Permissions Required for Various RudderStack Features
10 minute read
This guide provides a comprehensive reference of the permissions required to use different RudderStack features in the new Access Management system.
It also lists the permissions required to use the same features in the legacy Permissions Management (RBAC) system for comparison.
APIs
To consume APIs, you require a Service Access Token with specific permissions.
Audit Logs API
- Access Management system: Organization-level Service Access Token
- Legacy RBAC system: Organization-level Service Access Token
See Audit Logs API for more details.
Data Catalog API
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| Tracking Plans | Create & Delete, Edit |
| Data Catalog | Edit |
- Legacy RBAC system: Workspace-level Service Access Token with Admin permissions
See Data Catalog API for more details.
Event Audit API
- Access Management system: Workspace-level Service Access Token with no dedicated permissions
- Legacy RBAC system: Workspace-level Service Access Token with Viewer permissions
See Event Audit API for more details.
HTTP API
No dedicated permissions are required to consume the HTTP API — it uses your source write key for authentication.
Pixel API
No dedicated permissions are required to consume the Pixel API — it uses your source write key for authentication.
Profiles API
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| Profiles | Edit |
- Legacy RBAC system: Workspace-level Service Access Token with Editor permissions
See Profiles API for more details.
Reverse ETL Connections API
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| Tables / SQL Models / Audiences | Edit, Connect |
| Destinations | Edit, Connect |
| PII permissions Enterprise plan only | Reverse ETL Sync Failure Samples configured for the required source |
- Legacy RBAC system: Workspace-level Service Access Token with Admin permissions
See Reverse ETL Connections API for more details.
Test API
- Access Management system: Workspace-level Service Access Token with no dedicated permissions
- Legacy RBAC system: Workspace-level Service Access Token with Viewer permissions
See Test API for more details.
Transformations API
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| Transformations | Create & Delete, Connect, Edit |
| Transformation Libraries | Edit |
| Destinations | Connect |
- Legacy RBAC system: Workspace-level Service Access Token with Admin permissions with Grant edit access toggled on under Transformations.

See Transformations API for more details.
User Suppression API
- Access Management system: Workspace-level Service Access Token with no dedicated permissions
- Legacy RBAC system: Workspace-level Service Access Token with Viewer permissions
See User Suppression API for more details.
AI Features
To use these features, you require a Service Access Token with specific permissions.
Rudder AI Reviewer
- Access Management system: Workspace-level Service Access Token with no dedicated permissions
- Legacy RBAC system: Workspace-level Service Access Token with Viewer permissions
See Rudder AI Reviewer for more details.
CLI and Dev Tools
To use these tools, you require a Service Access Token with specific permissions.
RudderTyper
- Access Management system: Workspace-level Service Access Token with no dedicated permissions
- Legacy RBAC system: Workspace-level Service Access Token with Viewer permissions
See RudderTyper for more details.
Rudder CLI
To use Rudder CLI, you require a Service Access Token with specific permissions to manage the resources you want to manage.
Tracking Plans and Data Catalog
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| Tracking Plans | Create & Delete, Edit |
| Data Catalog | Edit |
- Legacy RBAC system: Workspace-level Service Access Token with Admin permissions
See CLI-based Tracking Plans and Data Catalog Management for more details.
Event Stream Sources
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions | Description |
|---|---|---|
| Event Stream Sources | Create & Delete | Create or delete Event Stream sources in the workspace |
| Event Stream Sources | Edit | Make changes to the configuration of Event Stream sources |
| Event Stream Sources | Connect | Connect an Event Stream source to a Tracking Plan |
| Tracking Plans | Edit, Connect | Connect a Tracking Plan to an Event Stream source |
- Legacy RBAC system: Workspace-level Service Access Token with Admin permissions
See Manage Event Stream Sources using Rudder CLI for more details.
SQL Models
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| SQL Models | Create & Delete, Edit |
- Legacy RBAC system: Workspace-level Service Access Token with Admin permissions
See Manage SQL Models using Rudder CLI for more details.
Transformations and Transformation Libraries
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| Transformations | Create & Delete, Edit, Connect |
| Transformation Libraries | Edit |
- Legacy RBAC system: Workspace-level Service Access Token with Admin role and Grant edit access toggled on under Transformations
See Manage Transformations and Transformation Libraries using Rudder CLI for more details.
Data Governance
This section lists the permissions required to use different Data Governance features in the new Access Management system.
Tracking Plans
Access Management system:
- Admins have full access to create and manage tracking plans
- Members must have the following permissions:
| Resource | Permissions |
|---|---|
| Tracking Plans | Create & Delete, Edit, Connect |
| Data Catalog | Edit |
Legacy RBAC system:
- Org Admins have full access to create and manage Tracking Plans
- Members with the Connections Admin role in their workspace policy can create and manage Tracking Plans
- Members with the Connections Editor role in their workspace policy can only connect Tracking Plans to Event Stream sources
See the Tracking Plans documentation for more details.
Data Catalog
Access Management system:
- Admins have full access to manage Data Catalog
- Members must have the following permissions:
| Resource | Permissions |
|---|---|
| Data Catalog | Edit |
Legacy RBAC system:
- Org Admins have full access to manage Data Catalog
- Members must have the Connections Admin role in their workspace policy
See the Data Catalog documentation for more details.
Bot Management
Access Management system:
- Admins have full access to the Bot Management feature
- Members must have the Bot Management permission
Legacy RBAC system:
- Org Admins have full access to the Bot Management feature
- Members must have the Connections Admin role in their workspace policy
See the Bot Management documentation for more details.
Event Blocking
- Access Management system: Only Admins can manage event blocking
- Legacy RBAC system: Only Org Admins can manage event blocking
See Event Blocking for more details.
Alerts
Access Management system:
Legacy RBAC system:
- Only Org Admins can set up workspace-level alerts
- Org Admins and members with the Connections Admin role in their workspace policy can set up resource-level alerts
See Configurable Alerts for more details.
Data Pipelines
This section lists the permissions required to manage data pipelines and their associated resources.
Event Stream Sources
Access Management system:
- Admins have full access to create and manage event stream sources
- Members can have the following permissions in their workspace policy:
| Resource | Permissions |
|---|---|
| Event Stream Sources | Edit, Connect, Create & Delete |
Legacy RBAC system:
- Org Admins have full access to create and manage Event Stream sources
- Members with the Connections Admin role in their workspace policy can create and manage Event Stream sources
- Members with the Connections Editor role in their workspace policy can only edit the Event Stream source configuration and connect Event Stream sources to destinations
See Event Stream Sources for more details.
Reverse ETL Sources
Access Management system:
- Admins have full access to create and manage reverse ETL sources
- Members can have the following permissions in their workspace policy:
| Resource | Permissions |
|---|---|
| Tables / SQL Models / Audiences | Edit, Connect, Create & Delete |
Legacy RBAC system:
- Org Admins have full access to create and manage reverse ETL sources
- Members with the Connections Admin role in their workspace policy can create and manage reverse ETL sources
- Members with the Connections Editor role in their workspace policy can only edit the reverse ETL source configuration and connect reverse ETL sources to destinations
See Reverse ETL Sources for more details.
Destinations
Access Management system:
- Admins have full access to create and manage destinations
- Members can have the following permissions in their workspace policy:
| Resource | Permissions |
|---|---|
| Destinations | Edit, Connect, Create & Delete |
Legacy RBAC system:
- Org Admins have full access to create and manage destinations
- Members with the Connections Admin role in their workspace policy can create and manage destinations
- Members with the Connections Editor role in their workspace policy can only edit the destination configuration and connect destinations to sources
See Destinations for more details.
Airflow Orchestrator
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| Tables / SQL Models / Audiences | Edit, Connect |
| Destinations | Edit, Connect |
| Profiles | Edit, Connect |
- Legacy RBAC system: Workspace-level Service Access Token with Admin permissions
See RudderStack Airflow Integration for more details.
Dagster Orchestrator
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| Tables / SQL Models / Audiences | Edit, Connect |
| Destinations | Edit, Connect |
| Profiles | Edit, Connect |
- Legacy RBAC system: Workspace-level Service Access Token with Admin permissions
See RudderStack Dagster Integration for more details.
Profiles
Access Management system:
- Admins have full access to create and manage Profiles projects
- Members can have the following permissions in their workspace policy:
| Resource | Permissions |
|---|---|
| Profiles | Edit, Create & Delete, Connect |
Legacy RBAC system:
- Org Admins have full access to create and manage Profiles projects
- Members with the Connections Admin role in their workspace policy can create and manage Profiles projects
- Members with the Connections Editor role in their workspace policy can only edit the Profiles project configuration and connect Profiles projects to destinations
See Profiles Quickstart for more details.
Activation API
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| PII Permission | Destination Data Access for the specific Redis destination |
- Legacy RBAC system: Workspace-level Service Access Token with Admin permissions
See Activation API for more details.
Profiles Audit
- Access Management system: Workspace-level Service Access Token with no dedicated permissions
- Legacy RBAC system: Workspace-level Service Access Token with Viewer permissions
See the Profiles Audit documentation for more details.
SSO and Audit Logs
This section lists the permissions required to use the Audit Logs and different SSO setups.
Audit Logs
- Access Management system: Only Admins can access the Audit Logs
- Legacy RBAC system: Only Org Admins can access the Audit Logs
See Audit Logs for more details.
Okta SSO (SCIM)
- Access Management system: Organization-level Service Access Token
- Legacy RBAC system: Organization-level Service Access Token
See Okta SCIM Configuration for more details.
Azure Entra ID SSO (SCIM)
- Access Management system: Organization-level Service Access Token
- Legacy RBAC system: Organization-level Service Access Token
See Azure Entra ID SSO Setup for more details.
Transformations
Access Management system:
- Admins have full access to create and manage transformations
- Members can have the following permissions in their workspace policy:
| Resource | Permissions |
|---|---|
| Transformations | Edit, Connect, Create & Delete |
Legacy RBAC system:
- Org Admins have full access
- Members must have the Grant edit access permission in Transformations and Library toggled on to create, edit, and delete transformations
- Members with the Connections Admin or Connections Editor role in their workspace policy can only connect transformations to destinations
See Transformations for more details.
Libraries
Access Management system:
- Admins have full access to create and manage transformation libraries
- Members must have the Transformation Libraries permission in their workspace policy
Legacy RBAC system:
- Org Admins have full access
- Members must have the Grant edit access permission in Transformations and Library toggled on to create, edit, and delete transformation libraries
See Transformation Libraries for more details.
Credential Store
Access Management system:
- Admins have full access to the credential store
- Members must have the Credential Store permission in their workspace policy
Legacy RBAC system:
- Org Admins have full access to the credential store
- Members must have the Connections Admin role in their workspace policy
See Credential Store for more details.
Transformation Action
- Access Management system: Workspace-level Service Access Token with the following permissions:
| Resource | Permissions |
|---|---|
| Transformations | Edit, Connect, Create & Delete |
| Transformation Libraries | Edit |
- Legacy RBAC system: Workspace-level Service Access Token with Admin role and Grant edit access toggled on under Transformations
See Transformation Action for more details.