Skip to main content
Version: 2.0-rc2

Tenant Admin

Role overview​

note

Your Mission: You are the administrator of your organization's instance. Your primary goal is to build the foundation for collaboration by inviting the right people and ensuring they have the correct permissions to do their work.

Why your role is vital: You are the "Enabler". Without your initial setup, Data Architects, Stewards and Owners cannot access the Platform to begin creating Data-related elementsData-related elementsA collective term for Datasets, Data structures, Data pools and Data sources..

Defining your scope: You manage Users, Groups, Roles, and platform-wide access. You define the organizational foundation on which others create and govern data.

Your core responsibilities​

  • User Management: You are responsible for onboarding your team. You invite new users to the Platform and manage their accounts.
  • Access Control: Using Groups, Roles, and platform-wide assignments, you define what users can access across the Platform.

Outside your scope​

It is not your responsibility to create data-related elementsData-related elementsA collective term for Datasets, Data structures, Data pools and Data sources. or to govern them. If you want to work with data-related elementsData-related elementsA collective term for Datasets, Data structures, Data pools and Data sources. themselves, the Data Architect or Data Steward role is likely the right role for you.

Understanding the Authorisation Logic

To manage permissions effectively, it helps to understand the authorisation concept CIVITAS/CORE uses to grant access:

The access logic: Access is always the result of a User being assigned to a Group, which has been assigned to specific Roles.

Scopes: Roles are limited to specific "Scopes" (functional areas). This ensures that users only interact with the parts of the Platform relevant to their specific tasks.

→ Deep Dive Authorisation

Typical administrative tasks​

Beyond the initial setup, your day-to-day administration involves:

  • Systematic User Onboarding: Creating Users in the UI. Once saved, the system automatically sends a secure invitation email with a login link. → see Onboard Users for the full walkthrough, including validation rules and the first-login flow.
  • Structuring the Organization: Building groups that mirror your actual organization (e.g., by Departments, Offices, or specific use cases like "Traffic Monitoring").
  • Scaling Permissions: Assigning roles to entire groups rather than individuals. This is a necessity for maintaining a secure and manageable Platform as your team grows.

Your first steps​

To get your organization started with CIVITAS/CORE, follow this path:

  1. Familiarize yourself with the User List: Open the User Management section from the sidebar to see an overview of all current members in your tenantTenantAn isolated organizational partition that owns Data pools, Datasets, Users, Groups, and Roles. All access rules exist within their Tenant, and the Tenant is the widest Scope of a Role. Currently, one Tenant corresponds to the Platform..
  2. Familiarize yourself with the standard role set and the difference between system roles and data roles.
  3. Plan out how your organization could be split into logical Groups.
  4. Invite your Core Team: Use the + Create User (+ User erstellen) workflow to invite your to-be Data Architects and Data Stewards so they can begin structuring your data ecosystem. → see Onboard Users for the full walkthrough.
  5. Assign Roles: Ensure each invited user is assigned to the appropriate Group and Role right from the start.

Best practices & avoiding mistakes​

  • Avoid "Tailored" Roles: Never customize a role for a specific individual. Always assign roles to Groups. If an employee leaves, your permission structure remains intact for their successor.
  • Mirror your Organigram: Building your Groups based on your existing organizational chart makes management intuitive.
  • Make essential assignments: Assign at least one group with a data role with platform-wide scope to let them start creating data-related elementsData-related elementsA collective term for Datasets, Data structures, Data pools and Data sources. (→ Deep Dive Authorisation)

Key terms to know​

To manage your tenantTenantAn isolated organizational partition that owns Data pools, Datasets, Users, Groups, and Roles. All access rules exist within their Tenant, and the Tenant is the widest Scope of a Role. Currently, one Tenant corresponds to the Platform. effectively, please review these terms in our Glossary:

  • User: An individual invited to your tenantTenantAn isolated organizational partition that owns Data pools, Datasets, Users, Groups, and Roles. All access rules exist within their Tenant, and the Tenant is the widest Scope of a Role. Currently, one Tenant corresponds to the Platform. via their email address
  • Groups: A way to organize users logically (e.g., "Department A")
  • Roles: A set of permissions that defines a user's functional capabilities (e.g., "Data Steward")
  • Scopes: The organizational or functional boundary within which a specific Group and specific Role is active. Scopes are either the Platform, or a specific data-related elementsData-related elementsA collective term for Datasets, Data structures, Data pools and Data sources. like data structure, data sourceData sourceA data-related element that represents the origin of data. It defines how data is connected, accessed, and ingested into the Platform, such as an external database or sensor network. or DatasetDatasetA data-related element that contains processed data and makes it available for consumption. A Dataset is populated via Pipelines and carries Metadata and access permissions.
  • Data poolData poolA governed, centralized collection of Datasets that are managed together within the Platform. It provides a shared place to organize, discover, and access data, including associated metadata, ownership, and access permissions. With Data pools users can cluster their Datasets according to their organizational structure (e.g., by Departments, Offices).: Organizes related DatasetsDatasetA data-related element that contains processed data and makes it available for consumption. A Dataset is populated via Pipelines and carries Metadata and access permissions. and provides an additional scope for access management and Data sourceData sourceA data-related element that represents the origin of data. It defines how data is connected, accessed, and ingested into the Platform, such as an external database or sensor network. availability
  • Permissions: A granular rule that defines a single allowed action within the system, such as "read DatasetDatasetA data-related element that contains processed data and makes it available for consumption. A Dataset is populated via Pipelines and carries Metadata and access permissions." or "update Data sourceData sourceA data-related element that represents the origin of data. It defines how data is connected, accessed, and ingested into the Platform, such as an external database or sensor network."
  • Authorization: The security mechanism that determines the specific actions a user is permitted to perform based on their assigned permissions

Deep Dives​

→ Authorisation