---
sourceDocument: Zurich Platform Analytics
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/now-intelligence

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Platform Analytics

ft:clusterId :

    - par

bundleId :

    - par

workflow :

    - Platform


---

# Roles

# Performance Analytics roles {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Assign roles to ensure that users can perform all necessary actions.

## Roles and personas {#r_PARoles__section_fm5_pg5_g2b}

Warning:  
Giving someone the pa_admin or pa_data_collector role is equivalent to giving them admin, from a security perspective.  
{#r_PARoles__table_ydm_wzd_4v__entry__3}

| Role | Authorizations | Typical persona |
|-|-|-|
| No role | * View Performance Analytics visuals on the Service Portal. * View dashboards that have been shared with this user. Some dashboards require a subject matter related role for viewing, such as sn_hr_core_basic for the HR Agent dashboard. Dashboard owners and administrators can also restrict dashboard access by role. For more information, see [Dashboard permissions](https://www.servicenow.com/docs/OliU~AWi0pQMRGPHd8c9YA "Dashboards have special granular view and edit permissions that are managed from the Sharing pane. Access control lists (ACLs) apply to most widgets that are added to dashboards."). {#r_PARoles__ul_skv_vgj_f2b} | Requester who does not need any access to Performance Analytics beyond certain visualizations of results |
| Any role (not necessarily a Performance Analytics role) | * Open the indicator library * Create dashboards. * Restrict access by role to a dashboard they create. * Share dashboards they own. {#r_PARoles__ul_zqp_yqt_g2b} |   |
| pa_viewer Contained by: All roles except pa_contributor | Before Quebec, this role was necessary for the following actions. It may still be necessary on upgraded instances. * View Analytics Hub. * Create personal thresholds and targets for indicators. * Read, Update, and Delete thresholds and targets that they created. * View text analytics widgets on dashboards. {#r_PARoles__ul_oqs_3hj_f2b} | Requester who needs and understands the details of key performance indicators |
| sn_pa_diagnostics.pa_diagnostic Contained by: pa_admin | * Read from the Diagnostics tables. * Activate or deactivate a diagnostic. * Run diagnostics. * Delete message records and diagnostic logs. {#r_PARoles__ul_ujb_5hj_f2b} | No specific persona, but this role would typically be assigned to individual business analysts or groups of fulfillers. |
| pa_contributor Contained by: pa_power_user, pa_admin | For indicators for which the user is designated as a Contributor: * Read and update scores in scoresheets. * View the Analytics Hub. {#r_PARoles__ul_l2n_jkj_f2b}This user can also read dashboards that have been shared with them. | No specific persona, but this role would typically be assigned to individual fulfillers or groups, who are allowed to set indicator scores manually |
| pa_kpi_signal_admin Contained by: admin | Enables the user to dismiss a signal or reset the baseline for [KPI Signals](https://www.servicenow.com/docs/LrklG8FdZ~RLhiYEaulyoA "KPI Signals notifies you when the behavior of a process changes significantly. This feature applies standard statistical Process Behavior Charts to Performance Analytics indicators."). | Process owner who also has some training in Performance Analytics. Also needs the pa_viewer role. |
| pa_target_admin Contained by: pa_power_user, pa_admin | * Create targets. * Read, update, and delete all targets, including those that they do not own. * Assign targets to indicators. {#r_PARoles__ul_d1x_5kj_f2b} | Manager who knows what targets to set but may not have any further input to Performance Analytics |
| pa_threshold_admin Contained by: pa_power_user, pa_admin | * Create global thresholds. * Read, update, and delete all thresholds, including those that they do not own. * Assign thresholds to indicators. {#r_PARoles__ul_pcx_ykj_f2b} | Manager who knows what thresholds to set but may not have any further input to Performance Analytics |
| pa_analyst Contained by: pa_power_user, pa_admin | * CRUD text analytics keywords, phrases, and stop words * Read indicator sources. {#r_PARoles__ul_a21_blj_f2b} | No specific persona, but this role would be assigned to individual fulfillers or groups whose expertise includes keywords, phrases, and stop words for word clouds. |
| pa_power_user Contained by: pa_admin The pa_power_user role contains the viz_admin, pa_viewer, pa_contributor, pa_target_admin, pa_analyst, and pa_threshold_admin roles. | * CRUD indicators and breakdowns. * CRUD widgets * Add Performance Analytics widgets to dashboards. * CRUD text index configurations for text analytics. * CRUD bucket groups. * CRUD indicator groups {#r_PARoles__ul_uhs_mlj_f2b} | Business analyst and visualization designer. Understands the use cases for Performance Analytics and the requirements for indicators and breakdowns. |
| pa_data_collector Contained by: pa_admin | * CRUD, schedule, and run [data collection jobs](https://www.servicenow.com/docs/zwkjt8wNk53iiqV1IWV_HQ#gloss-data-collector "A scheduled job that collects data from one or more indicator sources to produce indicator scores.") * CRUD indicator and breakdown sources * Read some system properties * CRUD system units * CRUD scripts and automated notifications * CRUD bucket groups * Activate or deactivate data snapshots {#r_PARoles__ul_lqf_wnj_f2b} | Technical expert who understands the underlying database record structure of Performance Analytics |
| pa_admin The pa_admin role contains the pa_power_user, sn_pa_diagnostics.pa_diagnostic, viz_admin, and pa_data_collector roles. | * Read Performance Analytics properties. * Access Admin Console * Launch Dependency Assessment {#r_PARoles__ul_cqy_4pj_f2b} | Performance Analytics technical expert who also understands business needs. |
| admin | The system administrator role. Users with the admin role can perform all pa_admin functions, edit properties, create [database views](https://www.servicenow.com/docs/zwkjt8wNk53iiqV1IWV_HQ#gloss-database-view "A database view defines table joins for reporting purposes. For example, a database view can join the Incident table to the Metric Definition table. This view can be used for an indicator source."), CRUD any dashboard, and assign ownership to dashboards. | System administrator |
[ ]

{#r_PARoles__table_ydm_wzd_4v}

## Spotlight roles {#r_PARoles__section_kdv_gxz_dhb}

{#r_PARoles__table_qrp_kxz_dhb__entry__3}

| Role | Authorization | Typical persona |
|-|-|-|
| pa_spotlight Contains: pa_viewer, pa_spotlight_copy_breakdown | CRUD Spotlight groups and criteria. | Expert who understands the business logic of what records require reminders. |
| pa_spotlight_viewer | Access to the dashboards from the Analytics and Reporting Spotlight Solutions. | Fulfiller who needs more than simple Priority setting to remind them of records that require action. |
| pa_spotlight_copy_breakdown | Can copy Spotlight groups to multiple elements of a breakdown. | Spotlight expert or business analyst who understands the applicability of a Spotlight group by breakdown element. |
| pa_spotlight_copy_domain | Can copy Spotlight groups to multiple domains | Domain administrator with Performance Analytics expertise |
[ ]

{#r_PARoles__table_qrp_kxz_dhb}

## Role hierarchy {#r_PARoles__section_gm5_pg5_g2b}

Certain roles such as pa_power_user and pa_admin include other roles. For example,
pa_power_user includes pa_contributor. This diagram shows the role hierarchy.

## Required roles for actions {#r_PARoles__section_mdx_fwj_d2b}

{#r_PARoles__table_sps_5pq_d2b__entry__3}

| Module | Action | Minimal required role |
|-|-|-|
| Admin Console | Access | pa_admin |
| Analytics Hub (Scorecards) | View | None, since Quebec. However, upgraded instances may still require pa_viewer. |
| Automated indicators | CRUD | pa_power_user |
| Automation schedules | Read and delete (other security restrictions likely apply) | pa_data_collector |
| Automation scripts | CRUD | pa_data_collector |
| Breakdowns and elements, including breakdown relations | CRUD | pa_data_collector or pa_power_user |
| Bucket groups | CRUD | pa_data_collector or pa_power_user |
| Color schemes for charts and targets | CRUD | pa_power_user |
| Dashboards (Responsive or Platform Analytics) | Create a dashboard. Update a dashboard they created, including restricting access by role. | Any roles necessary to access the data to display, or any one role |
| Data snapshots | Activate or deactivate | pa_data_collector |
| Responsive dashboards | Add Performance Analytics widgets to responsive dashboards you own. | pa_power_user |
| Dashboards (Responsive or Platform Analytics) | Read a dashboard that has been shared with you | No role by default, but dashboards can require roles to view their data. For more information, see [Dashboard permissions](https://www.servicenow.com/docs/OliU~AWi0pQMRGPHd8c9YA "Dashboards have special granular view and edit permissions that are managed from the Sharing pane. Access control lists (ACLs) apply to most widgets that are added to dashboards."). |
| Dashboards (Responsive or Platform Analytics) | Update, delete, or share a dashboard that you own. | pa_power_user |
| Dashboards (Responsive or Platform Analytics) | Update, delete, or share any dashboard. Reassign ownership of any dashboard. | admin (and dashboard role dashboard_admin) |
| Data collector jobs | Read, write, execute | pa_data_collector |
| Dependency assessment | Launch dependency assessment from indicator or breakdown form | pa_admin |
| External indicators and breakdowns | CRUD | pa_data_collector or pa_power_user |
| Formula and manual indicators | CRUD | pa_power_user |
| Indicator Groups | CRUD | pa_power_user |
| Sources, either indicator or breakdown | CRUD | pa_data_collector |
| Indicator targets | Read and edit targets that you do not own | pa_target_administrator |
| Indicator targets or thresholds | Create new. Read or edit ones you own. | None, since Quebec. However, upgraded instances may still require pa_viewer. |
| Indicator thresholds | Read and edit thresholds that you do not own | pa_threshold_administrator |
| In-form analytics | CRUD | pa_power_user |
| KPI Signals | Reset baseline or dismiss signal | pa_kpi_signal_admin |
| Lists in all applications | Access an interactive analysis | No role by default, but some interactive analyses require roles to view their tables |
| Manage diagnostics | Read, execute, delete | sn_pa_diagnostics.pa_diagnostic |
| Scheduled email summary jobs | CRUD | pa_power_user |
| Scoresheets | CRUD | pa_power_user |
| Service Portal | View Performance Analytics visuals | No role |
| System Properties | Edit | admin |
| System Properties | Read | pa_data_collector for some, pa_admin for all |
| System Units | CRUD | pa_data_collector |
| Text Analytics | Set up text index configurations | pa_power_user |
| Text Analytics | View a text widget on a dashboard | None, since Quebec. However, upgraded instances may still require pa_viewer. |
| Text analytics keywords, phrases, or stop words | CRUD | pa_analyst |
| What's on the Move News Rules and Statistics Generators | Read, edit | pa_power_user |
| Visualizations that contain indicator information | CRUD | pa_power_user |
[ ]

{#r_PARoles__table_sps_5pq_d2b}
**Related concepts**   

* [Dashboard permissions](https://www.servicenow.com/docs/OliU~AWi0pQMRGPHd8c9YA "Dashboards have special granular view and edit permissions that are managed from the Sharing pane. Access control lists (ACLs) apply to most widgets that are added to dashboards.")
* [Administering reports](https://www.servicenow.com/docs/aWCX5MDLOnonL5GSPUTOrg "Learn about the tasks report administrators typically perform, the objects that they work with, and the roles and rules that apply.")

