delete data lifecycle.
Data ModelingManage SchemasAccess to read, create, edit, and delete schemas and related resources.
Data ModelingView SchemasRead-only access to schemas and related resources.
Data ModelingManage RelationshipsAccess to read, create, edit, and delete schema relationships.
Data ModelingManage Identity MetadataAccess to read, create, edit, and delete identity metadata for schemas.
Data ManagementManage DatasetsAccess to read, create, edit, and delete datasets. Read-only access for schemas.
Data ManagementView DatasetsRead-only access for datasets and schemas.
Data ManagementData MonitoringRead-only access to monitoring datasets and streams.
Data Science WorkspaceManage Data Science WorkspaceAccess to read, create, edit, and delete in Data Science Workspace.
Decision ManagementManage Experience DecisioningAbility to manage experience decisioning entities.
Decision ManagementView Experience DecisioningRead-only access to experience decisioning entities.
Decision ManagementManage DecisionsAccess to read, create, edit, and delete decisioning entities.
Decisions ManagementView DecisionsRead-only access to decision entities.
Decision ManagementManage OffersAccess to read, create, edit, and delete all offers and components. Read-only access to decisions and collections.
Decsion ManagementManage Ranking StrategiesAccess to read, create, edit, and delete custom reports and use action features.
DestinationsView DestinationsRead-only access to view available destinations in the Catalog tab and authenticated destinations in the Browse tab.
DestinationsManage DestinationsAccess to read, create, and delete destinations connections and destination accounts.
DestinationsActivate DestinationsAbility to activate data to active destinations that have been created. This permission also requires either View Destinations or Manage Destinations to be granted to the user who will activate destinations.
DestinationsActivate Segment without MappingThe ability to activate audiences to existing destinations, without displaying the mapping step. Users can add and remove audiences in activation workflows, but cannot add or remove mapped attributes or identities. This permission also requires the View Destinations permission to be granted to the user who will activate data to destinations.
DestinationsManage and Activate Dataset DestinationsAbility to read, create, edit, and disable dataset export flows. Ability to also activate data to active datasets that have been created. This permission also requires the View Destinations permission to be granted to the user who will activate data to destinations.
DestinationsDestination AuthoringAbility to author destinations using Adobe Experience Platform Destination SDK.
Federated DataManage Federated DataThe ability to access all federated data features such as creating schemas, models, and compositions.
Identity ManagementManage Identity NamespacesAccess to read, create, edit, and delete identity namespaces.
Identity ManagementView Identity NamespacesRead-only access for identity namespaces.
Identity ManagementView Identity GraphRead-only access for identity graphs.
Identity ManagementManage Identity SettingsAccess to read, create, and edit identity settings.
Identity ManagementView Identity SettingsRead-only access to identity settings.
Intelligent ServicesView Attribution AIRead-only access for Attribution AI settings and insights.
Intelligent ServicesManage Attribution AIAccess to read, create, edit, and delete Attribution AI models.
Intelligent ServicesView Customer AIAccess to read or view Customer AI models.
Intelligent ServicesManage Customer AIAccess to create, update, delete, enable, or disable Customer AI models.
IP Warmup ConfigurationsView IP Warmup PlansRead-only access to IP warmup plans.
IP Warmup ConfigurationsManage IP Warmup PlansThe ability to manage IP warmup plans.
IP Warmup ConfigurationsView IP Warmup ReportsRead-only access to IP warmup reports.
JourneysManage JourneysAccess to read, create, edit, and delete journeys.
JourneysView JourneysRead-only access to journeys.
JourneysView Journeys ReportRead-only access to journeys report.
JourneysManage Journeys Events, Data Sources and ActionsAccess to read, create, edit, and delete events, data sources, or actions.
JourneysView Journeys Events, Data Sources and ActionsRead-only access to events, data sources, or actions.
JourneysApprove and Publish JourneysAbility to approve and publish journeys when a policy is applied.
JourneysPublish JourneysAbility to publish journeys.
Journey Optimizer LibraryManage Library ItemsThe ability to add and delete saved expressions.
Journey Optimizer LibraryPublish FragmentsThe ability to publish content fragments.
Journey Optimizer LibrarySimulate ContentAccess to the simulate content option for previewing and proofing.
Journey Optimizer RulesView Frequency RulesRead-only access to frequency rules.
Journey Optimizer RulesManage Frequency RulesAccess to read, create, edit, or delete frequency rules.
MessagesManage MessagesAccess to read, create, edit, and delete messages.
MessagesView MessagesRead-only access to messages.
MessagesView Messages ReportAccess to read and edit message reports.
MessagesPublish MessagesAbility to publish messages.
MessagesManage Messages Preview and TestAbility to approve and publish messages when a policy is applied.
Privacy ServiceManage Privacy ServiceAccess to read and write privacy workflows.
Privacy ServiceView Privacy ServiceRead-only access to privacy workflows.
Profile ManagementManage ProfilesAccess to read, create, edit, and delete datasets that are used for customer profiles. Read-only access to available profiles.
Profile ManagementView ProfilesRead-only access to available profiles.
Profile ManagementManage SegmentsAccess to read, create, edit, and delete audiences.
Profile ManagementView SegmentsRead-only access to available audiences.
Profile ManagementManage Merge PoliciesAccess to read, create, edit, and delete merge policies.
Profile ManagementView Merge PoliciesRead-only access to available merge policies.
Profile ManagementImport AudiencesAbility to use the CSV upload workflow to import new audiences.
Profile ManagementExport Audience SegmentAbility to export an evaluated audience to a dataset.
Profile ManagementEvaluate a Segment to an AudienceAbility to generate profiles for an audience by evaluating a segment definition.
Profile ManagementView B2B AIRead-only access to settings and configurations for all B2B AI/ML services.
Profile ManagementManage B2B AIAccess to read, create, edit, and delete settings and configurations for all B2B AI/ML services.
Profile ManagementView B2B ProfileRead-only access to B2B entity profiles (such as Account, Opportunity, and so on), settings and configurations for all B2B AI/ML services, and B2B dashboard widgets.
Profile ManagementManage B2B ProfileAccess to read, create, edit, and delete B2B entity profiles (such as Account, Opportunity, and so on). Read-only access for settings and configurations for all B2B AI/ML services, and B2B dashboard widgets.
Profile ManagementManage LookalikesAbility to create or delete look-alike audiences.
Profile ManagementView B2B ExperienceAbility to view B2B profiles and attributes.
Profile ManagementView Profile SettingsRead-only access to all profile settings.
Profile ManagementManage Profile SettingsAccess to read and edit all profile settings.
ProspectsView ProspectsRead-only access to prospect schemas, profiles, audiences, and the prospect accordion.
ProspectsManage ProspectsAbility to create and manage prospect schemas, profiles, and audiences. Read-only access to the prospect accordion.
Query ServiceManage QueriesAccess to read, create, edit, and delete structured SQL queries for Platform data.
Query ServiceManage Query Service IntegrationAccess to create, update, and delete non-expiring credentials for Query Service access.
Query ServiceManage Query SessionsAbility to evict existing sessions.
Query ServiceManage Allow ListAbility to manage IP restrictions for your organization.
ReportsView Channel ReportsThe ability to view and modify channel reports.
Sandbox AdministrationManage SandboxesAccess to read, create, edit, and delete sandboxes.
Sandbox AdministrationView SandboxesRead-only access for sandboxes belonging to your organization.
Sandbox AdministrationReset a SandboxAbility to reset a sandbox.
Sandbox AdministrationManage PackagesAccess to create, import, or export packages.
Sandbox AdministrationShare PackagesAccess to share packages across different organizations.
Traits ConfigurationsView TraitsRead-only access for traits.
Traits ConfigurationsManage TraitsAccess to manage traits.
Translation ServiceManage Translation ProjectsThe ability to manage translation projects.
Translation ServiceView Translation ProjectsRead-only access to translation projects.
Translation ServiceManage Translation TasksThe ability to manage translation tasks.
Translation ServiceView Translation TasksRead-only access to translation tasks.
Translation ServiceManage Translation ReviewsThe ability to manage translation reviews.
Translation ServiceView Translation ReviewsRead-only access to translation reviews.
Translation ServiceManage Translation In-houseThe ability to manage translation in-house.
Translation ServiceView Translation In-houseRead-only access to translation in-house.
Translation ServiceManage Translation SettingsThe ability for administrators to manage translation settings.
Translation ServiceManage Translation ProvidersThe ability to manage translation providers.