Data and Analytics

Roles and permissions

What Organization Admin, Collaborator, and Read-Only user roles can see and do.

Access model

Access in Sovos Intelligence is the product of three independent things:

  • Your license (Professional or Enterprise) decides which capabilities exist.

  • Your role (Organization Admin, Collaborator, or Read-Only user) decides who may use them.

  • Your company scope decides which data you see.

Roles follow one principle. The depth of allowed action differentiates the roles, not the sections they can reach. The three roles form strictly nested tiers. Each can do everything the lighter role can, plus more.

Read-Only user (Consume)
Views and downloads governed, saved outputs, such as dashboards and reports, and browses the underlying data. Creates nothing and runs no generative actions.
Collaborator (Author)
Everything Consume can do, plus building:
  • Ask Sovi AI and use Agentic Reporting.

  • Create widgets, dashboards, report templates, and reports.

  • Run reconciliation, change statuses, Manual Match, and write rules.

  • Create, edit, and run queries.

  • Export from Data.

  • Upload external data and trigger manual refresh.

Organization Admin (Administer)
Everything Author can do, plus governing the tenant:
  • Manage the organization, companies, users, and role assignments.

  • Own connector configuration.

  • Own the cost envelope (data-volume ceiling, refresh cadence, and consumption monitoring).

Sections by role (Enterprise)

Section Organization Admin Collaborator Read-Only user
Dashboards Build, manage, view and download Build, manage, view and download View and download
Insights (Sovi AI) Full, including Agentic Reporting Full, including Agentic Reporting Hidden
Reports Create templates, run, export Create templates, run, export View and download
Data (All Data) Browse and export Browse and export Browse (view only)
Queries Create, edit, delete, run Create, edit, delete, run Hidden
Connectors View, settings, upload View, upload, manual refresh Hidden
Downloads Own queue Own queue Own queue (permitted outputs)
Settings / Administration Full Hidden Hidden

Governed outputs versus raw data

A Read-Only user can download a report or a dashboard. Both are governed outputs that an Author defined and shaped. A Read-Only user cannot initiate a raw export of a Data model, which is an unshaped bulk extract of the underlying table.

Professional access model

Professional also has three roles: Read-Only user, Collaborator, and Organization Admin. Enterprise and Professional distinguish the roles more narrowly, since Professional licenses only a subset of Author capabilities.

Capability Read-Only user Collaborator Organization Admin
4 pre-built dashboards View and download View and download View and download
5 report templates (run + view/download) View and download outputs only Run, view, download Run, view, download
Create templates, build widgets, queries, reconciliation, Agentic Reporting Not available (Enterprise only) Not available (Enterprise only) Not available (Enterprise only)
All Data Browse (view) Browse (view) Browse (view)
Raw Data-model export Not available Not available Not available
Sovi AI Q&A (25 prompts per organization per calendar month) Hidden Full Full
Connectors - sync status, data freshness, usage View View View
Connectors - configuration, upload, manual refresh Not available (Enterprise) Not available (Enterprise) Not available (Enterprise)
Downloads (own queue) Yes Yes Yes
User & access management No No Yes (after Sovos activation)

A Read-Only user consumes the pre-built dashboards and report outputs. A Collaborator adds Sovi AI Q&A and running the report templates. An Organization Admin adds user and access management. Sovos performs the initial tenant activation. Afterward, the Organization Admin self-serves adding users, assigning roles, and setting company scope. Company scope (row-level security) works the same way regardless of license type or role.

Note:

Data access is further scoped by the company or companies associated with your user account, regardless of role.