Skip to content

Conversation

srosenthal-dd
Copy link
Member

What does this PR do? What is the motivation?

I'm looking at ways to reduce the confusion around roles & permissions. I noticed the docs don't explicitly cover the main distinction between managed and custom roles, and would like to fix it.

Merge instructions

Merge readiness:

  • Ready for merge

For Datadog employees:

Your branch name MUST follow the <name>/<description> convention and include the forward slash (/). Without this format, your pull request will not pass CI, the GitLab pipeline will not run, and you won't get a branch preview. Getting a branch preview makes it easier for us to check any issues with your PR, such as broken links.

If your branch doesn't follow this format, rename it or create a new branch and PR.

[6/5/2025] Merge queue has been disabled on the documentation repo. If you have write access to the repo, the PR has been reviewed by a Documentation team member, and all of the required checks have passed, you can use the Squash and Merge button to merge the PR. If you don't have write access, or you need help, reach out in the #documentation channel in Slack.

Additional notes

I'm looking at ways to reduce the confusion around roles & permissions. I noticed the docs don't explicitly cover the main distinction between managed and custom roles, and would like to fix it.
[1]: /account_management/rbac/granular_access
[2]: /account_management/users/#edit-a-user-s-roles
[3]: /api/latest/roles/#list-permissions
[3]: /api/latest/roles/#list-permissions
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I didn't mean to change this line. Might be the change of a newline at the end of the file?

Copy link
Contributor

Preview links (active after the build_preview check completes)

Modified Files

@srosenthal-dd srosenthal-dd marked this pull request as ready for review September 23, 2025 01:17
@srosenthal-dd srosenthal-dd requested a review from a team as a code owner September 23, 2025 01:17
- Datadog Read Only Role

All users with one of these roles can read all data types, except for [individually read-restricted][1] resources. Admin and Standard users have write permissions on assets. Admin users have additional read and write permissions for sensitive assets relating to user management, org management, billing, and usage.
All users with one of these roles can read data, except for [individually read-restricted][1] resources. Admin and Standard users have write permissions on assets. Admin users have additional read and write permissions for sensitive assets relating to user management, org management, billing, and usage.
Copy link
Member Author

@srosenthal-dd srosenthal-dd Sep 23, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All users with one of these roles can read all data types

This seemed misleading to me. Read Only Role cannot read Audit Trail, for example. Read Only role grants only read access but does not grant ALL read data accesses.

@joepeeples joepeeples added the editorial review Waiting on a more in-depth review label Sep 23, 2025
@joepeeples
Copy link
Contributor

joepeeples commented Sep 23, 2025

Opened DOCS-12139 to assign a Docs writer and follow up with editorial review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
editorial review Waiting on a more in-depth review
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants