Custom roles at the Account level
PlannedWe would like to separate out the responsibilities of the Account Owner role.
Specifically, we have production engineers that we want to have the ability to create/manage destinations, but not to create/manage users or handle billing details. Right now, there's very little granularity to the roles at at account level, and none of Owner, Billing, and Read Only have the specific permission boundaries required for our use case.
Please advise if there's any way to customize these permissions, thanks.
-
Official comment
Hi Michael Li
Thank you for submitting this feature request with Fivetran. I'd love to learn more about your use case. Are there any restrictions on the destinations that the production engineers can see/edit? And can the product engineers manage users within the destination?
We are working on supporting an enhance RBAC model to provide more granular permissioning at the account, destination and connector level. We will definitely reach out as we progress on this project!
Thank you,
Meera -
Hi Meera,
Thanks for taking a look at this. For our use case, we want to leave user management and billing up to just a handful of superadmins (currently "Owner" suffices for this). We are also expanding our usage of Fivetran which means different engineering teams will be creating new destinations pointing to separate data stores. In this case, those data stores are managed by different sets of production engineers per team, and we want to enable these engineers to create their own Fivetran Destination(s), and then manage Fivetran user permissions within the destination. But we do not want them to be able to update any billing details nor manage Fivetran user permissions at the account-level, and so "Owner" has too many permissions, while the other levels does not have enough.
Hope that makes sense, happy to help clarify anything else that might be helpful. Would love to subscribe to any updates on this, thanks!
Michael
-
Hi Michael,
We have released support for custom roles at the account level. For the use case specified below:
1. A new out of the box role called Destination creator enables users to create and manage destinations
2. There is a private preview for teams. This would allow you to onboard teams onto Fivetran and set permissions up across the team. The documentation is available here https://fivetran.com/docs/getting-started/fivetran-dashboard/account-management/role-based-access-control#newrbacmodelbenefits.
Please let us know if you have any questions at all.
Cheers,
Meera
Please sign in to leave a comment.
Comments
3 comments