Roles and permissions
What Organization Admin, Collaborator, and Read-Only user roles can see and do.
Access model
Access in Sovos Intelligence is the product of three independent things:
-
Your license (Professional or Enterprise) decides which capabilities exist.
-
Your role (Organization Admin, Collaborator, or Read-Only user) decides who may use them.
-
Your company scope decides which data you see.
Roles follow one principle. The depth of allowed action differentiates the roles, not the sections they can reach. The three roles form strictly nested tiers. Each can do everything the lighter role can, plus more.
- Read-Only user (Consume)
- Views and downloads governed, saved outputs, such as dashboards and reports, and browses the underlying data. Creates nothing and runs no generative actions.
- Collaborator (Author)
-
Everything Consume can do, plus building:
-
Ask Sovi AI and use Agentic Reporting.
-
Create widgets, dashboards, report templates, and reports.
-
Run reconciliation, change statuses, Manual Match, and write rules.
-
Create, edit, and run queries.
-
Export from Data.
-
Upload external data and trigger manual refresh.
-
- Organization Admin (Administer)
-
Everything Author can do, plus governing the tenant:
-
Manage the organization, companies, users, and role assignments.
-
Own connector configuration.
-
Own the cost envelope (data-volume ceiling, refresh cadence, and consumption monitoring).
-
Sections by role (Enterprise)
| Section | Organization Admin | Collaborator | Read-Only user |
|---|---|---|---|
| Dashboards | Build, manage, view and download | Build, manage, view and download | View and download |
| Insights (Sovi AI) | Full, including Agentic Reporting | Full, including Agentic Reporting | Hidden |
| Reports | Create templates, run, export | Create templates, run, export | View and download |
| Data (All Data) | Browse and export | Browse and export | Browse (view only) |
| Queries | Create, edit, delete, run | Create, edit, delete, run | Hidden |
| Connectors | View, settings, upload | View, upload, manual refresh | Hidden |
| Downloads | Own queue | Own queue | Own queue (permitted outputs) |
| Settings / Administration | Full | Hidden | Hidden |
Governed outputs versus raw data
A Read-Only user can download a report or a dashboard. Both are governed outputs that an Author defined and shaped. A Read-Only user cannot initiate a raw export of a Data model, which is an unshaped bulk extract of the underlying table.
Professional access model
Professional also has three roles: Read-Only user, Collaborator, and Organization Admin. Enterprise and Professional distinguish the roles more narrowly, since Professional licenses only a subset of Author capabilities.
| Capability | Read-Only user | Collaborator | Organization Admin |
|---|---|---|---|
| 4 pre-built dashboards | View and download | View and download | View and download |
| 5 report templates (run + view/download) | View and download outputs only | Run, view, download | Run, view, download |
| Create templates, build widgets, queries, reconciliation, Agentic Reporting | Not available (Enterprise only) | Not available (Enterprise only) | Not available (Enterprise only) |
| All Data | Browse (view) | Browse (view) | Browse (view) |
| Raw Data-model export | Not available | Not available | Not available |
| Sovi AI Q&A (25 prompts per organization per calendar month) | Hidden | Full | Full |
| Connectors - sync status, data freshness, usage | View | View | View |
| Connectors - configuration, upload, manual refresh | Not available (Enterprise) | Not available (Enterprise) | Not available (Enterprise) |
| Downloads (own queue) | Yes | Yes | Yes |
| User & access management | No | No | Yes (after Sovos activation) |
A Read-Only user consumes the pre-built dashboards and report outputs. A Collaborator adds Sovi AI Q&A and running the report templates. An Organization Admin adds user and access management. Sovos performs the initial tenant activation. Afterward, the Organization Admin self-serves adding users, assigning roles, and setting company scope. Company scope (row-level security) works the same way regardless of license type or role.
Data access is further scoped by the company or companies associated with your user account, regardless of role.
