Skip to main content

Intro

There are five system roles in Domo:
  • Admin
  • Privileged*
  • Editor
  • Participant
  • Social
*Privileged is the default role for new users in Domo unless an admin changes the default role. Each system role includes various grants, or specific permissions, to parts of the Domo platform and to perform various tasks. When a person is assigned a system role, they are given the grants included with that role. While you can’t edit a system role, you can duplicate a system role, make changes to it, and save it as a new custom role. To learn more about creating other custom roles and assigning grants, see Manage Roles. This article describes the differences between each of the five system roles. Social gives the most basic access—each subsequent role includes all the same grants as the role below it plus additional grants. The Admin role gives access to nearly all available grants. Learn more about Admin below.

Social

Social is the most basic system role. It only allows access to Buzz, user profiles, and Projects and Tasks. Social users can subscribe to existing alerts and create OAuth clients for access tokens to authenticate to the Domo platform API. In the web version of Domo, social users cannot open dashboards to view included cards.

Compare Participant, Editor, and Privileged Roles

The Participant, Editor, and Privileged roles include all Social role access. This table describes which additional access each role includes.
Note: Privileged is the default role for new Domo users unless changed by an admin.

Feature

Access

Participant

Editor

Privileged

Alerts

Create, edit, and share alerts to which they have access.

View, edit, add, or delete Alert Actions on any Alert they own.

Appstore

View the Domo Appstore and app info.

Install and use apps from the Domo Appstore.

Uninstall apps that they previously installed.

Cards and Dashboards

Create Scheduled Reports and export Domo content* to email, print, PowerPoint, CSV file, and Excel.

* The Participant role only allows read-only access to Domo cards and dashboards. There is no access to the DataSets that power them.

Use Domo Everywhere to embed cards and dashboards externally, with or without authentication.

Create, edit, and delete cards, Drill Paths, and Beast Mode calculations to which they have access.

Create and edit DataSet Views in Analyzer.

Create, edit, and delete dashboards, styles, templates, and layouts.

Create and edit natural language-generated narratives in Notebook Cards.

Data

Create data in AppDB .

Create, edit, and delete DataSets to which they have access.

Export data from DataSets to which they have access.

Create accounts for DataSets in the instance.

Allow Workbench download.

Create, edit, and delete DataFlows to which they have access. Note: Requires the Edit DataSet grant.

Train AutoML models. Run DataFlows containing AutoML Inference actions.

Create, edit, and run Magic ETL DataFlows to which they have access.

Create, edit, and delete Jupyter Workspaces to which they have access. Note: Requires the Edit DataSet grant.

DomoApps

View custom DomoApps to which they have access.

Create, edit, and upload custom DomoApps.

Forms

Create new forms .

Goals

Create and edit any goals to which they have access.

Pipeline Executor Service Create, edit, or remove custom pipeline processes.

Queues

Create new task queues .

Users and Groups

Add new people to the instance.

Create, edit, and delete groups to which they have access, including adding and removing members.

Create, edit, and delete achievements.

Workflows

Submit a certification request for content to which they have access.

Create workflow models.

Admin

The Admin system role includes nearly all available grants with a few exceptions. To see a full list of available grants, including those included with the Admin and other roles, go to Admin > Roles (in the Governance section). Select a default role in the Roles tab to see its included grants.
Go to the Grants tab to see all available grants.
Important: Grants marked with a warning icon ( ) are high-security grants that provide access to instance-wide controls.