Skip to main content

Celonis Product Documentation

Available Service permissions

When using the Celonis Platform, team admins can assign and manage the permissions their team members / users hold in the Services enabled for their team. These permissions control who can access each Service and what features they can use within them.

Admins can assign and manage Service permissions by clicking Admin & Settings - Permissions:

Accessing_permissions.png

Depending on your Celonis Platform license, the following Services and permissions may be enabled for your team:

All Celonis Platform Service permissions are listed in the following format:

Permission name (Permission type) - Description.

Admins can assign and manage the following Action Engine service permissions in the Celonis Platform:

  • My Inbox (Viewer) - The user has access to 'My Inbox'.

  • Manage Skills (Analyst) - The user has access to 'My Inbox' and can manage skills and see projects.

  • Access All Projects (Analyst) - The user has access to 'My Inbox' and can see adoption.

  • Create Projects (Analyst) - The user has access to 'My Inbox' and can create new projects

action_engine_permissions.png

Admins can assign and manage the following Data Integration service permissions in the Celonis Platform:

  • Use all Data Models (Viewer) - The user can assign any Data Model from any Data Pool to, e.g. a variable in Studio and use it from there. This does not give any permission to access or make changes in Data Integration.

  • View all Data Pool (Analyst) - The user can view all Data Pools of this team in a read-only mode and has no permission to modify any of them.

  • Edit all Data Pools (Analyst) - The user has “edit” permissions and can perform all operations for all Data Pools except deleting a Data Pool and managing permissions.

  • Create Data Pools (Analyst) - The user can create new Data Pools in Data Integration and will automatically have Manage Data Pool Permissions in those.

  • Manage all Data Pools (Analyst) - The user has "edit" permissions and can perform all operations, including sensitive ones on all Data Pools of this team.

data_integration_permissions.png

Admins can assign and manage the following File Storage Manager service permissions in the Celonis Platform:

  • Get (Viewer) - The user can view all files in a storage bucket.

  • Create (Analyst) - The user is able to create storage buckets.

  • Delete (Analyst) - The user is able to delete storage buckets.

  • Admin (Analyst) - The user is able to create and delete storage buckets.

  • List (Analyst) - The user is able to call a list of all storage buckets.

file_storage_manager_permissions.png

Admins can assign and manage the following Machine Learning service permissions in the Celonis Platform:

  • Create Apps (Viewer) - The user can create new apps.

  • Use all Apps (Analyst) - The user can use all existing Apps.

  • Manage All Apps (Analyst) - The user can edit, upgrade, delete, update the associated application key and update the permissions for all apps.

  • Create Workspaces (Analyst) - The user can create workspaces.

  • Manage All Workspaces (Analyst) - The user can edit, delete all workspaces.

machine_learning_permissions.png

Admins can assign and manage the following On-prem automation service permissions in the Celonis Platform:

  • View agents (Viewer) - The user can view the list of agents in the Automation global page.

  • Manage permissions (Analyst) - The user can update permissions related to automation.

  • Register agents (Analyst) - The user can register new agents in the EMS team. Meaning, the user can create a connection between the agent installed in a customer's on-prem environment and the Celonis Platform team.

  • Edit agents (Analyst) - The user can edit or delete agents in the Automation global page.

on-prem_automation_permissions.png

Admins can assign and manage the following Process Repository service permissions in the Celonis Platform:

  • Use categories (Viewer) - The user can exist existing process repository categories but not create them.

  • Create and modify categories (Analyst) - The user can create and modify existing process categories but, unless combined with other permissions, can't delete existing categories.

  • Modify existing categories (Analyst) - The use can modify existing process categories but, unless combined with other permissions, can't create categories.

  • Delete existing categories (Analyst) - The use can delete existing process categories but, unless combined with other permissions, can't create or modify categories.

process_repository_permissions.png

Admins can assign and manage the following Studio service permissions in the Celonis Platform:

  • Edit all spaces (Analyst) - The user can only edit existing space names but can create, edit, delete and set permissions for spaces and content they have created unless permissions are removed.

  • Delete all spaces (Analyst) - The user can create, edit, delete and set permissions to spaces and content they have created, unless permissions are removed. They can't delete other spaces unless this permissions is combined with Edit all Spaces.

  • Create space (Analyst) - The user can create a new space, package or install from Marketplace. Once the space is created the user can edit, delete and assign permissions to the created space and its contents.

  • Manage permissions (Analyst) - The user can create, edit, delete and set permissions to spaces and content they have created, unless permissions are removed. They can't manage permissions to other spaces unless this permissions is combined with Edit all Spaces.

Studio_permissions.png

Admins can assign and manage the following Task Mining service permissions in the Celonis Platform:

  • Edit Client Settings (Analyst) - Analysts are granted permissions to see and edit everything behind the menu point "Client Setups" in Task Mining.

  • Edit Users (Analyst) - Analysts are granted permissions to see and edit everything behind the menu point "Users & Invite".

task_mining_permissions.png

Admins can assign and manage the following team service permissions in the Celonis Platform:

  • Import members (Viewer) - The granted user can import members from one team to another.

  • Use Audit Logs API (Analyst) - The granted user can now configure an API to export audit logs.

  • Use Login History API (Analyst) - The granted user can now configure an API to export login history logs.

  • Use Studio Adoption API (Analyst) - The granted user can now configure an API to export user adoption events.

  • Manage Audit Logs (Analyst) - The granted user gets limited access to Admin & Settings, but can only see Audit Logs in the menu.

  • Manage Login History (Analyst) - The granted user gets limited access to Admin & Settings, but can only see login history in the menu.

  • Manage General Settings (Analyst) - The granted user gets limited access to Admin & Settings, but can only see Settings in the menu.

  • Manage SSO Settings (Analyst) - The granted user gets limited access to Admin & Settings, but can only see Single sign-on in the menu.

  • Manage Members (Analyst) - The granted user gets limited access to Admin & Settings, but can only see Users in the menu.

  • Manage Groups (Analyst) - The granted user gets limited access to Admin & Settings, but can only see Groups in the menu.

  • Manage Permissions (Analyst) - The granted user gets limited access to Admin & Settings, but can only see Permissions in the menu.

  • Manage Member Locking Policy (Analyst) - The granted user gets limited access to Admin & Settings, but can only see User locking policy in the menu.

  • Manage License Settings (Analyst) The granted user gets limited access to Admin & Settings, but can only see License in the menu.

  • Manage Admin Notifications (Analyst) - The granted user gets limited access to Admin & Settings, but can only see Notifications in the menu.

  • Manage Uplink Integrations (Analyst) - The granted user gets limited access to Admin & Settings, but can only see Uplink integrations in the menu.

  • Manage Event Collection on Premises (Analyst) - The granted user gets limited access to Admin & Settings, but can only see Permissions in the menu.

  • Manage Adoptions Views (Analyst) - The granted user gets limited access to Admin & Settings, but can only see User Adoption Views in the menu.

  • Manage Download Portal (Analyst) - The granted user gets full access to the Download Portal, giving them access to files which support Celonis provided apps.

team_permissions.png

Admins can assign and manage the following Transformation Center service permissions in the Celonis Platform:

  • View Objective (Viewer) - The user can view existing objectives.

  • Create Objective (Analyst) - The user can create an objective.

  • Edit Objective (Analyst) - The user can edit an existing objective.

  • Delete Objective (Analyst) - The user can delete an objective.

  • Create KPI (Analyst) - The user can create and edit KPIs.

  • Export Content (Analyst) - The user can export KPIs and objectives.

  • Move to (Analyst) - The user can move content.

  • Manage permissions (Analyst) - The user can manage service permissions.

transformation_center_permissions.png

Admins can assign and manage the following Transformation Hub service permissions in the Celonis Platform:

  • Access Transformation Hub (Analyst) - The user can access the Transformation Hub service.

transformation_hub_permissions.png

Admins can assign and manage the following User Provisioning servicer permissions in the Celonis Platform:

  • SCIM (Viewer) - The user can configure SCIM API for user provisioning (If enabled).

user_provisioning_permissions.png