Performance Analytics roles
Assign roles to ensure that users can perform all necessary actions.
Roles and personas
Warning: Giving someone the pa_admin or pa_data_collector role is equivalent to giving them admin, from a security perspective.
| Role | Authorizations | Typical persona |
|---|---|---|
| No role | - View Performance Analytics visuals on the Service Portal. - View dashboards that have been shared with this user. Some dashboards require a subject matter related role for viewing, such as sn\_hr\_core\_basic for the HR Agent dashboard. Dashboard owners and administrators can also restrict dashboard access by role. For more information, see Dashboard permissions. | Requester who does not need any access to Performance Analytics beyond certain visualizations of results |
| Any role \(not necessarily a Performance Analytics role\) | - Open the indicator library - Create dashboards. - Restrict access by role to a dashboard they create. - Share dashboards they own. | |
| pa\_viewerContained by: All roles except pa\_contributor | Before Quebec, this role was necessary for the following actions. It may still be necessary on upgraded instances. - View Analytics Hub. - Create personal thresholds and targets for indicators. - Read, Update, and Delete thresholds and targets that they created. - View text analytics widgets on dashboards. | Requester who needs and understands the details of key performance indicators |
| sn\_pa\_diagnostics.pa\_diagnosticContained by: pa\_admin | - Read from the Diagnostics tables. - Activate or deactivate a diagnostic. - Run diagnostics. - Delete message records and diagnostic logs. | No specific persona, but this role would typically be assigned to individual business analysts or groups of fulfillers. |
| pa\_contributorContained by: pa\_power\_user, pa\_admin | For indicators for which the user is designated as a Contributor:- Read and update scores in scoresheets. - View the Analytics Hub. This user can also read dashboards that have been shared with them. | No specific persona, but this role would typically be assigned to individual fulfillers or groups, who are allowed to set indicator scores manually |
| pa\_kpi\_signal\_adminContained by: admin | Enables the user to dismiss a signal or reset the baseline for KPI Signals. | Process owner who also has some training in Performance Analytics. Also needs the pa\_viewer role. |
| pa\_target\_adminContained by: pa\_power\_user, pa\_admin | - Create targets. - Read, update, and delete all targets, including those that they do not own. - Assign targets to indicators. | Manager who knows what targets to set but may not have any further input to Performance Analytics |
| pa\_threshold\_adminContained by: pa\_power\_user, pa\_admin | - Create global thresholds. - Read, update, and delete all thresholds, including those that they do not own. - Assign thresholds to indicators. | Manager who knows what thresholds to set but may not have any further input to Performance Analytics |
| pa\_analystContained by: pa\_power\_user, pa\_admin | - CRUD text analytics keywords, phrases, and stop words - Read indicator sources. | No specific persona, but this role would be assigned to individual fulfillers or groups whose expertise includes keywords, phrases, and stop words for word clouds. |
| pa\_power\_userContained by: pa\_admin The pa\_power\_user role contains the viz\_admin, pa\_viewer, pa\_contributor, pa\_target\_admin, pa\_analyst, and pa\_threshold\_admin roles. | - CRUD indicators and breakdowns. - CRUD widgets - Add Performance Analytics widgets to dashboards. - CRUD text index configurations for text analytics. - CRUD bucket groups. - CRUD indicator groups | Business analyst and visualization designer. Understands the use cases for Performance Analytics and the requirements for indicators and breakdowns. |
| pa\_data\_collectorContained by: pa\_admin | - CRUD, schedule, and run data collection jobs - CRUD indicator and breakdown sources - Read some system properties - CRUD system units - CRUD scripts and automated notifications - CRUD bucket groups - Activate or deactivate Data snapshots | Technical expert who understands the underlying database record structure of Performance Analytics |
| pa\_adminThe pa\_admin role contains the pa\_power\_user, sn\_pa\_diagnostics.pa\_diagnostic, viz\_admin, and pa\_data\_collector roles. | - Read Performance Analytics properties. - Access Admin Console - Launch Dependency Assessment | Performance Analytics technical expert who also understands business needs. |
| admin | The system administrator role. Users with the admin role can perform all pa\_admin functions, edit properties, create database views, CRUD any dashboard, and assign ownership to dashboards. | System administrator |
Spotlight roles
| Role | Authorization | Typical persona |
|---|---|---|
| pa\_spotlightContains: pa\_viewer, pa\_spotlight\_copy\_breakdown | CRUD Spotlight groups and criteria. | Expert who understands the business logic of what records require reminders. |
| pa\_spotlight\_viewer | Access to the dashboards from the Analytics and Reporting Spotlight Solutions. | Fulfiller who needs more than simple Priority setting to remind them of records that require action. |
| pa\_spotlight\_copy\_breakdown | Can copy Spotlight groups to multiple elements of a breakdown. | Spotlight expert or business analyst who understands the applicability of a Spotlight group by breakdown element. |
| pa\_spotlight\_copy\_domain | Can copy Spotlight groups to multiple domains | Domain administrator with Performance Analytics expertise |
Role hierarchy
Certain roles such as pa_power_user and pa_admin include other roles. For example, pa_power_user includes pa_contributor. This diagram shows the role hierarchy.
Image omitted: pa\_role-hierarchy.png
The pa\_admin role hierarchy.
The pa\_admin role hierarchy.
Required roles for actions
| Module | Action | Minimal required role |
|---|---|---|
| Admin Console | Access | pa\_admin |
| Analytics Hub \(Scorecards\) | View | None, since Quebec. However, upgraded instances may still require pa\_viewer. |
| Automated indicators | CRUD | pa\_power\_user |
| Automation schedules | Read and delete \(other security restrictions likely apply\) | pa\_data\_collector |
| Automation scripts | CRUD | pa\_data\_collector |
| Breakdowns and elements, including breakdown relations | CRUD | pa\_data\_collector or pa\_power\_user |
| Bucket groups | CRUD | pa\_data\_collector or pa\_power\_user |
| Color schemes for charts and targets | CRUD | pa\_power\_user |
| Dashboards \(Responsive or Platform Analytics\) | Create a dashboard. Update a dashboard they created, including restricting access by role. | Any roles necessary to access the data to display, or any one role |
| Data snapshots | Activate or deactivate | pa\_data\_collector |
| Responsive dashboards | Add Performance Analytics widgets to responsive dashboards you own. | pa\_power\_user |
| Dashboards \(Responsive or Platform Analytics\) | Read a dashboard that has been shared with you | No role by default, but dashboards can require roles to view their data. For more information, see Dashboard permissions. |
| Dashboards \(Responsive or Platform Analytics\) | Update, delete, or share a dashboard that you own. | pa\_power\_user |
| Dashboards \(Responsive or Platform Analytics\) | Update, delete, or share any dashboard. Reassign ownership of any dashboard. | admin \(and dashboard role dashboard\_admin\) |
| Data collector jobs | Read, write, execute | pa\_data\_collector |
| Dependency assessment | Launch dependency assessment from indicator or breakdown form | pa\_admin |
| External indicators and breakdowns | CRUD | pa\_data\_collector or pa\_power\_user |
| Formula and manual indicators | CRUD | pa\_power\_user |
| Indicator Groups | CRUD | pa\_power\_user |
| Sources, either indicator or breakdown | CRUD | pa\_data\_collector |
| Indicator targets | Read and edit targets that you do not own | pa\_target\_administrator |
| Indicator targets or thresholds | Create new. Read or edit ones you own. | None, since Quebec. However, upgraded instances may still require pa\_viewer. |
| Indicator thresholds | Read and edit thresholds that you do not own | pa\_threshold\_administrator |
| In-form analytics | CRUD | pa\_power\_user |
| KPI Signals | Reset baseline or dismiss signal | pa\_kpi\_signal\_admin |
| Lists in all applications | Access an interactive analysis | No role by default, but some interactive analyses require roles to view their tables |
| Manage diagnostics | Read, execute, delete | sn\_pa\_diagnostics.pa\_diagnostic |
| Scheduled email summary jobs | CRUD | pa\_power\_user |
| Scoresheets | CRUD | pa\_power\_user |
| Service Portal | View Performance Analytics visuals | No role |
| System Properties | Edit | admin |
| System Properties | Read | pa\_data\_collector for some, pa\_admin for all |
| System Units | CRUD | pa\_data\_collector |
| Text Analytics | Set up text index configurations | pa\_power\_user |
| Text Analytics | View a text widget on a dashboard | None, since Quebec. However, upgraded instances may still require pa\_viewer. |
| Text analytics keywords, phrases, or stop words | CRUD | pa\_analyst |
| What's on the Move News Rules and Statistics Generators | Read, edit | pa\_power\_user |
| Visualizations that contain indicator information | CRUD | pa\_power\_user |
Parent Topic:Performance Analytics reference
Related topics