Why Can't I Access the Transformations Tab With the Manage Connection Role?
Question
I have the Manage Connection user role, but I can't open the Transformations tab or edit the transformations associated with my connection. Why can't I access transformations, and which role grants this access?
Environment
- Role-based access control
- Transformations
Answer
Transformation permissions apply at the destination level. Connection-level roles, including Manage Connection, Edit Connection, and View Connection, don't grant access to transformations, regardless of how many connections they cover. To grant access, assign a standard role with transformation permissions or create a custom role.
Assign a standard role
The Edit Destination role is the least privileged standard destination role that grants transformation access. It allows users to view the destination and create, view, edit, and delete its transformations and connections. It doesn't allow users to edit or delete the destination.
The Account Analyst and Account Administrator roles also grant transformation access across all destinations. For more information, see Role Permission Matrix Tables.
Create and assign a custom role
To grant transformation access with more limited connection permissions, create a custom destination role. For more information, see Custom roles in our RBAC model.
Custom roles are available only on the Enterprise and Business Critical plans. To create one, you must be an Account Administrator or have a custom role with the Roles:Manage permission.
- In your Fivetran dashboard, go to the Roles page.
- Click + Add role.
- Enter a Role name.
- Select Destinations as the area of permissions.
- Click Continue.
- Set the following destination permissions:
- Destinations: View
- Users: None
- External logging services: None
- Transformations: Manage
- Set the connection permission level to Create.
- Review the role details, then click Create.
- Assign the role to the user for the applicable destination.
This role lets the user create, view, edit, and delete transformations in the destination without allowing them to edit or delete the destination itself. It also lets them create connections and view, edit, and delete only the connections they create.