Unify and manage your data

Roles and permissions for AgentFlow Unstructured

Learn more about the roles and permissions that control access to templates, sources, pipelines, and batch runs in AgentFlow Unstructured.

AgentFlow Unstructured uses role-based access control to manage user permissions across the various components of the feature. Access is assigned by role and determines whether a user can create extraction templates, manage document sources, configure pipelines, run batch jobs, and review processing results.

Access areas

The following table describes the main access areas in AgentFlow Unstructured.

AreaWhat it covers
TemplatesExtraction template design, including parsing, extraction, mapping, schema browsing, and defining target Reltio tenant for data creation
SourcesDocument source connections, including Amazon S3 and Google Cloud Storage, file access, and connection testing
PipelinesPipeline configuration, scheduling, and pipeline settings
Batch runsPipeline execution, monitoring, document processing status, and extracted entity review

Permission types

The following table describes the permissions used across AgentFlow Unstructured resources.

PermissionMeaning
CreateCreate a new template, source, pipeline, or batch run
ReadView configurations, runs, and results
UpdateModify an existing configuration or re-execute a pipeline.
DeleteRemove a configuration
ExecutePerform an action such as testing a source connection or running a pipeline for document processing

Role access matrix

The following table summarizes the customer-facing roles for AgentFlow Unstructured.

RoleTemplatesSourcesPipelinesBatch runs
ROLE_ADMIN_AFUFull accessFull accessFull accessFull access
ROLE_AFU_DOCAI_ADMINFull accessNo accessFull accessFull access
ROLE_AFU_TEMPLATE_DESIGNERFull accessRead-onlyNo accessNo access
ROLE_AFU_PIPELINE_MANAGERNo accessRead-onlyFull accessNo access
ROLE_AFU_PIPELINE_OPERATORNo accessRead-onlyNo accessCreate, read, update, and execute
ROLE_AFU_SOURCE_MANAGERNo accessFull accessNo accessNo access
ROLE_AFU_PIPELINE_VIEWERRead-onlyNo accessRead-onlyRead-only
ROLE_AFU_VIEWERRead-onlyRead-onlyRead-onlyRead-only
Note: Full access includes create, read, update, delete, and execute permissions where those actions are available.

Role access details

The following table describes access behavior for specific AgentFlow Unstructured roles.

Role or areaAccess behavior
ROLE_ADMIN_AFUApplies to customer-facing AgentFlow Unstructured resources only
ROLE_AFU_TEMPLATE_DESIGNERIncludes read access to sources so template authors can review source configurations while working with sample documents
ROLE_AFU_PIPELINE_MANAGERIncludes read access to sources so pipeline configurators can select and review source configurations
ROLE_AFU_PIPELINE_OPERATORIncludes read access to sources so operators can review the source used by a batch run
ROLE_AFU_PIPELINE_OPERATORDoes not include delete access for batch run history
ROLE_AFU_PIPELINE_VIEWERCan view templates, pipelines, and batch runs, but cannot view sources
ROLE_AFU_VIEWERProvides read-only access across customer-facing AgentFlow Unstructured resources

Common role assignments

The following table lists common role combinations for typical users.

PersonaAssigned roles
Tenant adminROLE_ADMIN_AFU
Data engineerROLE_AFU_DOCAI_ADMIN + ROLE_AFU_SOURCE_MANAGER
Template authorROLE_AFU_TEMPLATE_DESIGNER
Pipeline configuratorROLE_AFU_PIPELINE_MANAGER + ROLE_AFU_SOURCE_MANAGER
Operations userROLE_AFU_PIPELINE_OPERATOR + ROLE_AFU_PIPELINE_VIEWER
Auditor or stakeholderROLE_AFU_VIEWER

Assigning roles and tenants to users

Use the User Management application in Console to assign AgentFlow Unstructured roles to users. User Management lets you create user accounts, assign roles, and assign tenant access.

For a new user, create the new user account, select the AgentFlow Unstructured roles, and then assign the relevant AgentFlow Unstructured tenant or tenants.

For an existing user, edit the user account and then update the assigned AgentFlow Unstructured roles and AgentFlow Unstructured tenant access on the Edit user page.