Permission List¶
TrueWatch supports setting permissions for custom roles within a workspace to meet the permission needs of different users.
Note
Currently, only functional operation permissions within the workspace can be set.
Permission List¶
- √: For default roles, it means supported for this permission. For custom roles, it means supported for authorizing this permission to custom roles.
- ×: For default roles, it means not supported for this permission. For custom roles, it means not supported for authorizing this permission to custom roles.
Features |
Operation Permissions |
Owner | Administrator | Standard | Read-only | Custom Roles |
|---|---|---|---|---|---|---|
| General | Default Access | √ | √ | √ | √ | √ |
| Explorer > Global Configuration Management | √ | √ | × | × | √ | |
| Export Management | √ | √ | √ | × | √ | |
| Workspace Management | API Key Management | √ | √ | × | × | √ |
| Member Personal API Key Usage Permission Management | √ | √ | × | × | √ | |
| Token View | √ | √ | × | × | √ | |
| Token Replacement | √ | √ | × | × | × | |
| Client Token Management | √ | √ | √ | × | √ | |
| Member Management View | √ | √ | √ | × | √ | |
| Invite Members | √ | √ | √ | × | √ | |
| Member Management | √ | √ | × | × | √ | |
| Transfer Ownership | √ | × | × | × | × | |
| Settings Management | √ | √ | × | × | √ | |
| Dissolve Workspace | √ | × | × | × | × | |
| Data Storage Strategy Management | √ | × | × | × | × | |
| Workspace Status Management | √ | × | × | × | × | |
| Data Permission Management | Configuration Management | √ | √ | × | × | √ |
| Sensitive Data Scanning | Configuration Management | √ | √ | × | × | √ |
| Field Management | Field Configuration Management | √ | √ | √ | × | √ |
| Regular Expressions | Regular Expression Configuration Management | √ | √ | × | × | √ |
| Cloud Account Management | Account Management | √ | √ | × | × | × |
| Integration Configuration Management | √ | √ | × | × | √ | |
| Global Tags | Global Tag Configuration Management | √ | √ | × | × | √ |
| Sharing Management | Sharing Configuration Management | √ | √ | √ | × | √ |
| Snapshot | Create Snapshot | √ | √ | √ | √ | √ |
| Delete Snapshot | √ | √ | √ | × | √ | |
| Plans & Billing | Plans & Billing Read-Only Permission | √ | √ | × | × | √ |
| Plans & Billing Read-Write Permission | √ | × | × | × | × | |
| Upgrade Permission | √ | × | × | × | × | |
| Scenarios | Dashboard & View View | √ | √ | √ | √ | √ |
| Dashboard Management | √ | √ | √ | × | √ | |
| Tag Permission Management | √ | √ | × | × | √ | |
| View Management | √ | √ | √ | × | √ | |
| Note & Explorer Management | √ | √ | √ | × | √ | |
| Chart Configuration Management | √ | √ | √ | × | √ | |
| Scheduled Report View | √ | √ | √ | × | √ | |
| Scheduled Report Management | √ | √ | √ | × | √ | |
| Events | Manual Recovery | √ | √ | √ | × | √ |
| Event Data Query | √ | √ | √ | √ | √ | |
| Infrastructure | Infrastructure Configuration Management | √ | √ | × | × | √ |
| Infrastructure Data Query | √ | √ | √ | √ | √ | |
| Logs | Log Index Management | √ | √ | × | × | √ |
| External Index Management | √ | √ | × | × | √ | |
| Data Forwarding | √ | √ | × | × | √ | |
| Log Data Query | √ | √ | √ | √ | √ | |
| Metrics | Metrics Description Management | √ | √ | √ | × | √ |
| Metrics Data Query | √ | √ | √ | √ | √ | |
| APM | Related Log Management | √ | √ | √ | × | √ |
| APM Data Query | √ | √ | √ | √ | √ | |
| Issue Auto-Discovery | √ | √ | √ | × | √ | |
| Service Management | √ | √ | × | × | √ | |
| RUM | Application Configuration Management | √ | √ | √ | × | √ |
| Tracing Configuration Management | √ | √ | √ | × | √ | |
| RUM Data Query | √ | √ | √ | √ | √ | |
| Session Replay View | √ | √ | √ | √ | √ | |
| Issue Auto-Discovery | √ | √ | √ | × | √ | |
| LLM Monitoring | Application Configuration Management | √ | √ | √ | × | √ |
| LLM Data Query | √ | √ | √ | √ | √ | |
| Synthetic Tests | Task Configuration Management | √ | √ | √ | × | √ |
| Self-built Nodes Configuration Management | √ | √ | √ | × | √ | |
| Monitoring | Monitor View | √ | √ | √ | √ | √ |
| Monitor Configuration Management | √ | √ | √ | × | √ | |
| External Event Configuration Management | √ | √ | × | × | √ | |
| Intelligent Inspection Configuration Management | √ | √ | √ | × | √ | |
| SLO Configuration Management | √ | √ | √ | × | √ | |
| Mute Configuration Management | √ | √ | √ | × | √ | |
| Alert Strategy Configuration Management | √ | √ | √ | × | √ | |
| Notification Target Configuration Management | √ | √ | × | × | √ | |
| Incidents | Channel Management | √ | √ | √ | × | √ |
| Channel Subscription | √ | √ | √ | √ | √ | |
| Channel View | √ | √ | √ | √ | √ | |
| Issue Management | √ | √ | √ | × | √ | |
| Issue View | √ | √ | √ | √ | √ | |
| Reply Management | √ | √ | √ | × | √ | |
| Reply View | √ | √ | √ | √ | √ | |
| Level Configuration | √ | √ | × | × | √ | |
| Notification Strategy | √ | √ | √ | × | √ | |
| Schedule | √ | √ | √ | × | √ | |
| Issue Discovery | √ | √ | √ | × | √ | |
| Pipelines | Pipelines Management | √ | √ | √ | × | √ |
| Blacklist | Blacklist Create & Edit | √ | √ | √ | × | √ |
| Blacklist Enable & Disable | √ | √ | √ | × | √ | |
| Blacklist Delete | √ | √ | √ | × | √ | |
| Generate Metrics | Generate Metrics Configuration Management | √ | √ | √ | × | √ |
| DCA | DCA Configuration Management | √ | √ | × | × | × |
| DataFlux Func (Automata) | Func Activation/Configuration | √ | × | × | × | × |
| RUM (Automata) | RUM Activation/Configuration | √ | × | × | × | × |
| RUM Administrator | √ | √ | × | × | × | |
| Cloud Billing | Cloud Billing Data Query | √ | √ | √ | √ | √ |
| External Data Sources | Data Source Configuration Management | √ | √ | × | × | √ |
| Data Source Query Permission | √ | √ | √ | √ | √ | |
| Environment Variables | Environment Variable Configuration Management | √ | √ | × | × | √ |
| Operation Audit | Operation Audit View | √ | √ | √ | √ | √ |
| Security Monitoring | CSPM Configuration Management | √ | √ | √ | × | √ |
| SIEM Configuration Management | √ | √ | √ | × | √ | |
| Fault Center | Fault View | √ | √ | √ | √ | √ |
| Fault Management | √ | √ | √ | × | √ | |
| Fault Collaboration | √ | √ | √ | × | √ | |
| Fault Level Management | √ | √ | × | × | √ | |
| On-Call Management | √ | √ | √ | × | √ | |
| Error Center | Error View | √ | √ | √ | √ | √ |
| Error Management | √ | √ | √ | × | √ | |
| Error Collaboration | √ | √ | √ | × | √ | |
| Error Delivery Rule Management | √ | √ | × | × | √ | |
| Error Delivery Rule View | √ | √ | √ | × | √ |
Permission Description Details¶
Contains specific descriptions for each permission item.
Features |
Operation Permissions |
Description |
|---|---|---|
| General | Default Access | Default view and operation permissions for users upon entering the workspace. Includes the following permission scopes |
| Explorer > Global Configuration Management | ||
| Export Management | Data export permission management within the workspace. Includes the following scopes: |
|
| Workspace Management | API Key Management | Operations including creating, viewing, and deleting API Keys |
| Member Personal API Key Usage Permission Management | Enable or disable member eligibility to use personal API Keys in the current workspace. Does not provide display of plaintext API Key, secret content, or credential lifecycle management | |
| Token View | Retrieve the workspace Token | |
| Token Replacement | Replace the workspace Token. Users must have the "Token View" permission to have this permission | |
| Client Token Management | Creating and deleting Client Tokens | |
| Member Management View | Includes view (read-only) permissions for the following pages: |
|
| Invite Members | ||
| Member Management | Operations related to workspace member management and SSO management, including - SSO Login (Enable, Disable, Delete) - SAML Mapping (Create, Delete, Modify, Enable, Disable) - Custom Mapping (Create, Delete, Modify) |
|
| Transfer Ownership | Transfer workspace ownership to another member | |
| Settings Management | Edit operations on the workspace settings page, including the following permission scopes | |
| Dissolve Workspace | Dissolve the workspace, including unbinding the Commercial Plan workspace from the Billing Center account and deleting the workspace. |
|
| Data Storage Strategy Management | ||
| Workspace Status Management | Includes some operations under workspace locked status. |
|
| Data Permission Management | Configuration Management | |
| Sensitive Data Scanning | Configuration Management | Create, Edit, Enable, Disable, Delete |
| Field Management | Field Configuration Management | Create, Edit, Delete |
| Regular Expressions | Regular Expression Configuration Management | Create, Edit, Clone, Delete |
| Cloud Account Management | Account Management | Create, Edit, Delete |
| Integration Configuration Management | Install, Uninstall, Modify Configuration | |
| Global Tags | Global Tag Configuration Management | Create, Edit, Delete |
| Sharing Management | Sharing Configuration Management | Share Chart, Cancel Chart Sharing, Share Snapshot, Cancel Snapshot Sharing |
| Snapshot | Create Snapshot | Create Snapshots. Includes: |
| Delete Snapshot | Delete Snapshots (Read-only members can only delete snapshots created by their own account). Includes: |
|
| Plans & Billing | Plans & Billing Read-Only Permission | |
| Plans & Billing Read-Write Permission | Includes viewing account balance, recharging, changing payment method, changing Billing Center account, navigating to Billing Center. Only available for members with the Owner role in the current workspace to view and initiate related operations | |
| Upgrade Permission | Entry point to initiate the upgrade process from Free Plan to Commercial Plan. Only available for members with the Owner role in the current workspace | |
| Scenarios | Dashboard & View View | Includes visibility of Dashboard and View modules, querying Dashboards and Views (viewing list page and details page), setting refresh frequency, changing query time; view permission for carousel |
| Dashboard Management | ||
| Tag Permission Management | Management of Dashboard tag permissions: Tag Add, Edit, Delete | |
| View Management | ||
| Note & Explorer Management | ||
| Chart Configuration Management | ||
| Scheduled Report View | View | |
| Scheduled Report Management | Create, Edit, Delete, Enable/Disable | |
| Events | Manual Recovery | Includes manual recovery operations for unrecovered events |
| Event Data Query | Queries all event data within the workspace, including all data for Events and Unrecovered Events | |
| Infrastructure | Infrastructure Configuration Management | Includes operations like editing Host Labels, editing Object Categories, adding Object Categories, adding Tags, and deleting Objects |
| Infrastructure Data Query | Queries all infrastructure object-related data within the workspace, including Host, Container, K8s, Process, Network data, Resource Catalog data, historical 48-hour data, and reported Layer 4 and Layer 7 network data. | |
| Logs | Log Index Management | Read-Write permission. Includes Create, Delete, Modify, Enable, Disable, Drag-and-drop operations |
| External Index Management | Read-Write permission. Includes Bind, Delete operations | |
| Data Forwarding | Read-Write permission. Includes Create, Edit, Delete, Enable, Disable operations | |
| Log Data Query | Query permission for all log data within the current workspace, including TrueWatch Log (L) default index, custom indexes, bound external indexes (ES, Opensearch, SLS standard logstore) data, and Backup Log (BL) data. | |
| Metrics | Metrics Description Management | Edit and modify metrics descriptions |
| Metrics Data Query | Queries all metrics data within the current workspace | |
| APM | Related Log Management | Edit log correlation field configurations |
| APM Data Query | Queries all Traces and Profile data within the current workspace | |
| Issue Auto-Discovery | Error tracking data automatically generates Incident Issues based on dimensions like service, version, resource, and error type | |
| Service Management | Service List management, configuration of custom service filter fields | |
| RUM | Application Configuration Management | Create, Modify, Delete applications |
| Tracing Configuration Management | Create, Modify, Delete tracing configurations | |
| RUM Data Query | Queries all RUM data within the current workspace, including session, session replay, view, resource, error, long task, action data |
|
| Session Replay View | View permission for all session replay data within the current workspace | |
| Issue Auto-Discovery | Error data automatically generates Incident Issues based on dimensions like application name, environment, version, and error type | |
| LLM Monitoring | Application Configuration Management | Create, Modify, Delete applications |
| LLM Data Query | Queries all LLM data within the current workspace | |
| Synthetic Tests | Task Configuration Management | Create, Delete, Modify, Enable, Disable, Test |
| Self-built Nodes Configuration Management | Create, Modify, Delete, Get Configuration | |
| Monitoring | Monitor View | View the monitor list page and monitor configuration details page |
| Monitor Configuration Management | Create, Delete, Test, Modify, Enable, Disable, Import, Batch Export, Batch Delete, Edit Alert Configuration, Create from Template | |
| External Event Configuration Management | View the Webhook address generated by the "External Event Check" monitor | |
| SLO Configuration Management | Create, Delete, Modify, Enable, Disable | |
| Mute Configuration Management | Create, Delete, Modify, Enable, Disable |
|
| Alert Strategy Configuration Management | Create, Delete, Edit Alert Configuration | |
| Notification Target Configuration Management | Create, Delete, Modify | |
| Incidents | Channel Management | |
| Channel Subscription | ||
| Channel View | ||
| Issue Management | Create, Modify, Delete Issues; Attachment Upload | |
| Issue View | ||
| Reply Management | ||
| Reply View | ||
| Level Configuration | ||
| Notification Strategy | Create, Modify, Delete | |
| Schedule | Create, Modify, Delete | |
| Issue Discovery | Create, Modify, Delete, Enable, Disable | |
| Pipelines | Pipelines Management | Read-Write permission. Includes Create, Modify, Delete, Enable, Disable, Import, Batch Export, Batch Delete, Clone from Official Library |
| Blacklist | Blacklist Create & Edit | Includes Create, Modify, Import, Export |
| Blacklist Enable & Disable | Includes Enable, Disable |
|
| Blacklist Delete | Delete Blacklist permission |
|
| Generate Metrics | Generate Metrics Configuration Management | Includes Create, Modify, Delete, Enable, Disable operations |
| DCA | DCA Configuration Management | |
| DataFlux Func (Automata) | Func Activation/Configuration | Activate application, modify domain/spec, upgrade version, reset password, deactivate application |
| RUM (Automata) | RUM Activation/Configuration | Activate application, modify service address, spec, upgrade version, deactivate application |
| RUM Administrator Permission | View configuration info, modify service address, spec, version, status, configuration | |
| Cloud Billing | Cloud Billing Data Query | |
| External Data Sources | Data Source Configuration Management | Create, Edit, Delete operations |
| Data Source Query Permission | Query external data sources | |
| Environment Variables | Environment Variable Configuration Management | Create, Import, Export, Edit, Delete |
| Operation Audit | Operation Audit View | View permission for operation audit data |
| Security Monitoring | CSPM Configuration Management | Create, Delete, Test, Modify, Enable, Disable, Import, Batch Export, Batch Delete, Edit Alert Configuration |
| SIEM Configuration Management | Create, Delete, Modify, Enable, Disable, Import, Batch Export, Batch Delete, Edit Alert Configuration | |
| Fault Center | Fault View | View permission for faults |
| Fault Management | Fault level change, claim, comment, attachment upload | |
| Fault Collaboration | Fault comment, attachment upload | |
| Fault Level Management | ||
| On-Call Management | Create On-Call, Modify On-Call, Delete On-Call | |
| Error Center | Error View | View error list, error details, error distribution, associated context information |
| Error Management | Error status change, claim, assignee, comment, attachment upload | |
| Error Collaboration | Error comment, attachment upload | |
| Error Delivery Rule Management | Create, Modify, Delete error delivery rules | |
| Error Delivery Rule View | View error delivery rules and their configuration scope |
Default Access¶
- Dashboard, Note, Explorer, Built-in View: Read-only permission
- Dashboard Carousel: Read-only permission
- Chart: Read-only permission, Copy
- Dashboard, Note, Explorer: Favorite
- All Explorers: Read-only permission
- All Explorer Personal Quick Filters: Edit permission
- All Explorer Display Columns: Configuration permission
- Dashboard, Note, Explorer Creator: Edit permission
- APM > Service List: Read-only permission
- RUM > Application Configuration: Read-only permission
- RUM > Tracing Configuration: Read-only permission
- Synthetic Tests > Task Configuration: Read-only permission
- Synthetic Tests > Self-built Node Configuration: Read-only permission
- Monitor, Intelligent Inspection, SLO, Mute Management, Alert Strategy, Notification Target Configuration: Read-only permission
- Pipelines Configuration: User pipeline, Official pipeline read-only permission
- Blacklist Configuration: Read-only permission
- Basic Workspace Information: Read-only permission
- Member Management: Read-only permission
- SSO Management: Read-only permission
- Role Management: Read-only permission
- Field Management: Read-only permission
- Data Permission Management: Read-only permission
- Regular Expressions: Read-only permission
- Sharing Management: Read-only permission
- Snapshot: Read-only permission (View/Copy)
- DQL Query Tool
- Integration
- Obs Assistant
- Try Demo Workspace
- Ticket Management
- Workspace Notes (Personal Account Level)
- New User Guide
- Auto-popup "New User Guide"
- Avatar > View New User Guide
- Log Data Access Configuration View: Read-only
- Incidents: Channel Read-only, Issue Read-only, Reply Read-only, Notification Strategy Read-only, Schedule Read-only
Settings Management¶
- Workspace Name Modification
- Description Modification
- Configuration Migration (Import, Export)
- Advanced Settings
- Add, Delete Key Metrics
- Feature Menu Management
- Operation Audit View
- IP Whitelist Settings
- Data Deletion
-
Manual data deletion operations within the workspace, including:
- Delete data for a specific measurement
- Delete custom objects
- Single custom object (Custom Object Details Page)
- All custom objects (Management > Settings > Risky Operations)
- Custom objects under a specific object category (Management > Settings > Risky Operations)
- Enable Approval to Join