Skip to main content Skip to complementary content

Managing user entitlements

Tenant administrators manage user access rights by assigning roles. Based on these access rights, the user is automatically assigned a user entitlement. Tenant administrators can manually change user entitlements from the Management Console.

Information noteThis topic is applicable to the Standard, Premium, and Enterprise editions of Qlik Cloud Analytics and Qlik Cloud Data Integration. If you have a Qlik Sense Enterprise SaaS, Qlik Sense Business, or Qlik Cloud Government subscription, see Managing users - User-based subscriptions.

What are user entitlements

There are two types of user entitlements: Full User and Basic User.

Full User entitlement

The Full User entitlement is applicable to all use cases in Qlik Cloud. Users with Full User entitlement can take on any space roles and user roles, as well as administrative roles in the tenant. They can perform a wide range of actions, depending on their assigned roles, including:

  • Creating shared spaces

  • Creating, editing, and publishing sheets and apps

  • Working with Data Integration

Basic User entitlement

Basic User entitlements are intended for limited read-only access. This user type is free of charge and available with Analytics Premium and Qlik Cloud Enterprise subscriptions.

As a Basic User, you can only have the role Has restricted view in managed spaces. This role allows you to perform the following actions:

For a comprehensive list of permissions granted by the Has restricted view role, see Managed space permissions for users with Professional or Full User entitlement.

Depending on the User Default settings, Basic Users may also be permitted to download app content. For more details, see Permissions in User Default and custom roles.

Granting any additional permissions to Basic Users will automatically upgrade their entitlement to Full User.

Monitoring consumption of user entitlements

The number of user entitlements is based on your Qlik Cloud subscription. Administrators can monitor the number of available and consumed user entitlements in the Management Console Home. For more information, see Monitoring resource consumption. The service account owner of the Qlik Cloud subscription can view subscription details in My Qlik portal.

Automatic assignment of user entitlements

Tenant administrators manage user access rights by assigning roles. Based on these access rights, the user is automatically assigned the correct user entitlement.

When a user logs in to Qlik Cloud, the access rights of a Basic User are validated according to the following criteria:

  • If the user only has the Has restricted view role in managed spaces, the user is assigned the Basic User entitlement.

  • If the user has permissions above what is included in the Has restricted view role, the user is assigned Full User entitlement.

Note that if you give a Basic User any additional permissions, such as access to an app in a shared space or more than just view permission, they will automatically be promoted to a Full User. You can override this assignment if needed and change the user entitlement manually. However, demoting a Full User to Basic User does not automatically change the user’s access control. If you want to find out why a user was promoted to Full User, you can check the user's access rights in the Entitlement column under Users > All users. Remove these permissions to prevent the user from being promoted to Full User again at the next login.

Manually changing user entitlement

Information noteAs per the Qlik® Customer Agreement, you are not allowed to reallocate user entitlements or let multiple users share entitlements to exceed your purchased quantity.

Tenant admins can manually manage user entitlements from the Management Console.

Note that removing an entitlement does not affect roles or permissions. To prevent an active user from being reassigned a Full User entitlement at login, you can remove any access rights that would promote the user to Full User or disable the user.

Removing a user's entitlement does not affect any resources owned by the user.

Do the following:

  1. In the Management Console, go to Users > All users.
  2. Select one or more users from the list.

  3. Click Change entitlements.
  4. Select or clear the entitlement checkbox, and then click Save.

Checking access rights

Tenant admins can investigate which access rights that caused a specific user to be assigned Full User entitlement.

Do the following:

  1. In the Management Console, go to Users > All users.

  2. In the Entitlement column, hover over Information.

    A tooltip shows information about the roles that promoted the user to Full User.

Tooltip with access rights

Tooltip for Entitlement column

Managing users in status Requested

The number of user entitlements is based on your Qlik Cloud subscription. Administrators can monitor the number of available and consumed users entitlements in the Management Console Home. If you add Full Users to the tenant when there are no more Full User entitlements available, the users get status Requested. In this status, they can't access to the hub or open apps. The users requesting an entitlement are listed in the Management Console under Users > All users.

Users remain in status Requested until you either add more user entitlements or remove access for other users, which frees up entitlements. Users requesting an entitlement are automatically assigned Full User entitlements when more are made available. Contact Qlik Sales to purchase additional Full User entitlements.

Full Users are added to a tenant by invitation. You can also promote Basic Users to Full Users by assigning them space roles or security roles. If the limit for user entitlements is reached, you will see a warning when you add members to a space, as this could cause users to be put into status Requested. If you want to find out why a user was promoted to Full User, you can check the user's access rights in the Entitlement column under Users > All users.

To free up entitlements by removing access from other users, you can remove the Full User entitlement, disable the user, or delete the user.

Do the following:

  1. In the Management Console, go to the Users > All users.
  2. Select one or more users from the list.

  3. To remove the user entitlement, click Change entitlements, clear the Full User checkbox, and then click Save.
  4. To disable or delete a user, click More, select Disable or Delete, and then confirm the action.

Did this page help you?

If you find any issues with this page or its content – a typo, a missing step, or a technical error – let us know how we can improve!