Deployment space collaborator roles and permissions

When you add collaborators to a deployment space, you can specify which actions they can do by assigning them access levels. Learn how to add collaborators to your deployment spaces and the differences between access levels.

User roles and permissions in deployment spaces

You can assign the following roles to collaborators based on the access level that you want to provide:

  • Admin: Administrators can control your deployment space assets, users, and settings.
  • Editor: Editors can control your space assets.
  • Job Operator: Job Operators can manage job runs and scheduling. They cannot create or modify assets or job definitions.
  • Viewer: Viewers can view your deployment space.

The following table provides details on permissions based on user access level:

Deployment space permissions
Enabled permission Viewer Job Operator Editor Admin
View assets and deployments
Comment
Monitor
Test model deployment API
Find implementation details
View job details and job runs
Run jobs
Pause, stop, cancel, or delete job runs
Edit job schedule
Specify parameter values when running a job
Configure deployments
Batch deployment score
Online deployment score
Update assets
Import assets
Download assets
Deploy assets
Remove assets
Remove deployments
View spaces/members
Delete space
Change deployment owner

Job Operator role

The Job Operator role is designed for production environments where a user needs to be able to operate jobs without having the privilege to edit jobs and other assets.

Key capabilities:

  • View access: Job Operators can view job details, job runs, and the assets that trigger jobs, but cannot edit or import assets.
  • Job execution: Job Operators can run jobs and manage job runs by pausing, stopping, canceling, or deleting them.
  • Schedule management: Job Operators can edit job schedules, which applies to the job definition.
  • Runtime parameters: Job Operators can specify parameter values when running a job. These changes apply only to the next run and do not modify the job definition.

Restrictions:

  • Job Operators cannot modify job definitions or assets.
  • Job Operators cannot import assets into the space.
  • Job Operators cannot perform batch or online deployment scoring.

Job execution privileges

When a Job Operator runs a job, the job executes with the privileges of an Editor or Admin who has job permissions delegated to them in the deployment space. An Admin can designate which Editor or Admin will provide these delegated permissions in the Access control settings. This allows the job to create and modify assets in the deployment space when required, even though the Job Operator does not have direct permission to perform these actions.

Adding collaborators to your deployment space

Prerequisites:
To add collaborators to any space, you must be a platform-level administrator and have the Manage deployment spaces permission. For more information, see Predefined roles and permissions and Managing IBM Software Hub users.

Restriction:
You can add collaborators to your deployment space only if they are a part of your organization and if they provisioned Watson Studio.

To add one or more collaborators to a deployment space:

  1. From your deployment space, go to the Manage tab and click Access Control.
  2. Click Add collaborators and choose one of the following options:
    • If you want to add a user, click Add users. Assign a role that applies to the user.
    • If you want to add pre-defined user groups, click Add user groups . Assign a role that applies to all members of the group.
  3. Add the user or user groups that you want to have the same access level and click Add.