System Roles Permission
The System Roles Permission report page presents the visuals listed below. Each row gives the on-screen name, its underlying metric, and a short description; see the metric glossary for the full formula and interpretation.
Visuals:
| Name | Measure | Description |
|---|---|---|
| Role assignment | List of analytics users with their user ID, full name, email, and assigned analytics roles | One row per analytics user, listing the security roles each account is granted in the app. It is a reference table for auditing who holds which access, not a computed metric. Read against your role policy to confirm assignments are correct. Keyed by user (Analytics User ID), so it reflects application accounts, not workers. |
| Users with global access | List of users whose data access is unrestricted, with worker ID, full name, and email | Users who can see data for the whole organization, with no row-level restriction applied. It identifies the accounts with the broadest visibility. Read against Users with restricted access for how the population splits by access scope. |
| Users with restricted access | List of users whose data access is limited to a defined scope, with worker ID, full name, and email | Users whose view is confined by row-level security to a subset of the organization, such as their own team or org unit. It identifies the accounts with limited visibility. Read against Users with global access for how the population splits by access scope. |
| Total number of workers | Count of distinct worker instances | Number of distinct workers who make up the population in view, i.e. the full headcount. It includes everyone with a worker record, managers among them, so it overlaps with # Managers rather than complementing it (managers are a subset of workers, not a separate group). It is also a different population from # Active users : workers are counted from the worker/employment records, whereas active users are provisioned application accounts, and the two do not always line up. |
| Total number of users in table | Count of users listed in the Role assignment table | Number of user accounts shown in the Role assignment table for the current selection. It is a live tally of that table's rows, so it moves with any filter applied. Read against Users with global access and Users with restricted access to see how those accounts break down by scope. |
| Total active users | Count of worker IDs | Number of users in scope, used as the denominator for the adoption percentages (for example % users having plans ). It sets the "out of how many people" baseline, so every share on the page is read against it. Filtering to a team or org unit re-bases it to that population. |
| Last data refresh | Timestamp of the most recent successful data refresh | Shows when the report data was last refreshed, so readers know how current every figure on the page is. It is a freshness stamp, not a business metric. Read against your expected refresh schedule to spot stale data. |