Jump to content

Test Kitchen/GrowthBook user guide/Access

From Wikitech

This part of the GrowthBook user guide focuses on access:

  • Overview of the different roles (sets of permissions) and LDAP groups that users need to be in
  • Expectations
  • Requesting access

Overview

It may take 30 minutes or more for for automation of your GrowthBook role/permissions to take effect after access approval. If your GrowthBook access has been approved, but you can't view anything after logging into GrowthBook, wait a bit and try signing out and back in again. If your access still doesn't work, please reach out in #talk-to-experiment-platform in Slack.

Access to growthbook.wikimedia.org is currently limited to WMF and WMDE staff who have been approved for GrowthBook access and who have at least level 1 access to private data (via membership in analytics-privatedata-users shell group). Access is managed through Wikimedia IDM. Membership in the following LDAP group will grant a corresponding role in GrowthBook.

LDAP group GrowthBook Role Description
growthbook-readonly Read Only Can only observe data and experiments in a read-only fashion. This would be the bulk of user seats, and is the default role.
growthbook-customelevatedaccess CustomElevatedAccess Meant for people who need to drive experiment and data analysis configuration. It's expected this will usually be A/B test fluent people with software/data/research engineer/scientist/analyst titles
growthbook-admin Admin Full R/W access to all growthbook features and settings

Before you request access below, read and understand the following Expectations:

Expectations

General system expectations

When you use GrowthBook, as with other systems, it comes with the expectation that you will not attempt to subvert the system's security controls, that you will not share your access credentials, that you won't use the software with prohibited data or in prohibited jurisdictions, and that you will be mindful that the system is used for configuration and measurement of experiments and so it's important to exercise caution in use of the application's facilities. We use the Enterprise version of this software, relying on its stock OSS functionality as well as the Enterprise functionality; the Enterprise functionality is governed under separate terms from the OSS portion of the software, so we don't extend the software package in general (and where we do, we do so so only in conversation and alignment with GrowthBook). If you have any questions, please do let us know in the #talk-to-experiment-platform channel in Slack.

CustomElevatedAccess

When you obtain access by way of the CustomElevatedAccess role, you have special permissions to manage a variety of assets – experiments, fact tables, and metrics (full list below). We expect you to use your elevated access with care and consideration, and to coordinate with the assets' owners on changes (e.g. modifying a metric's definition or the query powering a fact table) – it's best to note on Phabricator and the #talk-to-experiment-platform channel in Slack.

Seating

Our version of GrowthBook is a paid version, which provides some extra features (one of them being SSO and the custom elevated access role), as well as an avenue for Data Platform Engineering to coordinate with GrowthBook on support requests.

With this paid arrangement, it also means we pay for user seats based on the level of access.

Given the limited number of read only and non-read only seats granted, usage will be periodically checked and stale accounts may be deactivated if more room is needed for seating other users with an active need.

Requesting access

To gain access, visit idm.wikimedia.org/permissions and request access to the corresponding LDAP group from above; please ensure that you have active shell group membership required first before doing so, or your access will not work.

Please include a justification of your access request so the approvers know why you need the level of access you are requesting.

Your request will be reviewed by the Experiment Platform team's Product Manager and Engineering Manager. A response is targeted for within two full business days. If you don't hear back within two full business days, please reach out in the #talk-to-experiment-platform channel in Slack.

More about permissions

The Read Only and Admin roles are directly defined in GrowthBook's off-the-shelf configuration as detailed at docs.growthbook.io/account/user-permissions#permissions.

The CustomElevatedAccess role is, as the name suggests, custom.

CustomElevatedAccess role details

The CustomElevatedAccess role has all of the Read Only permissions and the following permissions:

Experiments Full Access
Create, edit, and delete experiments
Run Queries
Execute queries against data sources. Required to refresh experiment results. Does not include SQL Explorer access.
Metrics Full Access
Create, edit, and delete regular metrics (does not include Fact Metrics)
Fact Tables Full Access
Create, edit, and delete fact tables, metrics, and filters.
Fact Metrics Full Access
Create, edit, and delete fact metrics and filters.
Tags Full Access
Create, edit, and delete tags