Permissions
Permissions are the individual actions Matia controls — creating an integration, deleting a monitor, editing a catalog description, and so on. You never assign permissions to people one by one. Instead you assign roles, and each role comes with a ready-made set of permissions.
This page explains what those permissions let people do, area by area.
The three access levels
Within each product area, access comes in three levels that build on each other:
| Level | What it can do |
|---|---|
| Viewer | See everything in the area — browse resources and view issues — but make no changes. |
| Editor | Everything a Viewer can, plus create, edit, trigger, and enable/disable resources, and manage issues. |
| Admin | Everything an Editor can, plus delete resources and manage notification rules. |
You get a level in one of two ways:
- An area-specific role grants that level for a single area — for example, Integrations Editor gives Editor-level access to Integrations only.
- A Global role grants that level across every area at once — for example, Global Editor gives Editor-level access to Integrations, Observability, and Catalog together.
Everyone — regardless of role — can view the catalog, assets, and notifications. Those are read-only building blocks that every role includes.
The tables below use the area-specific role names (Viewer / Editor / Admin). A ✓ means that level grants the capability.
Integrations
Applies to ETL and Reverse ETL integrations. Roles: Integrations Viewer, Integrations Editor, Integrations Admin (or the matching Global role).
| Capability | Viewer | Editor | Admin |
|---|---|---|---|
| View integrations, their settings, and issues | ✓ | ✓ | ✓ |
| Create integrations | ✓ | ✓ | |
| Edit configuration, settings, schema, and name | ✓ | ✓ | |
| Enable or disable integrations | ✓ | ✓ | |
| Trigger a sync or a full re-sync | ✓ | ✓ | |
| Manage integration issues | ✓ | ✓ | |
| Manage integration notification rules | ✓ | ✓ | |
| Delete integrations | ✓ |
Observability
Applies to monitors. Roles: Observability Viewer, Observability Editor, Observability Admin (or the matching Global role).
| Capability | Viewer | Editor | Admin |
|---|---|---|---|
| View monitors and observability issues | ✓ | ✓ | ✓ |
| Create monitors | ✓ | ✓ | |
| Edit monitor configuration and name | ✓ | ✓ | |
| Enable or disable monitors | ✓ | ✓ | |
| Trigger (run) monitors | ✓ | ✓ | |
| Manage observability issues | ✓ | ✓ | |
| Manage monitor notification rules | ✓ | ||
| Delete monitors | ✓ |
Global Editor also includes managing monitor notification rules and tags, which the area-specific Observability Editor role does not.
Catalog
Applies to the data catalog, assets, and governance. The catalog has two roles: Catalog Editor and Catalog Admin (or the matching Global role). Browsing the catalog itself is available to everyone.
| Capability | Editor | Admin |
|---|---|---|
| View the catalog and lineage | ✓ | ✓ |
| Edit asset descriptions | ✓ | ✓ |
| Manage catalog issues | ✓ | ✓ |
| Manage catalog owners | ✓ | ✓ |
| Manage catalog notification rules | ✓ | ✓ |
| Trigger metadata extraction | ✓ | ✓ |
| Delete assets | ✓ |
Assets
Assets — the tables, views, and other objects that flow through Matia — are shared by Integrations and Catalog, so several roles can act on them.
| Capability | Who can do it |
|---|---|
| View assets | Everyone |
| Create and edit assets | Integrations Editor/Admin, Catalog Editor/Admin, Global Editor/Admin |
| Delete assets | Integrations Admin, Catalog Admin, Global Admin |
Platform-wide capabilities
A few capabilities aren't tied to a single product area.
| Capability | Who can do it |
|---|---|
| View notifications | Everyone |
| Create and update notifications | Global Admin |
| Manage tags | Observability Admin, Global Editor, Global Admin |
| View platform-wide issues | Global Viewer, Global Admin |
| Update platform-wide issues | Global Admin |
| Access account settings | Global Admin |
| Invite, edit, and remove users | Global Admin |
See Managing users for the user-management workflow, and the Roles reference for how these capabilities combine into each role.
Permission-to-role mappings are managed centrally and may evolve as Matia adds capabilities. This page reflects the current standard roles; if your workspace uses custom roles, the exact mapping may differ.