On This Page

Home / Identity and Access Management/ Access Control/ Permissions Model/Permissions

Permissions ​

Use Permissions to define and manage fine-grained access control across Cribl products and resources.


Cribl’s Permissions model provides fine-grained access control from the entire deployment down to individual resources.

Permissions are defined sets of access rights that you assign to Members and Teams. Members also inherit Permissions on lower-level objects like products and Worker Groups from the Permissions they are assigned on higher-level objects like Organizations and Workspaces.

Cribl.Cloud supports only the Permissions model. On-prem deployments support both the Permissions model and the legacy Roles and Policies model. Read more about when to use each access control model.

Quick Reference for Permissions ​

The following table summarizes each Permission and the objects it is available for. For details on specific access rights that each Permission grants for each object, refer to the linked sections within the table.

PermissionDescription
Object-Level Availability
OwnerBroadest access for Organizations and Workspaces in Cribl.Cloud. Includes all Admin access, plus exclusive access to actions like deleting Organizations.Organizations (Cribl.Cloud)
Workspaces (Cribl.Cloud)
AdminBroad access to manage settings and configurations (and Members if assigned at the Organization level), without access that is exclusive to the Owner at the Organization level.Organizations (Cribl.Cloud)
Global (on-prem)
Workspaces (Cribl.Cloud)
Products
Worker Groups/Edge Fleets
Billing ReaderLimited access to the Organization to view billing information only. Does not confer any Permissions on lower-level objects (Workspaces, products, Worker Groups and Edge Fleets, and resources).Organizations (Cribl.Cloud)
IAM AdminLimited access to manage Organization Members and SSO settings only. Does not confer any Permissions on lower-level objects (Workspaces, products, Worker Groups and Edge Fleets, and resources).Organizations (Cribl.Cloud)
User/MemberBasic login access with no automatic Permissions on lower-level objects. Serves as a flexible starting point, but Owners or Admins must manually assign specific Permissions on lower-level objects.Organizations (Cribl.Cloud)
Global (on-prem)
Workspaces (Cribl.Cloud)
Cribl Stream and Edge
Cribl Search
Worker Groups/Edge Fleets
MaintainerLimited access to manage and modify resources and configurations within a Worker Group/Edge Fleet or product, without administrative access to manage Members or Global Settings.Stream Projects
Search Dataset Providers and Datasets
Search Dashboards
Search Notebooks
EditorLimited access to create, modify, and delete most resources and configurations, without access to modify Members or Global Settings.Cribl Stream and Edge
Cribl Search
Worker Groups/Edge Fleets
Stream Projects
CollectLimited access to run collection jobs on a Worker Group or Edge Fleet, without access to modify configurations or resources or perform administrative tasks.Worker Groups/Edge Fleets
Read OnlyLimited access to view Members, Groups, settings, Leader commits, and monitoring pages. Does not allow configuration changes or administrative actions.Cribl Stream and Edge
Cribl Search
Worker Groups/Edge Fleets
Stream Projects
Search Dataset Providers and Datasets
Search Dashboards
Search Notebooks

No Access Permission ​

The No Access Permission is available for all objects except Organizations. No Access explicitly blocks all access for a Member on the object and all lower-level objects. This allows you to enforce least privilege and ensure that only explicitly assigned Members have access.

By default, when you invite a new Member, they receive the User Permission at the Organization level (Cribl.Cloud) or at the Global level (on-prem). If you do not grant any Permissions on lower-level objects, the Member can log in but has the No Access Permission by default on all lower-level objects (Workspaces, products, Worker Groups/Edge Fleets, and resources). You must explicitly assign Permissions to the Member on lower-level objects to allow access.

No Permissions on lower-level objects are inherited from the No Access Permission. In addition, unless an Owner or Admin changes a Member’s No Access Permission on the Organization (Cribl.Cloud) or Global level (on-prem), they cannot assign the Member any Permissions on lower-level objects.

User Permission ​

User is the most flexible Permission. When a Member has the User Permission on an object, you can assign them any available Permission on the next lower-level object. This makes User ideal for Members who need varying access across different Products or Worker Groups and Edge Fleets.

For example, in Cribl.Cloud, if a Member has the User Permission at the Organization level, you can assign them the Member Permission at the Workspace level. This in turn allows you to assign the Member any of the available Permissions on individual Cribl products. If you assign the User Permission on Cribl Stream (that is, at the product level), you can then assign the Member any of the available Permissions on individual Worker Groups.

Exception: Members cannot be assigned the Maintainer Permission on Cribl Stream Projects if they have the User Permission on the Organization, Product, or Worker Group/Edge Fleet or the Member Permission on the Workspace. The Maintainer Permission on Cribl Stream Projects requires Admin or Editor on higher-level objects.

Initial Permissions ​

On Cribl.Cloud, the first user to deploy Cribl is assigned the Admin Permission on the Organization.

In on-prem Distributed deployments at the correct plan/license tier, the first user to deploy Cribl is assigned the Admin Permission at the Global level.

With the Admin Permission, you can assign Permissions to other Members and Teams.

In on-prem Single-instance deployments and Distributed deployments at other license tiers, Cribl bypasses the Permissions model and assigns all users implicit Admin Permissions.

Organization Permissions (Cribl.Cloud) ​

Organizations and Organization-level Permissions are available only on Cribl.Cloud. In on-prem deployments, use Global Permissions to manage access at the deployment level.

The following table describes the access that you can grant on Organizations for each Permission:

Access DescriptionUserIAM AdminBilling ReaderAdminOwner
Log into the system✓✓✓✓✓
View the credit consumption dashboards in the FinOps Center✓✓✓
Update own Member profile✓✓✓✓
View Worker Groups/Edge Fleets and resources to which you have access✓✓✓✓
View, invite, update, and delete Organization Members✓✓✓
View and modify SSO settings✓✓✓
Manage Connected Environments✓✓✓
View and modify Global Settings✓✓
Download invoices✓✓
Manage access control lists✓✓
Manage API Credentials✓✓
View and execute Leader commits✓✓
View, provision, update, and delete Worker Groups/Edge Fleets✓✓
Create and manage secret stores, secret folders, and global secrets✓✓
Reload secret folders✓✓
View data Sources and trust policies✓✓
Create and delete Lakehouses✓✓
Link and unlink Lakehouses with Datasets✓✓
View Organization details✓✓
Send Cloud Identity event logs to Cribl Stream✓✓
Download Cloud Identity event logs✓
Update Organization details✓
Add and delete Workspaces✓✓
Delete Organization✓

Inheritance for Organization Permissions ​

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Organization Permissions on Cribl.Cloud:

Owner or Admin on Organization
└── Admin on Workspaces
    └── Admin on Cribl Stream and Edge
        └── Admin on Worker Groups and Edge Fleets
            └── Maintainer on Resources
    └── Admin on Cribl Search and Lake
        └── Maintainer on Resources

Billing Reader on Organization
└── No access on lower-level objects

IAM Admin on Organization
└── No access on lower-level objects

User on Organization
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Global Permissions (On-Prem) ​

Global Permissions in on-prem deployments describe access rights at the deployment level, similar to Organization Permissions on Cribl.Cloud.

The following table describes the access that each Global Permission grants in on-prem deployments:

Access DescriptionUserAdmin
Log into the system✓✓
Create, view, update, and delete all Members✓
Create and manage secret stores, secret folders, and global secrets✓
Reload secret folders✓

Inheritance for Global Permissions (On-Prem) ​

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their on-prem Global Permissions:

Admin on Global
└── Admin on Products
    └── Editor on Worker Groups and Edge Fleets
        └── Maintainer on Resources

User on Global
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Workspace Permissions (Cribl.Cloud) ​

The following table describes the access that you can grant on Workspaces for each Permission:

Access DescriptionMemberAdminOwner
Log into the system✓✓✓
View Workspace Members✓✓
View Workspace details✓✓
Create and manage secret stores, secret folders, and global secrets✓✓
Reload secret folders✓✓
View default data Sources and trust policies✓✓
View and manage access control lists✓✓

When using the Cribl management plane API or SDK to create new API Credentials, the user Role on Workspaces is equivalent to Member.

Users must have the Owner, Admin, or IAM Admin Permission on the Organization to invite, update, or delete Members. Even Members with the Admin or Owner Permission on a Workspace in Cribl.Cloud must also have Owner, Admin, or IAM Admin on the Organization to invite, update, or delete Members.

If you have multiple Workspaces on Cribl.Cloud, you can manage Permissions independently for each of them. Permissions are scoped to each Workspace and do not carry over to other Workspaces. For example, a user can be an Admin in Workspace A and a Member in Workspace B. This allows granular control over segmented environments within your Organization (such as production, staging, and dev).

Inheritance for Workspace Permissions (Cribl.Cloud) ​

The Permission a Member has on the Organization automatically determines their Permissions on Workspaces as follows:

Organization   ──►   Workspace
------------         ---------
Owner          ──►   Admin
Admin          ──►   Admin
Billing Reader ──►   No Access
IAM Admin      ──►   No Access
User           ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Workspace Permissions on Cribl.Cloud:

Owner or Admin on Workspace (Cribl.Cloud)
└── Admin on Cribl Stream and Edge
    └── Admin on Worker Groups and Edge Fleets
        └── Maintainer on Resources
└── Admin on Cribl Search and Lake
    └── Maintainer on Resources

Member on Workspace (Cribl.Cloud)
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Product Permissions ​

Product Permissions grant access to particular actions and resources in Cribl Stream, Edge, Search, and Lake. Each product has different Permissions.

Cribl Stream and Edge Permissions ​

The following table describes the access that you can grant on Cribl Stream and Edge:

Access DescriptionUserRead OnlyEditorAdmin
Log in to the system✓✓✓✓
View Members, Worker Groups/Edge Fleets, settings, Leader commits, and legacy Local Users and Roles✓✓✓
View all Worker Groups/Edge Fleets✓✓
View all Monitoring pages✓✓
Add, update, restart Worker Groups/Edge Fleets✓
Create, view, update, and delete all Worker Groups/Edge Fleets and resources✓
Manage Worker Group/Edge Fleet Mappings✓
Create and manage secret folders and global secrets✓
Reload secret folders✓
Manage Notifications and Notification Targets✓

Inheritance for Cribl Stream and Edge Permissions ​

The Permissions a Member has on the Organization and Workspace (Cribl.Cloud) or at the Global level (on-prem) automatically determine their Permission on Cribl Stream and Edge as follows:

Cribl.Cloud:
Organization   +   Workspace   ──►   Cribl Stream and Edge
------------       ---------         ---------------------
Owner          +   Admin       ──►   Admin
Admin          +   Admin       ──►   Admin
Billing Reader +   No Access   ──►   No Access
IAM Admin      +   No Access   ──►   No Access
User           +   Owner       ──►   Admin
User           +   Admin       ──►   Admin
User           +   Member      ──►   No Access (configurable)

On-Prem:
Global   ──►   Cribl Stream and Edge
------         ---------------------
Admin    ──►   Admin
User     ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Cribl Stream and Edge Permissions:

Admin on Cribl Stream and Edge
└── Admin on Worker Groups and Edge Fleets
    └── Maintainer on Cribl Stream and Edge Resources

Editor on Cribl Stream and Edge
└── Editor on Worker Groups and Edge Fleets
    └── Maintainer on Cribl Stream and Edge Resources

Read Only on Cribl Stream and Edge
└── Read Only on Worker Groups and Edge Fleets
    └── Read Only on Cribl Stream and Edge Resources

User on Cribl Stream and Edge
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Cribl Search Permissions ​

The following table describes the access that you can grant on Cribl Search.

For details on individual Datasets, Dataset Providers, Dashboards, and Notebooks, see the resource Permissions.

For details on specific operators, functions, and commands, see the Cribl Search Language Reference (for example, send).

Access DescriptionUserEditorAdmin
Add and resize lakehouse engines✓
Resize the federated engine✓
Add new Datasets and Dataset Providers✓✓
Access existing Datasets or Dataset ProvidersOnly if sharedOwn or shared✓
Add or modify Datatype rules and Dataset rules✓✓
Add new Dashboards and Notebooks✓✓✓
Access existing Dashboards or NotebooksOnly if sharedOwn or shared✓
See search historyOwn or sharedOwn or shared✓
View, add, and modify lookups, Parsers, regexes,
Grok patterns, saved or scheduled searches, and custom Datatypes
✓✓✓
View, add, use, import, modify, and export Packs✓✓
Export results (export operator)Only to lookups✓✓
Manage Members, usage groups and limits✓

Inheritance for Cribl Search Permissions ​

The Permissions a Member has on the Organization and Workspace automatically determine their Permission on Cribl Search as follows:

Organization   +   Workspace   ──►   Cribl Search
------------       ---------         ------------
Owner          +   Admin       ──►   Admin
Admin          +   Admin       ──►   Admin
Billing Reader +   No Access   ──►   No Access
IAM Admin      +   No Access   ──►   No Access
User           +   Owner       ──►   Admin
User           +   Admin       ──►   Admin
User           +   Member      ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Cribl Search Permissions:

Admin on Cribl Search
└── Maintainer on Cribl Search Resources

Editor on Cribl Search
└── No inherited Permissions on Cribl Search Resources

User on Cribl Search
└── No inherited Permissions on Cribl Search Resources

Members with the Editor and User Permissions on Cribl Search do not inherit Permissions on Cribl Search Resources. Instead, they gain resource-level Permissions on the individual resources that they create or when another Member shares a resource with them. See the resource-level sections for Dataset Providers and Datasets, Dashboards, and Notebooks for details.

Cribl Lake Permissions ​

The following table describes the access that you can grant on Cribl Lake:

Access DescriptionRead OnlyEditorAdmin
Read Lake Datasets✓✓✓
Read Lakehouses✓✓✓
Search a Lake Dataset directly from the Dataset table

Also requires User, Editor, or Admin on Cribl Search and Read Only or Maintainer on the Cribl Search Dataset
✓✓✓
View the Connected to column in the Dataset table, which lists the Cribl Lake Collectors and Destinations that each Lake Dataset is connected with

Also requires Read Only, Editor, or Admin on Cribl Stream
✓✓✓
Create and edit Lake Datasets✓✓
Delete Lake Datasets✓
Create and delete Lakehouses✓
Assign and unassign Lake Datasets to Lakehouses✓

Inheritance for Cribl Lake Permissions ​

The Permissions a Member has on the Organization and Workspace automatically determine their Permission on Cribl Lake as follows:

Organization   +   Workspace   ──►   Cribl Lake
------------       ---------         ----------
Owner          +   Admin       ──►   Admin
Admin          +   Admin       ──►   Admin
Billing Reader +   No Access   ──►   No Access
IAM Admin      +   No Access   ──►   No Access
User           +   Owner       ──►   Admin
User           +   Admin       ──►   Admin
User           +   Member      ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Cribl Lake Permissions:

Admin on Cribl Lake
└── Maintainer on Cribl Lake Resources

Editor on Cribl Lake
└── Maintainer on Cribl Lake Resources

Read Only on Cribl Lake
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Worker Group and Edge Fleet Permissions ​

The following table describes the access that you can grant on Worker Groups and Edge Fleets:

Access DescriptionUserRead OnlyCollectEditorAdmin
Be assigned to resources within the Worker Group/Edge Fleet✓✓✓✓
View all Worker Group/Edge Fleet Settings, encryption keys, certificates, secrets, scripts.✓✓✓
View all Sources, Destinations, Pipelines, Packs, Apps, Routes, QuickConnect connections, Knowledge Objects, Notifications, and Notification Targets✓✓✓
View all Edge Subfleets and their Settings, and Stream Projects and Subscriptions✓✓✓
Run Collection jobs on the Worker Group/Edge Fleet✓✓✓
Create, view, update, and delete all Worker Group/Edge Fleet encryption keys, certificates, secrets, scripts, Sources, Destinations, Pipelines, Packs, Apps, Routes, QuickConnect connections, Knowledge Objects, and Notifications and Notification targets✓✓
Commit configuration changes✓✓
Create, view, update, and delete all Worker Group/Edge Fleet access management (Members’ Permissions), Settings, encryption keys, key management system (KMS) settings, certificates, secrets, scripts✓
Create, view, update, and delete all Sources, Destinations, Pipelines, Packs, Apps, Routes, QuickConnect connections, Knowledge Objects, Notifications and Notification targets, Stream Projects/Subscriptions, and can run tests on Sources and Destinations✓
Restart Worker/Edge Nodes✓
Update Edge Nodes✓
(Fleet admin only)
Commit and deploy configuration changes✓
On Edge, CRUD capabilities on Subfleet Settings and access management identical to those on the parent Fleet✓

Inheritance for Worker Group and Edge Fleet Permissions ​

The Permissions a Member has on the Workspace and products (Cribl.Cloud) or at the Global level and on products (on-prem) automatically determine their Permission on Worker Groups and Edge Fleets as follows:

Cribl.Cloud:
Workspace   +   Cribl Stream and Edge   ──►   Worker Group/Edge Fleet
---------       ---------------------         -----------------------
Owner       +   Admin                   ──►   Admin
Admin       +   Admin                   ──►   Admin
Member      +   Admin                   ──►   Admin
Member      +   Editor                  ──►   Editor
Member      +   Read Only               ──►   Read Only
Member      +   User                    ──►   No Access (configurable)

On-Prem:
Global   +   Cribl Stream and Edge   ──►   Worker Group/Edge Fleet
------       ---------------------         -----------------------
Admin    +   Admin                   ──►   Admin
User     +   Admin                   ──►   Admin
User     +   Editor                  ──►   Editor
User     +   Read Only               ──►   Read Only
User     +   User                    ──►   No Access (configurable)

The following diagram depicts the Permissions that Members automatically inherit on lower-level objects based on their Worker Group/Edge Fleet Permissions:

Admin on a Worker Group or Edge Fleet
└── Maintainer on Resources

Editor on a Worker Group or Edge Fleet
└── Maintainer on Resources

Collect on a Worker Group or Edge Fleet
└── No access on lower-level objects

Read Only on a Worker Group or Edge Fleet
└── Read Only on Resources

User on a Worker Group or Edge Fleet
└── No inherited Permissions on lower-level objects; Permissions must be assigned

Resource Permissions ​

Certain Cribl products provide Permission-based access to particular resources.

Stream Projects ​

You must use the Permissions model to manage access to Stream Projects and Subscriptions. Cribl does not support the legacy Roles and Policies model for Stream Projects.

The following table describes the access that you can share on Stream Projects for each Permission:

Access DescriptionRead OnlyEditorMaintainer
View Project and Subscription settings and connections among the Project’s Subscriptions, Packs, and Destinations✓✓✓
Configure connections among the Project’s Subscriptions, Packs, and Destinations✓✓
Create, modify, and delete Pipelines within the Project✓✓
Modify Project settings✓
Delete the Project✓

Inheritance for Stream Projects ​

The Permissions a Member has on higher-level objects automatically determine their Permission on Stream Projects as follows:

Cribl.Cloud:
Organization   +   Workspace   +   Cribl Stream/Edge   ──►   Stream Projects
------------       ---------       -----------------         ---------------
Owner          +   Admin       +   Admin               ──►   Maintainer
Admin          +   Admin       +   Admin               ──►   Maintainer
Billing Reader +   No Access   +   No Access           ──►   No Access
IAM Admin      +   No Access   +   No Access           ──►   No Access
User           +   Owner       +   Admin               ──►   Editor
User           +   Admin       +   Admin               ──►   Editor
User           +   Member      +   Admin               ──►   Editor
User           +   Member      +   Editor              ──►   Editor
User           +   Member      +   Read Only           ──►   Read Only
User           +   Member      +   User                ──►   No Access (configurable)

On-Prem:
Global   +   Cribl Stream/Edge   +   Worker Group/Fleet   ──►   Stream Projects
------       -----------------       ------------------         ---------------
Admin    +   Admin               +   Admin                ──►   Maintainer
User     +   Admin               +   Admin                ──►   Editor
User     +   Admin               +   Editor               ──►   Editor
User     +   Admin               +   Collect              ──►   No Access
User     +   Admin               +   Read Only            ──►   Read Only
User     +   Editor              +   Editor               ──►   Editor
User     +   Editor              +   Collect              ──►   No Access
User     +   Editor              +   Read Only            ──►   Read Only
User     +   Read Only           +   Read Only            ──►   Read Only
User     +   User                +   Collect              ──►   No Access
User     +   User                +   User                 ──►   No Access (configurable)

The Maintainer Permission on Stream Projects is not available for Members who have the User Permission on any higher-level object.

Cribl Search Dataset Providers and Datasets ​

The following table describes the access that you can share on individual Dataset Providers and Datasets (both Cribl-hosted and federated).

Access DescriptionRead OnlyMaintainer
View the Dataset Provider/Dataset configuration and settings✓✓
Search and export the Dataset✓✓
Modify and delete the Dataset Provider/Dataset✓
Assign Datatypes✓
Share and revoke access to the Dataset Provider/Dataset for Members and Teams✓
Unhide Dataset Provider credentialsSearch Admin onlySearch Admin only

The Member who creates a Dataset Provider or Dataset becomes its Maintainer by default.

Inheritance for Cribl Search Dataset Providers and Datasets Permissions ​

The Permissions a Member has on higher-level objects automatically determine their Permission on Cribl Search Dataset Providers and Datasets as follows:

Organization   +  Workspace  +  Cribl Search   ──►   Dataset Providers/Datasets
------------      ---------     ------------         --------------------------
Owner          +  Admin      +  Admin          ──►   Maintainer
Admin          +  Admin      +  Admin          ──►   Maintainer
Billing Reader +  No Access  +  No Access      ──►   No Access
IAM Admin      +  No Access  +  No Access      ──►   No Access
User           +  Owner      +  Admin          ──►   Maintainer
User           +  Admin      +  Admin          ──►   Maintainer
User           +  Member     +  Admin          ──►   Maintainer
User           +  Member     +  Editor         ──►   No Access (configurable)
User           +  Member     +  User           ──►   No Access (configurable)

Cribl Search Dashboards ​

The following table describes the access that you can share on individual Search Dashboards.

Access DescriptionRead OnlyMaintainer
View the Dashboard and settings✓✓
View the Dashboard’s queries and widgets✓✓
Export and forward data from the Dashboard✓✓
Export and forward data from Dashboard widgets

Also requires Read Only or Maintainer on the Cribl Search Dataset
✓✓
Clone the Dashboard✓✓
Create, modify, and delete a Dashboard✓
Edit the Dashboard’s queries and widgets✓
Share and revoke access to the Dashboard for Members and Teams✓

The Member who creates a Dashboard becomes its Maintainer by default.

Inheritance for Cribl Search Dashboards Permissions ​

The Permissions a Member has on higher-level objects automatically determine their Permission on Cribl Search Dashboards as follows:

Organization   +  Workspace  +  Cribl Search   ──►   Dashboards
------------      ---------     ------------         ----------
Owner          +  Admin      +  Admin          ──►   Maintainer
Admin          +  Admin      +  Admin          ──►   Maintainer
Billing Reader +  No Access  +  No Access      ──►   No Access
IAM Admin      +  No Access  +  No Access      ──►   No Access
User           +  Owner      +  Admin          ──►   Maintainer
User           +  Admin      +  Admin          ──►   Maintainer
User           +  Member     +  Admin          ──►   Maintainer
User           +  Member     +  Editor         ──►   No Access (configurable)
User           +  Member     +  User           ──►   No Access (configurable)

Cribl Search Notebooks ​

The following table describes the access that you can share on Search Notebooks.

Access DescriptionRead OnlyMaintainer
View the Notebook✓✓
View Results✓✓
Export Results✓✓
Open in Cribl Search✓✓
Create Notebooks✓
Share Notebooks✓
Lock or unlock Notebooks✓
Delete Notebooks✓
Rerun cells✓
Add cells✓
Edit cells✓
Delete cells✓

The Member who creates a Notebook becomes its Maintainer by default.

Inheritance for Cribl Search Notebooks ​

The Permissions a Member has on higher-level objects automatically determine their Permission on Cribl Search Notebooks as follows:

Organization   +  Workspace  +  Cribl Search   ──►   Notebooks
------------      ---------     ------------         ---------
Owner          +  Admin      +  Admin          ──►   Maintainer
Admin          +  Admin      +  Admin          ──►   Maintainer
Billing Reader +  No Access  +  No Access      ──►   No Access
IAM Admin      +  No Access  +  No Access      ──►   No Access
User           +  Owner      +  Admin          ──►   Maintainer
User           +  Admin      +  Admin          ──►   Maintainer
User           +  Member     +  Admin          ──►   Maintainer
User           +  Member     +  Editor         ──►   No Access (configurable)
User           +  Member     +  User           ──►   No Access (configurable)

Cribl Search Editors and Users have No Access on existing Notebooks by default. Other Members can share Notebooks that they have the Maintainer Permission on, assigning either the Read Only or Maintainer Permission on each Notebook to each Member they share it with.