Roles
The four Celiq roles โ Luminary, Weaver, Tracer, and Lens โ and what each one can see, build, and manage.
When to use it: Whenever you add a teammate or need to change someone's level of access โ viewers get read-only, builders get edit access, admins get everything.
Where to find it: Lumen โ Users (the role badge and the Change role menu sit next to each user).
Who can use it: Only a Luminary can assign or change roles. The Luminary role is auto-assigned to the workspace creator.
Celiq has four roles: Luminary, Weaver, Tracer, and Lens. Every user in a workspace has exactly one role, assigned by a Luminary. The role determines what a user can see, build, and manage across every part of the product.
Roles are ranked. A higher role can do everything a lower role can, plus more. In ascending order the ranking is Lens โ Tracer โ Weaver โ Luminary, so any permission granted to a Tracer is also available to a Weaver and a Luminary.
Overview
A role is the single most important access setting on a user. It is checked on every request: the backend confirms which role you hold and whether that role meets the minimum required for the action. If it does not, the action is refused before any data is touched.
The four roles, with the short description shown next to each user in Lumen โ Users:
| Role | Description | Rank |
|---|---|---|
| Luminary | Full admin + all features | 4 |
| Weaver | Build nodes and domains | 3 |
| Tracer | Query and analyse data | 2 |
| Lens | View-only access | 1 |
Because roles are ranked, many actions are gated by a minimum role rather than an exact one. For example, anything a Tracer can do is also available to Weavers and Luminaries.
When to use it
Set or change a role when you:
- Invite a new teammate โ pick the lowest role that still lets them do their job.
- Promote a builder โ move a trusted analyst from Tracer to Weaver so they can edit the semantic model.
- Hand off administration โ promote a second person to Luminary before you step down or go on leave.
- Lock down a stakeholder โ set executives or external viewers to Lens so they can read dashboards but cannot explore or query freely.
Concepts
| Term | What it means |
|---|---|
| Role | One of Luminary, Weaver, Tracer, or Lens. Each user has exactly one. |
| Role rank | A numeric level used to compare roles: Luminary 4, Weaver 3, Tracer 2, Lens 1. Higher ranks inherit everything below them. |
| Minimum role | The lowest rank allowed to perform an action. "Weaver and above" means Weavers and Luminaries pass; Tracers and Lens are refused. |
| Lumen | The admin area of Celiq, where Luminaries manage users, roles, and security. |
The four roles
Luminary
The Luminary is the workspace administrator โ full admin plus all features. There must be at least one Luminary in every workspace, and there is no upper limit on how many you can have.
Luminaries can:
- Manage the workspace, users, billing, and integrations from Lumen
- Assign and change every user's role
- Configure Data Keys and Data Gates
- Access all content in the workspace, regardless of vault membership
Weaver
The Weaver is a builder โ someone who builds nodes and domains. Weavers have deep access to the data model and can create and share content, but they cannot administer the workspace.
Weavers can do everything a Tracer can, plus:
- Edit the semantic model in Forge (Projects, with Build/Browse/Validate/Evals modes and the Check & Save gate)
- Build and share dashboards and content
Weavers cannot:
- Open Lumen or manage users
- Assign roles
- Configure Data Keys or Data Gates
A typical Weaver is a data engineer, analytics engineer, or senior analyst who owns part of the semantic model.
Tracer
The Tracer is the standard analyst โ someone who queries and analyses data. Most users in a Celiq workspace are Tracers.
Tracers can do everything a Lens can, plus:
- Run queries and explore data in Discover
- Save and organise their own content
- Use Orion to ask questions and get insights
Tracers cannot:
- Edit the semantic model in Forge
- Open Lumen or change any security setting
Lens
The Lens is a restricted viewer โ view-only access. Lens users are designed for stakeholders, executives, or external partners who need to read reports but should not explore or query freely.
Lens users can:
- View dashboards and content they have been explicitly given access to
Lens users cannot:
- Open Discover or run their own queries
- Save or create content
- Open Lumen or change any setting
Getting started
Prerequisites: you must be a Luminary. Only Luminaries can open Lumen and change roles. To open the roles view:- Open Lumen from the main navigation.
- Choose Users.
- Each user row shows a coloured role badge (Luminary, Weaver, Tracer, or Lens) and a Change role control.
Step-by-step
Open Lumen โ Users
From the main navigation, open Lumen, then choose Users. You see every user in the workspace with their current role badge.
Find the user
Locate the person whose role you want to change. Each row shows their name, email, and current role.
Open the Change role menu
On that user's row, open the Change role menu. It lists all four roles, each with its short description, and marks the current role with a checkmark.
Pick the new role
Select the new role. Celiq saves it immediately โ there is no separate Save button. Selecting the role the user already has simply closes the menu with no change.
Confirm it stuck
The role badge on the row updates to the new role. The change takes effect on the user's next request. If anything goes wrong, you see a message and the role is left unchanged โ see Troubleshooting below.
Examples
A new analyst joins and needs to explore data but should not edit the model. Invite them as a Tracer. Later, they take ownership of the orders domain in Forge, so you promote them to Weaver.
Roles map to ranks, which is how the backend decides who passes a permission check:
luminary rank 4 โ everything: Lumen, roles, Data Keys, Data Gates
weaver rank 3 โ edit the semantic model in Forge + everything below
tracer rank 2 โ query and analyse in Discover + everything below
lens rank 1 โ view shared content onlyA check phrased as "Weaver and above" admits ranks 3 and 4 (Weaver, Luminary) and refuses ranks 1 and 2 (Lens, Tracer).
Best practices
- Grant the least privilege that still works. Default new users to Tracer, and only promote to Weaver when they genuinely need to edit the model.
- Keep at least two Luminaries. A single admin is a single point of failure. Promote a backup before anyone goes on leave.
- Use Lens for read-only audiences. Executives and external partners rarely need query access; Lens keeps their view clean and safe.
- Pair roles with Data Gates and Data Keys. Roles decide what features a user reaches; Data Gates and Data Keys decide which rows and columns they see within those features.
Tips
Roles are ranked, so you never need to grant a long list of permissions. Pick the single role that matches the job and the rest follows automatically โ a Weaver already has everything a Tracer and Lens have.
Common mistakes
Over-provisioning everyone as Weaver. Weavers can edit the semantic model. Reserve the role for people who actually build, and keep most users as Tracers.
Expecting roles to hide data. A role controls which features a user can reach, not which rows or columns. To restrict the data itself, use Data Gates and Data Keys.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| "Could not change the role. Please try again." | The role update request failed (network error, or the user could not be found in your workspace). | Reload Lumen โ Users and try again. Confirm the user still belongs to your workspace. |
| The Change role menu is missing or Lumen is inaccessible | You are not a Luminary. | Only Luminaries can open Lumen and change roles. Ask an existing Luminary to make the change or promote you. |
| "Requires role: โฆ" or "This action requires โฆ role or higher" | The signed-in user's role is below the minimum the action needs. | Promote the user to the required role, or have someone with that role perform the action. |
| "Account disabled" on sign-in or requests | The user has been disabled in Lumen โ Users. | A Luminary can re-enable the account from the user's row. |
| "Cannot disable your own account" / "Cannot delete your own account" | You tried to disable or delete the account you are signed in as. | Have another Luminary perform the action, or sign in as a different admin. |
Related pages
- Users โ invite, disable, and manage the people in your workspace
- Data Keys โ restrict which rows each user can see
- Data Gates โ restrict which columns each user can see
- Lumen overview โ the admin area where roles and security live