Privileges are granted to members through roles. Privileges allow role members to perform various tasks and workflows in an organization. For example, some members have privileges to create and publish content, while others have privileges to view content but cannot create their own.
Default roles include a specific set of privileges that cannot be altered. When the organization administrator creates custom roles, the administrator specifies which privileges the custom role includes.
There are two levels of privileges: General privileges and Administrative privileges.
General privileges
Members who perform specific tasks in the organization—create maps or edit features, for example—can be assigned the general privileges they need to work and share with groups, content, and features.
The following table lists privileges, grouped by privilege type, and provides a description of each privilege. The table also lists which default roles include the privilege.
In addition to these privileges that you can grant to custom roles and that are included with default roles, all users can use geosearch and subscriber content regardless of their role.
General privileges | Default roles that include the privilege | |
---|---|---|
Members | View Allows members to view the Members tab of the organization page. Without this privilege, members cannot see the organization page. | User, Publisher, Facilitator, Administrator |
Groups | Create, update, and delete Allows members to create groups in the organization and control the groups they own. | User, Publisher, Facilitator, Administrator |
Join organizational groups Allows members to be added to or request to join groups in the organization. Members can only request to join organizational groups if they also have the privilege to view groups shared with the organization. Without the privilege to view groups shared with the organization, members do not see the groups and, therefore, cannot request to join them. | All default roles Note:Only members of the User, Publisher, Facilitator, and Administrator default roles can join shared update groups. | |
Join external groups Allows members to be added to or request to join groups external to your organization. Members can only request to join external groups if they also have the privilege to view groups shared with the organization. Without the privilege to view groups shared with the organization, members do not see the groups and, therefore, cannot request to join them. | User, Publisher, Facilitator, Administrator | |
View groups shared with organization Allows members to discover and view groups that are configured to allow organization members to view them. | User, Publisher, Facilitator, Administrator | |
Invite partnered organization members Allows members to create groups that include members from partnered organizations, as well as invite members of partnered organizations to groups. | User, Publisher, Facilitator, Administrator | |
Add members from other organizations Allows members to create groups that include members from other organizations, as well as invite members of other organizations to groups. | User, Publisher, Facilitator, Administrator | |
Content | Create, update, and delete Allows members to create items in the organization and control items they own. | User, Publisher, Facilitator, Administrator |
Publish hosted feature layers Allows members to publish hosted feature layers from shapefiles, .csv files, and so on. | Publisher, Facilitator, Administrator | |
Publish hosted tile layers Allows members to publish hosted tile layers from tile packages, features, and so on. | Publisher, Facilitator, Administrator | |
Publish hosted scene layers Allows members to publish hosted scene layers. | Publisher, Facilitator, Administrator | |
Publish hosted tiled imagery layers Allows members to publish hosted tiled imagery layers from a single image or collection of images, and allows members to export a tile package from a hosted tiled imagery layer. Note:This privilege requires an ArcGIS Image for ArcGIS Online user type extension license. | Publisher, Facilitator, Administrator | |
Publish hosted dynamic imagery layers Allows members to publish hosted dynamic imagery layers from a single image or collection of images. Note:This privilege requires an ArcGIS Image for ArcGIS Online user type extension license. | Publisher, Facilitator, Administrator | |
View content shared with the organization Allows members to view content shared with the organization. | All default roles | |
Create and edit notebooks Allows members to create and edit interactive notebooks. | Administrator | |
Schedule notebooks Allows members to schedule future automated runs of a notebook. | Administrator | |
View location tracks Allows members to view members' location tracks using shared track views when location sharing is enabled. | Administrator | |
Publish feeds Allows members to publish feeds to collect and display real-time data using ArcGIS Velocity. Note:This privilege is only visible if your organization has ArcGIS Velocity licenses. | Publisher, Facilitator, Administrator | |
Publish real-time analytics Allows members to publish real-time analytics to analyze and process real-time data using ArcGIS Velocity. Note:This privilege is only visible if your organization has ArcGIS Velocity licenses. | Publisher, Facilitator, Administrator | |
Publish big data analytics Allows members to publish big data analytics to analyze historical observation data using ArcGIS Velocity. Note:This privilege is only visible if your organization has ArcGIS Velocity licenses. | Publisher, Facilitator, Administrator | |
Reassign content Allows members to transfer ownership of content they own to another member in the same organization. The member to whom ownership is transferred must have the privilege to receive content. | Administrator | |
Receive content Allows members to receive content transferred to them from members who have the privilege to reassign content. This privilege is not required to receive content transferred by organization administrators. | Administrator | |
Sharing | Share with groups Allows members to share items they own with groups to which they belong. | User, Publisher, Facilitator, Administrator |
Share with organization Allows members to share items they own with your organization. | User, Publisher, Facilitator, Administrator | |
Share with public Allows members to share items they own with the public, including those who are not signed in. | User, Publisher, Facilitator, Administrator | |
Make groups visible to organization Allows members to make groups discoverable by your organization. | User, Publisher, Facilitator, Administrator | |
Make groups visible to public Allows members to make groups discoverable by the public, including those who are not signed in. | User, Publisher, Facilitator, Administrator | |
Make groups available to Open Data Allows members to designate groups as being available for use in Open Data sites. | User, Publisher, Facilitator, Administrator | |
Premium Content | Geocoding Allows members to use ArcGIS World Geocoding Service (or a view of this locator) to convert addresses or places to map points and store the results—for example, when publishing spreadsheets (.csv or Microsoft Excel files) as hosted feature layers. This does not apply to your own locators configured for the organization. | All default roles |
Network Analysis Allows members to perform network analysis tasks such as routing and drive-time areas. | All default roles | |
Spatial Analysis Allows members to perform spatial analysis tasks such as creating buffers. | User, Publisher, Facilitator, Administrator | |
GeoEnrichment Allows members to use GeoEnrichment to enrich features. | User, Publisher, Facilitator, Administrator | |
Demographics Allows members to use premium demographic data. | All default roles | |
Imagery Analysis Allows members to perform imagery and raster analysis tasks such as calculating slope. This requires an ArcGIS Image for ArcGIS Online user type extension license. | Publisher, Facilitator, Administrator | |
Advanced notebooks Allows members to import and use ArcPy modules in ArcGIS Notebooks. | Administrator | |
Feature report Allows members to create feature reports in ArcGIS Survey123. | User, Publisher, Facilitator, Administrator | |
Features | Edit Allows members to edit features in editable layers that are not public, based on the edit options enabled on the layer. | Data Editor, User, Publisher, Facilitator, Administrator |
Edit with full control Allows members to add, delete, and update features and attributes in editable hosted feature layers, regardless of the editing operations enabled on the layer. | Administrator |
Administrative privileges
The privileges in the table below are included in the default administrator role and can also be assigned to custom roles. Including administrative privileges in custom roles gives members the ability to assist default administrators with managing members, groups, and content in the organization.
Note:
Some administrative privileges are reserved for members of the default administrator role and are not available for custom roles.
Administrative privileges | |
---|---|
Members | View all Allows members to view all member account information. |
Update Allows members to reset passwords, update member account information, and assign (and unassign) member categories. Note:Only members of the default administrator role can reset the passwords of other members of the default administrator role. | |
Delete Allows members to delete member accounts. | |
Invite Allows members to invite members to the organization. | |
Disable Allows members to disable and enable member accounts. | |
Change roles Allows members to change roles assigned to organization members. Note:Only members of the default administrator role can change another member's role to and from the default administrator role. | |
Manage licenses Allows members to manage licenses for members. | |
Manage categories Allows members to configure member categories for the organization. | |
Groups | View all Allows members to view groups owned by members. |
Update Allows members to update groups owned by members. | |
Delete Allows members to delete groups owned by members. | |
Reassign ownership Allows members to reassign ownership of groups. | |
Assign members Allows members to assign members to groups, remove members from groups, and update members' group roles in your organization. | |
Link to organization-specific group Allows members to link ArcGIS Online group membership to organization-specific groups. | |
Create with update capabilities Allows members to create and own groups that allow group members to update all items in the group (shared update groups). | |
Content | View all Allows members to view content owned by members. |
Update Allows members to update and categorize content owned by members. | |
Delete Allows members to delete content owned by members. | |
Reassign ownership Allows members to reassign ownership of content. | |
Manage categories Allows members to configure content categories for the organization. | |
Share member content with organization Allows members to share content owned by other members of your organization with the organization. | |
Share member content with public Allows members to share content owned by other members of your organization with the public. | |
ArcGIS Marketplace subscriptions | Create and manage Allows members to create listings, list items, and manage subscriptions in ArcGIS Marketplace, and manage purchasers and contact information for your organization. Note:Use of this privilege depends on your organization obtaining listing and publishing access to ArcGIS Marketplace. |
Purchase and get free products Members can send purchase requests and access free products from providers in ArcGIS Marketplace. Note:To allow members to purchase products using credit cards, you must designate them as ArcGIS Marketplace purchasers. | |
Start trials Allows members to start trials in ArcGIS Marketplace. | |
Organization settings | Security and infrastructure Manage the organization's security settings. Allows members to configure the following in the organization settings:
|
Organization website Manage the organization's website settings. Allows members to configure the following in the organization settings:
| |
Collaborations Allows members to configure and manage the organization's collaborations in the organization settings. | |
Credits Allows members to configure credits in the organization settings and enable credit budgeting. | |
Member roles Allows members to configure member roles in the organization settings and change member roles. | |
Utility services Manage the organization's utility service settings. Allows members to configure the following in the organization settings:
|
Privileges reserved for members of the default administrator role
Some administrative privileges are reserved for members of the default administrator role and are not available for custom roles. For example, only members of the default administrator role can remove other administrators from the organization. The following is a list of privileges reserved for members of the default administrator role:
- Create and manage administrative reports.
- Enable and disable Esri access on member accounts.
- Change member role to or from administrator.
- Delete other administrators from the organization.
- Change member email addresses for ArcGIS organizational accounts.
- Reset the passwords of other members of the default administrator role.
- Create and own administrative groups.
- Assign custom roles with administrative privileges to new members when adding them to the organization.
Privileges for common workflows
Some workflows require a combination of privileges. In some cases, members are responsible for performing multiple workflows. For example, a GIS analyst may need to use certain analysis tools as well as publish hosted feature layers, which require the privileges listed in the table below for the Use the analysis tools and Publish hosted feature and WFS layers workflows. If you are unable to perform a function that you think your role should allow you to perform, verify that the organization administrator has enabled the full set of privileges required for the function.
General workflows
Workflow | Required privileges | |
---|---|---|
Use the analysis tools |
Note:Some tools require the following additional privileges:
| |
Publish hosted feature and WFS layers |
| |
Publish hosted tile layers |
| |
Publish hosted scene layers |
| |
Publish hosted elevation layers |
| |
Publish hosted imagery layers |
| |
Publish apps from Map Viewer, Map Viewer Classic, or a group page |
| |
Embed maps or groups |
| |
Make groups available to Open Data sites |
| |
Reassign ownership of your items to another member |
Note:Only members who have the privilege to receive content can become owners of your reassigned content. | |
Add, update, and delete features in hosted feature layers that have editing enabled for add or update only |
|
Administrative workflows
Workflow | Required privileges | |
---|---|---|
Manage content owned by members |
| |
Manage groups owned by members |
| |
Manage member profiles |
| |
View subscription status reports |
| |
Manage the organization's security settings |
| |
Manage the organization's website settings |
| |
Manage the organization's collaborations |
| |
Manage the organization's credit settings |
| |
Manage the organization's member roles |
| |
Change a member's user type |
| |
Manage the organization's utility service settings |
|