Viewer
Read-only access to team jobs and state.
Data Convoy separates viewing, safe copying, production deletion, paid retrieval, team administration, and bucket redirection into explicit permissions.
The four fixed roles are backed by a permission matrix that site administrators can edit.
Read-only access to team jobs and state.
Dry runs, scheduled work, and archive/backup copies that leave production intact.
Destructive jobs plus member and worker management; no bucket repointing.
Full team control, including buckets, roles, ownership transfer, and deletion.
APIs compute permissions from the requested operation and enforce them server-side. User-to-role mappings are not TTL-cached, so removing a role immediately changes claim and request authorization.