Pipeline Permission Resources
On the Permissions tab of the Role form, the pipeline permissions are grouped under the PIPELINE header. Three resources appear there, and you set each one independently to one of four levels:- Pipelines
- Processor Groups
- Shared Ingestion Source (see Shared Sources)
What Each Permission Level Unlocks
Each of the three resources can be set to one of four levels. The table below describes what each level grants for the resource it is set on.
Publishing or deploying a pipeline or processor group requires the Manage level. A role set to Write can build and save, but a user needs Manage before they can push that work live.
When a user does not hold the level an action requires, the control for that action is disabled. If you do not have access to Settings > Organization > Roles, ask your organization admin to set the level your action requires.
Default Role Permissions
The built-in system roles carry the following pipeline permissions:
System roles are view-only, but you can clone one to use it as the starting point for a custom role. A custom role sets each of the three resources independently. See Role-Based Access Control for how to create a role.
Set Pipeline Permissions for a Role
- Go to Settings > Organization > Roles, open a role, and go to the Permissions tab. To create or clone a role, see Role-Based Access Control.
- Under the PIPELINE header, select the level (None, Read, Write, or Manage) for each of the three resources.
- Click Save.

