Skip to main content
In Splunk Agent Observability, capability-based access tokens and collaborator roles determine the actions that a user can perform on a resource. For an action to be allowed, both of these conditions must be met:
  1. The access token contains the matching capability.
  2. The user has the required collaborator role for the resource.
This page describes capability-based access control and the available capability keys.

Collaborator roles

Collaborator roles don’t apply to global evaluators or groups. Group access is based on group membership or visibility.
When a resource is shared with a user in the UI, the user is granted a collaborator role that sets a resource-level ceiling on the actions they can perform. The user’s access token must still contain the required capability for them to perform a given action. The following table describes resource access by collaborator role:

Capability types

Capabilities can be one of the following types:
  • SHARED actions apply to a shared resource. For example, a project used by multiple people. SHARED isn’t a blanket permission. It doesn’t add you as a collaborator or elevate your role.
  • ALL actions apply across the organization.
  • GLOBAL actions only apply to evaluators, which don’t use collaborator roles.

Capability keys

Annotation queues

Projects

Datasets

Prompts

LLM integrations

Evaluators

Groups

Agent controls

Custom dashboards

Provider-management API integrations

Organization settings

Users

Roles in Splunk Observability Cloud