Skip to main content

Manage Permissions Within a Clean Room

Within each clean room, owners and partners can determine which permissions apply to different user roles and assign permissions to roles.

Note

Understanding Permissions Within a Clean Room

Permissions within a clean room are managed at the partner and role levels:

  • Partner level: Clean room owners define which clean room permissions are available to their partners to assign.

  • Role level: Clean room managers can create custom user roles based on the available clean room permissions or assign org-level clean room roles to user groups.

    Note

    The clean room owner’s allowed permissions override the permissions assigned through user groups. For example, your clean room administrator might create a "Data Manager" role with the "Manage Datasets" permission for a user group, and add that group to a clean room. If the clean room owner has not granted your organization the "Manage Datasets" permission, the user group's role will exclude that permission.

    For information on organization level clean room roles, see "Managing LiveRamp Clean Room User Roles".

For example, a clean room manager could create an "Analyst" role with permissions to view reports and dashboards and a "Manager" role with permissions to configure datasets and manage users.

Default clean room permissions:

Product Area

Access Level

Description

Clean Room Management

Manage Clean Room Roles

Create, edit, and assign roles that govern member access within the clean room.

Partner Management (Owner Only)

Invite, configure, and remove clean room partners.

Questions

Create & Edit Questions

Create new questions and edit existing question definitions.

View Questions

View questions in the clean room and their basic details.

Delete Questions

Remove questions from the clean room.

Manage Questions

Provision org-level questions to the clean room and manage question permissions and settings.

Datasets

Assign Datasets

Assign datasets to questions and flows in the clean room, allowing runs to be created.

Manage Datasets

Provision, deprovision, and configure rules and settings for datasets.

Reports

Create & Delete Question Runs

Run questions and delete the resulting question runs.

View Reports

View question run results and reports.

Create or Modify and Delete Question Schedules

Create, modify, and delete schedules for recurring question runs.

Flows

Flows Builder (Private Preview)

Build and configure flows using the flow builder.

Create, Schedule, and Delete Flow Runs

Create, schedule, and delete flow runs.

View-only Flows

View flows and their run results without editing.

Activation

LiveRamp Activation Admin

Administer LiveRamp activation settings and destinations.

Intelligence

Habu Intelligence Viewer

View Intelligence dashboards and insights.

Note

  • Clean room owner must toggle on Intelligence as a feature for their clean room

  • Insufficient for downloading large result sets not otherwise accessible through core LiveRamp Clean Room UI

Habu Intelligence Creator

Create and edit Intelligence dashboards and insights.

Note

  • Clean room owner must toggle on Intelligence as a feature for this clean room

  • Required for downloading large result sets( via "Browse Data") not otherwise accessible through core LiveRamp Clean Room UI

Permission Available to Clean Room Owners

To access and manage clean room permissions:

Navigate to a clean room and select Clean Room Access from the left navigation pane.

CR_Access_Owner1.png

As a clean room owner, you can navigate between the following tabs:

  • Your Organization: Manage clean room access for users or groups from your organization.

  • Roles: Manage roles for this clean room and define enabled permissions for partners.

  • Partner Access: Invite partners to the clean room and view clean room invitation statuses.

Manage Available Permissions for Partners

Account admins who own a clean room and have "Partner Management" enabled in their clean room permissions can define which clean room permissions are made available to their partners for clean room roles. Roles are assigned to individual users and define what those users are able to access within a specific clean room.

When a clean room owner invites a partner to the clean room, the user who accepts the invitation will be assigned the Partner Administrator role, which provides access to all available permissions.

When a partner is added to a clean room, their default available permissions are:

  • Manage Clean Room Roles

  • Create & Delete Question Runs

  • View Reports

  • Create or Modify and Delete Question Schedules

  • Intelligence Viewer (if available to the Owner)

Procedure. To update partner-level clean room permissions:
  1. From the Partner Access tab, click the More Options menu (more-options-icon.png) of a partner organization and select "Manage Permissions".

  2. Toggle any permissions that the given partner organization should be able to use to define Clean Room roles. Select Save.

Manage Clean Room Roles

Clean room managers can create and edit roles.

By default, each clean room includes the following roles:

  • Partner Administrator: This role provides access to all clean room-level permissions made available by the owner.

  • Partner Viewer: This role enables users to view reports and Intelligence.

If you are a clean room manager, you will be able to create and modify roles based on specific permissions enabled by the account admin. If a permission is not available that you would like to add to a role definition, contact your account administrator.

Procedure. To manage roles:
  1. From the Roles tab of the Clean Room Access page, select Create a Role.

    CR_Access_Owner_createrole.png
  2. From the Partner Organization dropdown, select which organization you want to create the role for. Add a Role Name and slide the toggle for the permissions the role should enable for assigned users. Select Save Permissions. Repeat these steps for any newly created roles.

    Note

    If you're creating a role for a partner organization, you can only select permissions that have been enabled at a partner level.

  3. To modify an existing role, click the More Options menu (more-options-icon.png) of a given role and select "Edit".

    CR_Access_Owner_editroles.png
  4. Add or remove permissions and click Save Permissions.

Add Users or Groups to a Clean Room as Owners

You can add individual users or a group of users with the same role to a clean room. Adding a user group will grant multiple users of the same role access to the clean room. For more information on user groups, see "Managing Clean Room User Groups".

Procedure. To add a user or group to a clean room:
  1. From the Your Organization tab of the Clean Room Access page, click Add Users and Groups.

  2. Select the check box of the user or group you want to add. When adding individual users, you must select a role for each user via the "Roles" dropdown list.

    Click Add Users and Groups. The selected users or group members now have role-based access to the clean room.

    CR_Access_Owner_addusers.png
  3. To edit a user's role, click the More Options menu (more-options-icon.png) of a user and select "Edit Roles".

    You can only edit a group's role at the organization-level through the Roles & Groups page.

Permission Available to Clean Room Partners

To navigate to the Clean Room Access page, select Clean Room Access in the left-hand menu.

As a clean room partner user, you can navigate between the following tabs:

  • Users & Groups: Manage clean room access for users or groups from your organization.

  • Roles: Manage roles for your own users based on permissions enabled by the owner.

Create and Edit Clean Room Roles

To view, create, and edit existing clean room roles, select the Roles tab within the Clean Room Access page.

By default, each clean room includes the following roles:

  • Partner Administrator: This role provides access to all clean room-level permissions made available by the owner.

  • Partner Viewer: This role enables users to view reports and Intelligence.

Procedure. To add a new role:
  1. From the Roles tab, click Create Role.

  2. Enter a role name and select the permissions the role should enable for assigned users.

    Note

    Only permissions allowed by the owner will be visible.

    Screenshot_2026-07-21_at_17_11_12.png
  3. Click Save Permissions. Repeat these steps for any newly created roles.

  4. To modify an existing role, click the More Options menu (more-options-icon.png) of a given role and select "Edit".

  5. Add or remove permissions and then click Save Permissions.

Add Users or Groups to a Clean Room as Partners

The User & Groups tab allows clean room partners to add and remove users or groups from their organization and edit individual user roles.

Procedure. To add users who belong to your partner organization to the clean room:
  1. From the Users and Groups tab, click Add Users and Groups.

    Partner_AddUsertoCR.png
  2. Select the check box of the user or group you want to add. When adding individual users, you must select a role for each user via the "Roles" dropdown list.

    Click Add Users and Groups. The selected users or group members now have role-based access to the clean room.

  3. To edit a user's role, click the More Options menu (more-options-icon.png) of a user and select "Edit Roles".

    You can only edit a group's role at the organization-level through the Roles & Groups page.