Last updated: October 7, 2026
Access Control
Member Roles
Dash0 provides two primary member roles to manage access within your organization: Admin and Member. These roles determine what actions members can perform within the Dash0 platform. You can invite members and modify their roles within your organization settings in the dialog under Members.
Actions Which Require Admin Role
- Create datasets
- Modify billing information
- View usage and billing data
- Rename, change avatar and delete organization
- View and edit auth tokens
- Change member roles
- Invite new members to the organization
- Remove members from the organization
- View audit logs
- Add members to teams
- View member details
- Create and edit teams
Asset-Based Access Control
In addition to member roles, Dash0 implements granular access control at the asset level like dashboards, views, check rules, synthetic checks, or Agent0 automations.
As creator of one of the above mentioned assets, you are able to share them with view or edit permissions with roles, teams or individual members.
- With view permissions you give the permission to view and clone the asset.
- With edit permissions you can also delete, edit and update the sharing settings of the asset.
Static Permissions
Some assets have static permissions which cannot be changed. Every member in your organization has view permissions on all check rules and synthetic checks. Admins are always allowed to edit all check rules and synthetic checks. On the dataset level, admins always have "maintain" permissions.
Everyone who can read a dataset can view the Agent0 automations in it, so you share an automation only to give edit permissions. Admins can always edit automations created in Dash0. See Control Automation Sharing and Access.
Note: Assets which are maintained via infrastructure as code (IaC) cannot be edited in the UI. You can only delete and clone them.
Dataset Permissions
On every dataset you can assign the maintain, edit and read permissions for different roles, teams and individual members. Admins always have "maintain" permission on every dataset.
On every new dataset, members will also get "read" permission by default, which can be removed in the settings.
Dataset Permission Comparison
| Action | Maintain | Edit | Read |
|---|---|---|---|
| View traces, logs, and metrics | ✅ | ✅ | ✅ |
| Create and edit spam filters | ✅ | ❌ | ❌ |
| Create, edit and share dashboards | ✅ | ✅ | ✅ |
| Create, edit and share views | ✅ | ✅ | ✅ |
| View check rules and failed checks | ✅ | ✅ | ✅ |
| Create check rules | ✅ | ✅ | ❌ |
| View synthetic checks | ✅ | ✅ | ✅ |
| Create synthetic checks | ✅ | ✅ | ❌ |
| View Agent0 automations | ✅ | ✅ | ✅ |
| Create Agent0 automations | ✅ | ✅ | ✅ |
| View notification channels and rules | ✅ | ✅ | ✅ |
| Create and edit notification rules | ✅ | ✅ | ❌ |
| Edit and delete dataset | ✅ | ❌ | ❌ |
| View datasets | ✅ | ✅ | ✅ |
| View endpoints | ✅ | ✅ | ✅ |
| View teams and members | ✅ | ✅ | ✅ |
Auth Tokens
Dash0 provides auth tokens that enable programmatic interaction with the platform. These tokens are essential to send data to Dash0 or to integrate Dash0 with other solutions and technologies, e.g., Grafana or Terraform.
Each token belongs to one organization. Admins create, view, and revoke tokens in Settings → Auth Tokens, and can restrict a token to specific datasets, specific signal types, and ingestion-only or read-only permissions. See Auth Tokens for each setting and for how Dash0 routes ingested telemetry to a dataset.
Further Reading
- About Organizations: Top-level entity grouping users, datasets, and billing
- About Teams: Organize members into groups with shared access
- Auth Tokens: Authenticate and authorize API access
- Datasets: Separate observability data by environment or purpose