Skip to content

initial documentation for preview mode permissions #28842

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 9 commits into from
Apr 24, 2025
15 changes: 14 additions & 1 deletion content/en/account_management/rbac/permissions.md
Original file line number Diff line number Diff line change
@@ -16,7 +16,7 @@
subcategory: Datadog Role Permissions
---

## Overview
## Permissions

Permissions define the type of access a user has to a given resource. Typically, permissions give a user the right to read, edit, or delete an object. Permissions underlie the access rights of all roles, including the three managed roles and custom roles.

@@ -30,6 +30,19 @@

Sensitive permissions are flagged in the Roles and Permissions interfaces to identify that they may need increased scrutiny. As a best practice, administrators configuring roles should pay special attention to these permissions, and confirm which of these permissions are assigned to their roles and users.

### Preview mode permissions

Some permissions appear in "preview mode" before becoming fully enforced. During this period:

- Preview permissions are marked in the app with a "Preview" badge
- They do not restrict access until the preview period ends
- The preview typically lasts 2-4 weeks before enforcement begins
- Administrators should configure roles appropriately during this period

Preview mode gives your organization's administrators the ability to opt into certain new permissions, so they can prevent losing access to resources that were previously unrestricted. Release notes associated with each preview mode permission indicate when the permission is created and when it will be enforced. While these permissions don't restrict access during preview, Datadog recommends updating role configurations before they become enforced to prevent disruption.

Check notice on line 42 in content/en/account_management/rbac/permissions.md

GitHub Actions / vale

Datadog.sentencelength

Suggestion: Try to keep your sentence length to 25 words or fewer.

Check warning on line 42 in content/en/account_management/rbac/permissions.md

GitHub Actions / vale

Datadog.tense

Avoid temporal words like 'will'.

## Roles

### Managed roles

By default, existing users are associated with one of the three managed roles: