​
User permissions and RBAC

Under Settings > Users and roles, you can view the roles associated with each user, as well as whether those roles are granted directly or via SCIM. When adding new users to your Chalk environment, you can assign them roles that determine their permissions in the environment. The available roles in order of increasing permissions are:

  • Viewer: Read the web portal and create new alerts.
  • Data Scientist: Run queries and branch deploy, plus everything that a Viewer can do.
  • Developer: Run queries and migrations, plus everything that a Data Scientist can do.
  • Admin: Create deployments, service tokens, and secrets, plus everything that a Developer can do.
  • Owner: Manage team members, plus everything that an Admin can do.

Customers with Enterprise Features can also configure datasource-level and feature-level role-based access control (RBAC). Under Settings > Access tokens, you can create service tokens that carry tag permissions. At the datasource level, a token can access only the data sources whose tags it permits. At the feature level, a token can block tagged features in two ways: AllowInternal tags let the feature values feed the computation of other features but keep them out of the query results, and Deny tags block the features entirely.

​
Denylisting vs allowlisting tags

The Default permission setting in a token’s Permission tags section decides whether the token uses a denylist or an allowlist:

  • Denylist: Set the default permission to Allow and list the tags to restrict in Denied permission tags. The token can query every tag except the ones in the denylist.
  • Allowlist: Set the default permission to Deny and list the tags to permit in Allowed permission tags. The token cannot query any tag except the ones in the allowlist.

The Authentication page describes the default permission and each tag list in detail.