Default permissions and custom roles
Last updated: 10/5/2026Default permissions and custom roles control permissions for users and administrators. Default permissions define a baseline for all users, while custom roles allow more specific permissions for selected users or groups. The table below lists all available settings, with additional details in the sections that follow.
This topic is applicable to Qlik Sense Enterprise SaaS, Qlik Sense Business, and Qlik Cloud Government. If you have a subscription for the Standard, Premium, or Enterprise edition of Qlik Cloud Analytics or Qlik Talend Data Integration, see Managing users - Capacity-based subscriptions.
Understanding default permissions
Default permissions provide a tenant-wide baseline of permissions for all users. Administrators can change these permissions by clicking Manage default permissions to remove certain permissions for everyone and restrict broad access.
Understanding custom roles
Custom roles grant additional permissions to selected users or groups. To grant a permission only to specific users, first grant the permission through a custom role and assign the role to those users. Then, set the permission to Not allowed in Manage default permissions.
Permission hierarchy
Default permissions and custom roles, along with built-in security roles, control user and administrator access at the tenant level. Additionally, space roles control user actions on content within specific spaces. For more information about the different types of roles, see Roles and permissions for users and administrators.
Permission settings
The following sections list the permissions available in the default permissions and custom roles.
For each permission in a custom role, the default setting is shown, for example, (Default) Not allowed. This indicates the permission level that applies when the custom role does not override the default setting.
When a permission is Allowed by default, the Not allowed option is not available for that permission in a custom role. Custom roles can only grant additional permissions. They cannot remove permissions that are allowed by default.
Permission settings — Content types
The Content types section contains permissions to take action on different content types. These are user permissions.
| Subsection | Permission | Options |
|---|---|---|
| Applications | Share applications via fine-grained access control |
Allowed: Space owners and users with the Can manage role can share individual applications with users or groups without adding them to the space. Not allowed: Users can only share the entire space, not individual applications. |
| Applications | Manage engine assignments for applications |
Allowed: Users can assign an engine size to applications, overriding the default automatic engine selection. Not allowed: Users cannot override the automatic engine selection. For more information, see Assigning engines to improve application performance. |
| Applications | In-app content download |
No data: Users can only download images and PDFs. Data downloads are not permitted. Allowed: Users can download all types of application content. Not allowed: Application content downloads are not permitted. |
| Applications | Anonymous access link |
Allowed: Users can configure anonymous access for applications. Not allowed: Users cannot configure anonymous access for applications. For more information about setting anonymous access permissions, see Setting permissions for users who can configure anonymous access. For more information about anonymous access, see Sharing application content with anonymous access. |
| Applications | Insight triggers |
Allowed: Users can create, manage, and view insight triggers. Not allowed: Users cannot create or manage insight triggers. They can view insight triggers. |
| Automations | Shared Automations |
Allowed: Users have access to shared automations. Not allowed: Users do not have access to shared automations. Admins can set the permission to Not allowed in the default permissions, and create custom roles to provide access to specific users or groups. |
| Data content | Data connections |
Allowed: Users can list, create, view, update, and delete data connections. Users can also read data from, and store data to, these connections. Read: Users can view data connections, select and load data from connections, and store data to data connections. Not allowed: Users cannot create, view, update, or delete data connections. Users also cannot read data from, or store data to, these connections. For more information, see Assigning permissions for users to work with data connections. |
| Data products | Manage data products |
Consume only: Users have access to the Data marketplace. Allowed: Users can view, create, update, activate, and delete data products on the Data marketplace. Not allowed: Users cannot access data products on the Data marketplace. |
| Lineage | View lineage |
Allowed: Users can view lineage and impact analysis between assets. Not allowed: Users cannot view lineage and impact analysis between assets. |
| Links | Manage links |
Allowed: Users can view, create, update, and use links in the Analytics activity center. They can delete links that they created. Not allowed: Users cannot view or work with links in the Analytics activity center. For more information, see Who can create links. |
| Notes | Manage notes |
Allowed: Users can create, view, update, delete, and share notes in activity centers and applications. Not allowed: Users cannot create, view, update, delete, or share notes in activity centers and applications. For more information, see Enabling note creation. |
| Pipeline projects | Create, update, or view pipeline projects based on space access |
Read only: Users can view and list pipeline projects based on space access. Allowed: Users can create, update, or view pipeline projects based on space access. Not allowed: Users cannot create, update, or view pipeline projects. |
Permission settings — Features and actions
The Features and actions section contains permissions for tenant-wide access to special features and actions. These are user permissions.
| Subsection | Permission | Options |
|---|---|---|
| Agentic AI | Data analysis |
Allowed: Users can use application analysis and Answers assistants within the Qlik Answers agentic chat from Answers. Not allowed: Users cannot access application analysis or Answers assistants from the Qlik Answers agentic chat. If they have the permissions, they can use the experience with legacy assistants. |
| Agentic AI | Insights feed |
Allowed: Users can view insights in feeds. Not allowed: Users cannot view insights in feeds. |
| Agentic AI | Qlik product help |
Allowed: Users can access the Help agent. Not allowed: Users cannot access the Help agent. |
| Agentic AI | Review agent and chat interactions |
Allowed: Users can access the review portal and Feedback in agentic assistants to view conversations from Qlik Answers agentic experiences. Not allowed: Users cannot access the review portal or view Feedback in agentic assistants. |
| Data quality | AI-based descriptions and suggestions |
Allowed: Users can generate AI-based validation rules for datasets, and descriptions for any resources. Not allowed: Users cannot generate AI-based validation rules, descriptions or suggestions. |
| Data quality | Compute data quality |
Read: Users can view the results of the data quality computation. Allowed: Users can compute data quality and view the results. Not allowed: Users cannot compute data quality. |
| Data quality | Manage validation rules |
Apply only: Users can list and view validation rules (depending on their license), and apply rules on datasets. Allowed: Users can view, create, update, and delete validation rules on a space. Not allowed: Users cannot view validation rules. |
| Data quality | Assign classifications and regulations |
Allowed: Users can assign classifications and regulations on datasets, and view assigned classifications and regulations. Not allowed: Users cannot assign classifications and regulations, and cannot view assigned classifications and regulations. |
| Data quality | Manage semantic types |
Assign only: Users can list and view semantic types (depending on their license), and apply semantic types on datasets. Allowed: Users can view, create, update, and delete semantic types. No space role is needed. Not allowed: Users cannot view semantic types. |
| Data quality | Configure Qlik Trust Score™ |
Allowed: Users can configure the Qlik Trust Score™ dimensions at the tenant level, view the score and its history. Not allowed: Users cannot configure, or view the Qlik Trust Score™. |
| Developer | Manage API keys |
Allowed: Users can create, view, update, and delete their own API keys in their personal settings. Not allowed: Users cannot create or manage API keys. |
| Model Context Protocol (MCP) | MCP |
Allowed: Users can use Qlik MCP server. Not allowed: Users cannot use Qlik MCP server. |
| Insight Advisor | Data analysis |
Allowed: Users can access Insight Advisor in all forms within Qlik Cloud. In other words, users can access Insight Advisor and Insight Advisor Chat from activity centers and applications. Not allowed: Users cannot access Insight Advisor with in Qlik Cloud. In other words, users cannot access Insight Advisor or Insight Advisor Chat from activity centers or applications. |
| Insight Advisor | Insight Advisor in Microsoft Teams |
Allowed: Users can access Insight Advisor Chat from Microsoft Teams. Not allowed: Users cannot access Insight Advisor Chat from Microsoft Teams. |
| Mobile | Native mobile app |
Allowed: Users can access the Qlik Analytics app. Allowed with Intune: Users can access the Qlik Analytics mobile app with enforced MSAL authentication. MSAL cannot be disabled by users. Enables Intune MAM data protection policies. Not allowed: Users cannot access the Qlik Analytics app. For more information, see Setting access to the Qlik Analytics mobile app and Securing and configuring the Qlik Analytics mobile app with Microsoft Intune. |
| Feature preview | Activate feature preview |
Allowed: Users can activate and deactivate preview features. Not allowed: Users can view available preview features but cannot activate or deactivate them. For more information, see Managing feature preview for your tenant. |
| Space management | Request access to content |
Allowed: Users can request access to content through the standard Qlik process. Not allowed: Users cannot request access. You can customize the message shown when they try to access content to guide them to your organization's process. For more information, see Customizing the access request process and Approving access requests. |
| Webhooks | Use webhooks |
Allowed: Users can create, update, delete, and list their own webhooks using the webhooks API and automations UI. Not allowed: Users cannot manage webhooks. For more information, see Working with webhooks. |
| Learn | Access learning |
Allowed: Can access the learning center. Not allowed: Cannot access the learning center. For more information, see Getting started and learning options. |
Permission settings — Admin permissions
The Admin permissions section contains permissions for administrators of the Qlik Cloud tenant.
| Subsection | Permission | Options |
|---|---|---|
| Content Security Policy (CSP) | Admin CSP |
Allowed: Users can create, update, read, list, and delete content security policies. Not allowed: Users cannot manage content security policies. |
| Curate content | Custom home |
Allowed: Can customize the Insights Home page for all users. Not allowed: Can only customize their own home pages. For more information, see Customizing the Insights activity center Home. |
| Curate content | Public collections |
Allowed: Can set any collection in the tenant to public or private. Not allowed: Cannot set any collection in the tenant to public or private. For more information, see Managing public collections. |
| Data products | Administer data products |
Allowed: Users can access and manage all data products without space restrictions. Not allowed: Users cannot manage data products. |
| Data quality | Administer AI-based descriptions and suggestions |
Allowed: Users can manage tenant settings for generating AI-based descriptions for any resources and any validation rule suggestions for datasets. They can access and manage AI generations without space restrictions. Not allowed: Users cannot manage AI generation settings. |
| Data quality | Administer semantic types |
Allowed: Users can access and manage all semantic types. Not allowed: Users cannot manage semantic types. |
| Data quality | Administer validation rules |
Allowed: Users can access and manage all validation rules without space restrictions. Not allowed: Users cannot manage validation rules. |
| Pipeline projects | Read, delete, list, or change owner of all pipeline projects in the tenant for admin. | Allowed: Users can read, delete, list, or change owner of all pipeline projects in the tenant. Not allowed: Users cannot manage pipeline projects. |
'In-application content download' permission: Additional details
The value assigned to a user for the In-app content download permission can impact their access to other Qlik Cloud features. The following sections breaks down the difference between each of the available options.
No data
The following apply for the No data option:
-
Provides full access to Insight Advisor Chat when it is accessed through Qlik Cloud or an external collaboration platform (for example, Microsoft Teams).
Allowed
The following apply for the Allowed option:
-
Provides full access to Insight Advisor Chat when it is accessed through Qlik Cloud or an external collaboration platform (for example, Microsoft Teams).
Not allowed
The following apply for the Not allowed option:
-
The user will not see static charts in Insight Advisor Chat. The user will also not be able to see any visualizations when using Insight Advisor Chat through a collaboration platform (for example, Microsoft Teams). All other Insight Advisor Chat capabilities, such as natural language insights, will be available.