Connection permissions
Connection permissions control which users and groups can use a given connection in Alteryx One. You can list, inspect, create, and delete permissions from the CLI. Mutating commands are dry-run by default — add --apply to commit.
Quick reference
Section titled “Quick reference”| Command | What it does |
|---|---|
ayx one connections permissions list |
List all permissions for a connection |
ayx one connections permissions detail |
Inspect a single permission by subject ID |
ayx one connections permissions create |
Grant a permission from a JSON payload |
ayx one connections permissions delete |
Revoke a permission by subject ID |
All commands accept <connection-id> as the connection positional argument and --profile <profile-id>.
Listing permissions
Section titled “Listing permissions”# All permissions for a connectionayx one connections permissions list <id>
# Scoped to a profileayx one connections permissions list <id> --profile <profile-id>
# Machine-readable outputayx -o json one connections permissions list <id>Inspecting a permission
Section titled “Inspecting a permission”A subject is a user or group that has been granted access.
ayx one connections permissions detail \ <id> \ <subject-id>Granting a permission
Section titled “Granting a permission”# Dry-run using the convenience flagsayx one connections permissions create \ <id> \ --policy viewer \ --to-person <subject-id>
# Dry-run using a raw bodyayx one connections permissions create \ <id> \ --body permissions.json
# Commit (requires --apply and confirmation; use --yes for non-interactive runs)ayx one connections permissions create \ <id> \ --policy viewer \ --to-person <subject-id> \ --apply --yespermissions.json:
{ "connectionId": "<id>", "policy": "VIEWER", "subjects": {"person": ["<subject-id>"]}}The raw body must contain only non-empty person and/or group subject buckets. If
connectionId is omitted, the CLI binds the positional id; if it is present and differs, the
request is rejected before confirmation or network I/O.
Revoking a permission
Section titled “Revoking a permission”# Dry-runayx one connections permissions delete \ <id> \ <subject-id>
# Commit (skips TTY prompt in CI)ayx one connections permissions delete \ <id> \ <subject-id> \ --apply --yesAutomation patterns
Section titled “Automation patterns”Audit all subjects with access to a connection:
ayx -o json one connections permissions list <id> \ | jq -r '.data.response.people[]? | [.subjectId, .roleType] | @tsv'Remove all permissions for a decommissioned user across multiple connections:
# First collect connection IDsayx -o json one connections list --all | jq -r '.data.items[].id' > conn-ids.txt
# Then revoke per connection where the subject appearswhile read conn_id; doayx -o json one connections permissions list "$conn_id" \ | jq -r '.data.response.people[]? | select(.subjectId == "<subject-id>") | .subjectId' \ | grep -q . && \ ayx one connections permissions delete \ "$conn_id" \ <subject-id> \ --apply --yesdone < conn-ids.txtRelated
Section titled “Related”- Connections — manage connection records
- Connector metadata — defaults and overrides
- Safety model — how dry-run and
--applywork - Output & automation — JSON envelope and scripting patterns