Baserow Role Based Permissions give organizations more flexibility around permissions that can be granted to users. Role-based access control allows admins to provide users with varying levels of access based on their roles.
This support article describes the various actions available to users at each role level.
Assigning role-based permission is only available to users with a Self-hosted Enterprise License or on Cloud Hosted Advanced Plan on Baserow.io.
Teams can better manage complex access protocols using role-based permissions to monitor who should have access to resources and data as well as what they can do with it.
The right role determines what actions users can or cannot take in the workspaces, databases, and tables to which they have access. You can assign members one of the following roles – Admin, Builder, Editor, Commenter, Viewer, No Access or No Role. For an overview of each role, please refer to this support article.
An admin can assign roles to Members and/or Teams at the workspace level and on individual databases and tables. For example, an admin can invite a user to a Baserow workspace while restricting their access to just viewing tables and databases, by assigning the user a “Viewer” role. Learn more about assigning roles at Workspace, Database or Table levels.
For more information about how users and roles affect your billing, see this support article.
Roles are hierarchical, which means that a higher role can perform all of the functions of a lower role. You can lower or raise the role of a user or team by assigning a role on a specific table or database.
When a user has varying roles across workspace, database and table levels, we pick the most specific roles first and ignore any database or workspace level roles.
Member-specific roles will always override Team roles. To manage control, we recommend that you assign Members “No Role” at the Workspace level first, invite members to a team on workspace level, and then assign roles to the team on individual databases and tables as you see fit.
A higher role has all of the permissions of the lower roles. Other users might inherit access to a Database or Table via their respective roles on the parent Database or Workspace. For security, we recommend the following general workflow:
When a user is in teams and has roles assigned to a workspace, but also on individual databases or tables, the following rules apply to decide which role to go with:
For example, if a user has the following individual user permissions: Admin role at the workspace level, Builder role in database A, and Viewer role in table A. Also, the user is a member of a team with the following team permissions: Viewer role at the workspace level and Admin role on table A. This user’s active role for accessing table A is as a Viewer - the individual user role assigned to table A - which means they can only view the rows in the table and make no edits.
Learn more about Baserow pricing and who is considered a “user” for billing purposes.
Granting access to users at a lower level, such as individual databases instead of the entire workspace, can provide added security and control over sensitive information. While workspace members generally have access to all databases within the workspace, inviting users to specific databases allows you to restrict their access to sensitive or confidential data. This approach helps ensure that only authorized individuals can view the contents of certain databases.
For example, if there are two teams in a workspace: Sales Team A and Audit Team. While it is a good idea to have two separate databases for each team in a single workspace, it may not be a good idea for each team to be able to access each other’s databases. Create a team and grant appropriate access to the team, or assign key roles to members at the database level rather than at the workspace level.
Still need help? If you’re looking for something else, please feel free to make recommendations or ask us questions—we’re ready to assist you.
Contact support for questions about Baserow or help with your account.