Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Performance Analytics roles

Assign roles to ensure that users can perform all necessary actions.

Roles and personas

Warning: Giving someone the pa_admin or pa_data_collector role is equivalent to giving them admin, from a security perspective.

RoleAuthorizationsTypical persona
No role- View Performance Analytics visuals on the Service Portal. - View dashboards that have been shared with this user. Some dashboards require a subject matter related role for viewing, such as sn\_hr\_core\_basic for the HR Agent dashboard. Dashboard owners and administrators can also restrict dashboard access by role. For more information, see Dashboard permissions.Requester who does not need any access to Performance Analytics beyond certain visualizations of results
Any role \(not necessarily a Performance Analytics role\)- Open the indicator library - Create dashboards. - Restrict access by role to a dashboard they create. - Share dashboards they own. 
pa\_viewerContained by: All roles except pa\_contributorBefore Quebec, this role was necessary for the following actions. It may still be necessary on upgraded instances. - View Analytics Hub. - Create personal thresholds and targets for indicators. - Read, Update, and Delete thresholds and targets that they created. - View text analytics widgets on dashboards.Requester who needs and understands the details of key performance indicators
sn\_pa\_diagnostics.pa\_diagnosticContained by: pa\_admin- Read from the Diagnostics tables. - Activate or deactivate a diagnostic. - Run diagnostics. - Delete message records and diagnostic logs.No specific persona, but this role would typically be assigned to individual business analysts or groups of fulfillers.
pa\_contributorContained by: pa\_power\_user, pa\_admin

For indicators for which the user is designated as a Contributor:- Read and update scores in scoresheets. - View the Analytics Hub.

This user can also read dashboards that have been shared with them.

No specific persona, but this role would typically be assigned to individual fulfillers or groups, who are allowed to set indicator scores manually
pa\_kpi\_signal\_adminContained by: adminEnables the user to dismiss a signal or reset the baseline for KPI Signals.Process owner who also has some training in Performance Analytics. Also needs the pa\_viewer role.
pa\_target\_adminContained by: pa\_power\_user, pa\_admin- Create targets. - Read, update, and delete all targets, including those that they do not own. - Assign targets to indicators.Manager who knows what targets to set but may not have any further input to Performance Analytics
pa\_threshold\_adminContained by: pa\_power\_user, pa\_admin- Create global thresholds. - Read, update, and delete all thresholds, including those that they do not own. - Assign thresholds to indicators.Manager who knows what thresholds to set but may not have any further input to Performance Analytics
pa\_analystContained by: pa\_power\_user, pa\_admin- CRUD text analytics keywords, phrases, and stop words - Read indicator sources.No specific persona, but this role would be assigned to individual fulfillers or groups whose expertise includes keywords, phrases, and stop words for word clouds.
pa\_power\_userContained by: pa\_admin The pa\_power\_user role contains the viz\_admin, pa\_viewer, pa\_contributor, pa\_target\_admin, pa\_analyst, and pa\_threshold\_admin roles.- CRUD indicators and breakdowns. - CRUD widgets - Add Performance Analytics widgets to dashboards. - CRUD text index configurations for text analytics. - CRUD bucket groups. - CRUD indicator groupsBusiness analyst and visualization designer. Understands the use cases for Performance Analytics and the requirements for indicators and breakdowns.
pa\_data\_collectorContained by: pa\_admin- CRUD, schedule, and run data collection jobs - CRUD indicator and breakdown sources - Read some system properties - CRUD system units - CRUD scripts and automated notifications - CRUD bucket groups - Activate or deactivate Data snapshotsTechnical expert who understands the underlying database record structure of Performance Analytics
pa\_adminThe pa\_admin role contains the pa\_power\_user, sn\_pa\_diagnostics.pa\_diagnostic, viz\_admin, and pa\_data\_collector roles.- Read Performance Analytics properties. - Access Admin Console - Launch Dependency AssessmentPerformance Analytics technical expert who also understands business needs.
adminThe system administrator role. Users with the admin role can perform all pa\_admin functions, edit properties, create database views, CRUD any dashboard, and assign ownership to dashboards.System administrator

Spotlight roles

RoleAuthorizationTypical persona
pa\_spotlightContains: pa\_viewer, pa\_spotlight\_copy\_breakdownCRUD Spotlight groups and criteria.Expert who understands the business logic of what records require reminders.
pa\_spotlight\_viewerAccess to the dashboards from the Analytics and Reporting Spotlight Solutions.Fulfiller who needs more than simple Priority setting to remind them of records that require action.
pa\_spotlight\_copy\_breakdownCan copy Spotlight groups to multiple elements of a breakdown.Spotlight expert or business analyst who understands the applicability of a Spotlight group by breakdown element.
pa\_spotlight\_copy\_domainCan copy Spotlight groups to multiple domainsDomain administrator with Performance Analytics expertise

Role hierarchy

Certain roles such as pa_power_user and pa_admin include other roles. For example, pa_power_user includes pa_contributor. This diagram shows the role hierarchy.

Image omitted: pa\_role-hierarchy.png
The pa\_admin role hierarchy.

Required roles for actions

ModuleActionMinimal required role
Admin ConsoleAccesspa\_admin
Analytics Hub \(Scorecards\)ViewNone, since Quebec. However, upgraded instances may still require pa\_viewer.
Automated indicatorsCRUDpa\_power\_user
Automation schedulesRead and delete \(other security restrictions likely apply\)pa\_data\_collector
Automation scriptsCRUDpa\_data\_collector
Breakdowns and elements, including breakdown relationsCRUDpa\_data\_collector or pa\_power\_user
Bucket groupsCRUDpa\_data\_collector or pa\_power\_user
Color schemes for charts and targetsCRUDpa\_power\_user
Dashboards \(Responsive or Platform Analytics\)Create a dashboard. Update a dashboard they created, including restricting access by role.Any roles necessary to access the data to display, or any one role
Data snapshotsActivate or deactivatepa\_data\_collector
Responsive dashboardsAdd Performance Analytics widgets to responsive dashboards you own.pa\_power\_user
Dashboards \(Responsive or Platform Analytics\)Read a dashboard that has been shared with youNo role by default, but dashboards can require roles to view their data. For more information, see Dashboard permissions.
Dashboards \(Responsive or Platform Analytics\)Update, delete, or share a dashboard that you own.pa\_power\_user
Dashboards \(Responsive or Platform Analytics\)Update, delete, or share any dashboard. Reassign ownership of any dashboard.admin \(and dashboard role dashboard\_admin\)
Data collector jobsRead, write, executepa\_data\_collector
Dependency assessmentLaunch dependency assessment from indicator or breakdown formpa\_admin
External indicators and breakdownsCRUDpa\_data\_collector or pa\_power\_user
Formula and manual indicatorsCRUDpa\_power\_user
Indicator GroupsCRUDpa\_power\_user
Sources, either indicator or breakdownCRUDpa\_data\_collector
Indicator targetsRead and edit targets that you do not ownpa\_target\_administrator
Indicator targets or thresholdsCreate new. Read or edit ones you own.None, since Quebec. However, upgraded instances may still require pa\_viewer.
Indicator thresholdsRead and edit thresholds that you do not ownpa\_threshold\_administrator
In-form analyticsCRUDpa\_power\_user
KPI SignalsReset baseline or dismiss signalpa\_kpi\_signal\_admin
Lists in all applicationsAccess an interactive analysisNo role by default, but some interactive analyses require roles to view their tables
Manage diagnosticsRead, execute, deletesn\_pa\_diagnostics.pa\_diagnostic
Scheduled email summary jobsCRUDpa\_power\_user
ScoresheetsCRUDpa\_power\_user
Service PortalView Performance Analytics visualsNo role
System PropertiesEditadmin
System PropertiesReadpa\_data\_collector for some, pa\_admin for all
System UnitsCRUDpa\_data\_collector
Text AnalyticsSet up text index configurationspa\_power\_user
Text AnalyticsView a text widget on a dashboardNone, since Quebec. However, upgraded instances may still require pa\_viewer.
Text analytics keywords, phrases, or stop wordsCRUDpa\_analyst
What's on the Move News Rules and Statistics GeneratorsRead, editpa\_power\_user
Visualizations that contain indicator informationCRUDpa\_power\_user

Parent Topic:Performance Analytics reference

Related topics

Dashboard permissions

Administering reports