> For the complete documentation index, see [llms.txt](https://docs.tonic.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tonic.ai/app/admin/tonic-user-access/permissions/workspace-permissions/workspace-permission-built-in.md).

# Built-in workspace permission sets and available permissions

## Built-in workspace permission sets <a href="#permission-sets-builtin-workspace" id="permission-sets-builtin-workspace"></a>

Structural comes with the following built-in workspace permission sets.

### Manager

Provides complete access to all workspace permissions.

The Manager permission set automatically receives all new workspace permissions.

By default, the Manager workspace permission set is [assigned to workspace owners](/app/admin/tonic-user-access/permissions/workspace-permissions/workspace-owner-permission-set.md).

### Editor

An editor can view and update nearly every aspect of a workspace.

The Editor permission set automatically receives appropriate new workspace permissions.

They cannot rename or delete the workspace, change the connection information, or copy the workspace.

### Auditor

Requires an Enterprise license.

An auditor can view the workspace configuration, but cannot make any changes at all to it.

### Viewer

Requires an Enterprise license.

Similar to an auditor, a viewer can view but not edit the workspace configuration.

However, they are further restricted in that they cannot:

* View any of the data
* View the **Version History**
* Download the Privacy Report
* Download job logs

## Available workspace permissions

The following tables list the available workspace permissions, and indicate how the permissions apply to the built-in workspace permission sets.

### Workspace management and configuration permissions

<table><thead><tr><th valign="top">Permission</th><th width="134" valign="top">Manager</th><th width="90" valign="top">Editor</th><th width="106" valign="top">Auditor</th><th valign="top">Viewer</th></tr></thead><tbody><tr><td valign="top">Configure workspace settings</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top"><p>View workspace settings<br></p><p>(Automatically granted with Configure workspace settings)</p></td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top">✔️</td></tr><tr><td valign="top">Copy workspace</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Export and import workspace</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Delete workspace</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Manage file connector file groups</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Create child workspaces</td><td valign="top">✔️</td><td valign="top"></td><td valign="top"><br></td><td valign="top"><br></td></tr></tbody></table>

### Workspace access permissions

<table><thead><tr><th valign="top">Permission</th><th width="141" valign="top">Manager</th><th width="94" valign="top">Editor</th><th width="100" valign="top">Auditor</th><th valign="top">Viewer</th></tr></thead><tbody><tr><td valign="top">Share workspace access</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Transfer workspace ownership</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td><td valign="top"><br></td></tr></tbody></table>

### Table and column configuration permissions

<table><thead><tr><th valign="top">Permission</th><th width="135" valign="top">Manager</th><th width="99" valign="top">Editor</th><th width="92" valign="top">Auditor</th><th valign="top">Viewer</th></tr></thead><tbody><tr><td valign="top">Preview source data</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td></tr><tr><td valign="top">Preview destination data</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td></tr><tr><td valign="top">Configure column generators</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Configure column sensitivity</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Assign table modes</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Resolve schema change warnings</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr></tbody></table>

### Data generation, tracking, and downloads permissions

<table><thead><tr><th valign="top">Permission</th><th width="120" valign="top">Manager</th><th width="85" valign="top">Editor</th><th width="96" valign="top">Auditor</th><th valign="top">Viewer</th></tr></thead><tbody><tr><td valign="top">Run data generation</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Run sensitivity scan</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"></td><td valign="top"></td></tr><tr><td valign="top">Run collection scan</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"></td><td valign="top"></td></tr><tr><td valign="top">Download job logs</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td></tr><tr><td valign="top">Download Privacy Report</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td></tr><tr><td valign="top">View the Protection Audit Trail</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td></tr><tr><td valign="top">Download SqlLdr Files</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"></td><td valign="top"></td></tr></tbody></table>

### Other data generation configuration permissions

<table><thead><tr><th valign="top">Permission</th><th width="115" valign="top">Manager</th><th width="82" valign="top">Editor</th><th width="92" valign="top">Auditor</th><th valign="top">Viewer</th></tr></thead><tbody><tr><td valign="top">Decrypt data API</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Configure subsetting</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Configure virtual foreign keys</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr><tr><td valign="top">Configure post-job scripts and webhooks</td><td valign="top">✔️</td><td valign="top">✔️</td><td valign="top"><br></td><td valign="top"><br></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.tonic.ai/app/admin/tonic-user-access/permissions/workspace-permissions/workspace-permission-built-in.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
