Skip to main content
Bring your team and maximize your impact at Dreamforce. Register three or more to unlock $999 passes.

Identify User Roles in Master Data Management SaaS

Learning Objectives

After completing this unit, you’ll be able to:

  • Identify the predefined user roles available in Business 360 Console, Customer 360, Product 360, and Supplier 360.
  • Describe the tasks and permissions associated with each key role.

User and User Roles in MDM SaaS

You’ve just joined GlobalRetail, Inc. as its new Informatica Intelligent Data Management Cloud (IDMC) business user. Your first task is to set up Informatica MDM SaaS so the team can get to work. But before you can hand out access, you need to answer a critical question—who gets to do what?

If you give too much access, users might accidentally overwrite data models or delete records. If you give too little, data stewards can’t do their jobs. The key is to assign the right predefined user role to each team member—to match their responsibilities to exactly the access they need.

A user is an individual account in IDMC. Customer 360 and Business 360 Console users must have IDMC user accounts. You can create and manage users in the IDMC Administrator service.

A user role is a collection of privileges that you assign to users to allow access to Customer 360 and Business 360 Console.

In this unit, you learn about the predefined user roles available across Business 360 Console, Customer 360, Product 360, and Supplier 360, and what each role allows users to do.

Predefined User Roles in MDM SaaS

MDM SaaS comes with a set of predefined user roles. You can’t edit, rename, delete, or customize predefined user roles. But you can assign them to individual users or user groups based on what each person needs to accomplish. Roles are organized by application. Review what’s available in each.

Console Roles in Business 360

Before you configure your MDM SaaS system in Business 360 Console, it’s important to know who can do what. Familiarity with predefined user roles helps you assign the right access to the right people from the start.

  • Admin: Grants complete administrative authority within the Business 360 Console, which enables users to execute critical solution upgrades
  • Designer: Allows users to perform tasks in Business 360 Console that require integration with other services such as Data Integration and Data Quality
  • MDM Designer: Allows users to create MDM SaaS assets and delete custom assets
  • Business 360 Process Executor: Required role for users with custom user roles to perform tasks in Business 360 Console and business applications, and allows users to update business entities in Business 360 Console
  • Job Executor: Allows users to run ingress and egress jobs in Business 360 Console

Predefined Roles in Customer 360

To complete specific activities in the Customer 360 app, users must be assigned one of the following four predefined roles.

Predefined Role

Permitted Tasks and Responsibilities

Customer 360 Analyst

This role creates, modifies, and removes records. These actions initiate a review workflow necessitating approval from a manager. Analysts can also generate reports.

Customer 360 Manager

This role possesses the authority to create, edit, and delete records directly without external approval. Managers also manage the review process by approving or rejecting submissions, assigning unowned tasks, and creating reports.

Customer 360 Data Steward

This role is authorized to create, edit, and delete records without oversight. Data stewards review and approve records, execute jobs, and build reports.

MDM Business User

This role is granted read-only privileges in Customer 360. Business users can inspect records but are restricted from any creating or editing data.

Predefined Roles in Product 360

You might assign Product 360 users one of two specific roles depending on their level of responsibility.

Assigned Role

Permissions and Responsibilities

Product 360 Manager

This role has full authority to create, update, or remove records independently. This role manages workflows by approving or denying records and distributing unassigned review tasks. Managers also manage reports and product relationships and hierarchies.

Product 360 Read-Only

This role provides restricted access for viewing purposes only. These users can explore hierarchies and product data, but aren’t permitted to create, modify, or delete any records.

Predefined Roles in Supplier 360

To support comprehensive supplier lifecycle management, Supplier 360 features five specialized roles. These roles range from day-to-day data maintenance to high-level credit and risk assessment.

Supplier 360 Role

Permitted Tasks and Responsibilities

Supplier 360 Analyst

This role generates reports and manages records by creating, editing, or deleting them. Any data modifications automatically trigger a review workflow that requires a manager’s sign-off.

Supplier 360 Data Steward

This role manages the full record lifecycle (create, edit, delete) independently. This role handles merging and unmerging, record matching, job execution, report creation, and the assignment of unclaimed review tasks.

Supplier 360 Task Admin

This role manages evaluation tasks according to business event settings. It holds originator and approver privileges and can perform all standard record operations (create, read, edit, delete).

Supplier 360 Risk Manager

This role focuses on risk evaluation by claiming, releasing, and acting on related tasks. This role includes both originator and approver privileges.

Supplier 360 Credit Manager

This role handles credit evaluation tasks, with the authority to claim, release, and process them as both an originator and an approver.

Note

Important Detail

Standard predefined roles omit reporting privileges by default. To allow users to create or modify reports, you must manually grant the required asset permissions within the administrator service.

Role Assignment Tips

Keep these tips in mind when assigning roles.

  • Follow the principle of least privilege: Assign only the access each user needs to do their job. For example, avoid assigning the admin role to a user unless they have a genuine business need for that level of access.
  • Combine roles in Business 360 Console carefully: To give a user full access, assign them the admin, designer, and MDM designer roles. For configuration-only access, assign them designer and MDM designer roles.
  • Assign roles in Administrator: All role assignments happen through the IDMC Administrator service—not within the MDM SaaS applications themselves.

Back to the GlobalRetail, Inc. company scenario—now you’re ready to assign access with confidence. Your data stewards get the data steward role, your analysts get the analyst role, and your configuration team gets the designer and MDM designer roles in Business 360 Console. Everyone can do exactly what they need—no more, no less. You know which predefined user roles are available in MDM SaaS apps and how to assign them, and you’re ready to set up secure, well-governed access for your team.

Resources

Share your Trailhead feedback over on Salesforce Help.

We'd love to hear about your experience with Trailhead - you can now access the new feedback form anytime from the Salesforce Help site.

Learn More Continue to Share Feedback