Test Kitchen/GrowthBook user guide/Access
This part of the GrowthBook user guide focuses on access:
- Overview of the different roles (sets of permissions) and LDAP groups that users need to be in
- Expectations
- Requesting access
Overview
Access to growthbook.wikimedia.org is currently limited to WMF and WMDE staff who have been approved for GrowthBook access and who have at least level 1 access to private data (via membership in analytics-privatedata-users shell group). Access is managed through Wikimedia IDM. Membership in the following LDAP group will grant a corresponding role in GrowthBook.
| LDAP group | GrowthBook Role | Description |
|---|---|---|
| growthbook-readonly | Read Only | Can only observe data and experiments in a read-only fashion. This would be the bulk of user seats, and is the default role. |
| growthbook-customelevatedaccess | CustomElevatedAccess | Meant for people who need to drive experiment and data analysis configuration. It's expected this will usually be A/B test fluent people with software/data/research engineer/scientist/analyst titles |
| growthbook-admin | Admin | Full R/W access to all growthbook features and settings |
Before you request access below, read and understand the following Expectations:
Expectations
General system expectations
When you use GrowthBook, as with other systems, it comes with the expectation that you will not attempt to subvert the system's security controls, that you will not share your access credentials, that you won't use the software with prohibited data or in prohibited jurisdictions, and that you will be mindful that the system is used for configuration and measurement of experiments and so it's important to exercise caution in use of the application's facilities. We use the Enterprise version of this software, relying on its stock OSS functionality as well as the Enterprise functionality; the Enterprise functionality is governed under separate terms from the OSS portion of the software, so we don't extend the software package in general (and where we do, we do so so only in conversation and alignment with GrowthBook). If you have any questions, please do let us know in the #talk-to-experiment-platform channel in Slack.
CustomElevatedAccess
When you obtain access by way of the CustomElevatedAccess role, you have special permissions to manage a variety of assets – experiments, fact tables, and metrics (full list below). We expect you to use your elevated access with care and consideration, and to coordinate with the assets' owners on changes (e.g. modifying a metric's definition or the query powering a fact table) – it's best to note on Phabricator and the #talk-to-experiment-platform channel in Slack.
Seating
Our version of GrowthBook is a paid version, which provides some extra features (one of them being SSO and the custom elevated access role), as well as an avenue for Data Platform Engineering to coordinate with GrowthBook on support requests.
With this paid arrangement, it also means we pay for user seats based on the level of access.
Given the limited number of read only and non-read only seats granted, usage will be periodically checked and stale accounts may be deactivated if more room is needed for seating other users with an active need.
Requesting access
To gain access, visit idm.wikimedia.org/permissions and request access to the corresponding LDAP group from above; please ensure that you have active shell group membership required first before doing so, or your access will not work.
Your request will be reviewed by the Experiment Platform team's Product Manager and Engineering Manager. A response is targeted for within two full business days. If you don't hear back within two full business days, please reach out in the #talk-to-experiment-platform channel in Slack.
More about permissions
The Read Only and Admin roles are directly defined in GrowthBook's off-the-shelf configuration as detailed at docs.growthbook.io/account/user-permissions#permissions.
The CustomElevatedAccess role is, as the name suggests, custom.
CustomElevatedAccess role details
The CustomElevatedAccess role has all of the Read Only permissions and the following permissions:
- Experiments Full Access
- Create, edit, and delete experiments
- Run Queries
- Execute queries against data sources. Required to refresh experiment results. Does not include SQL Explorer access.
- Metrics Full Access
- Create, edit, and delete regular metrics (does not include Fact Metrics)
- Fact Tables Full Access
- Create, edit, and delete fact tables, metrics, and filters.
- Fact Metrics Full Access
- Create, edit, and delete fact metrics and filters.
- Tags Full Access
- Create, edit, and delete tags