What each Fabric workspace role can do across Power BI, data engineering, warehousing and real-time items.
From Ultra Transcenders DP-600 by Tony Rough (coming December 2026)
Workspace roles are Admin, Member, Contributor and Viewer. Fabric extends the original Power BI roles with data engineering, warehousing and real-time capabilities, so the capability matrix is the core of this objective.
| Capability | Admin | Member | Contributor | Viewer |
|---|---|---|---|---|
| Update and delete the workspace | Yes | No | No | No |
| Add or remove people, including other admins | Yes | No | No | No |
| Add members or others with lower permissions | Yes | Yes | No | No |
| Allow others to reshare items | Yes | Yes | No | No |
| Create a workspace identity | Yes | No | No | No |
| Connect the workspace to a Git repository | Yes | No | No | No |
| Create or modify warehouse, database and mirrored database items | Yes | Yes | Yes | No |
| Write or delete pipelines, notebooks, Spark job definitions, eventstreams, eventhouses, KQL querysets, lakehouse and warehouse data, shortcuts | Yes | Yes | Yes | No |
| Execute or cancel notebooks, Spark job definitions and pipelines | Yes | Yes | Yes | No |
| Connect to the SQL analytics endpoint or warehouse | Yes | Yes | Yes | Yes |
| Read lakehouse and warehouse data with T-SQL (ReadData) | Yes | Yes | Yes | Yes |
| Read lakehouse and warehouse data through Spark and OneLake APIs, or the Lakehouse explorer (ReadAll) | Yes | Yes | Yes | No |
| Subscribe to OneLake events | Yes | Yes | Yes | No |
| View pipeline, notebook and experiment content and execution output | Yes | Yes | Yes | Yes |
| Schedule refreshes through an on-premises gateway, modify gateway connection settings | Yes | Yes | Yes | No |
Shortcut data and gateway operations also need permissions on the shortcut target or the gateway, which are managed separately from workspace roles.
| Capability | Admin | Member | Contributor | Viewer |
|---|---|---|---|---|
| Publish, unpublish and change permissions for an app | Yes | Yes | No | No |
| Update an app | Yes | Yes | If the Admin allows it | No |
| Share items, including semantic models, and allow resharing | Yes | Yes | With Reshare | With Reshare |
| Create, edit and delete content | Yes | Yes | Yes | No |
| Build a report in another workspace on a semantic model here | Yes | Yes | Yes | No |
| Analyze in Excel, download a PBIX | Yes | Yes | Yes | No (Viewers need Build for Analyze in Excel) |
| Manage subscriptions created by others | Yes | No | No | No |
| View and interact with items | Yes | Yes | Yes | Yes |
Common trap: Giving a Member the job of connecting the workspace to Git or creating a workspace identity - both are Admin-only actions.
Common trap: Expecting Viewers to explore a lakehouse in a notebook - Viewers can read through the SQL analytics endpoint (ReadData) but not through Spark, OneLake APIs or the Lakehouse explorer (ReadAll), unless a OneLake security role or item permission grants it.
Common trap: Asking a Member to promote a Viewer to Contributor - Members can add people with the same or lower role but can’t change existing users’ roles.
This note is one section of Ultra Transcenders DP-600: Implementing Analytics Solutions Using Microsoft Fabric, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · DP-600 terms in the glossary · All DP-600 study notes
How the two Direct Lake flavours differ in table discovery, permission checks, fallback and unsupported cases, and which one to choose.
When each table storage mode fits a semantic model, based on data size, latency, source security and capacity.
Which items and settings a deployment copies or leaves alone, and how data source and parameter rules point each stage at its own data.
How data type, team skills, write needs and transactions decide between Fabric's lakehouse, warehouse, eventhouse and other stores.
What the Warehouse can do that a lakehouse's read-only SQL analytics endpoint can't, and when to use each.
The three many-to-many scenarios in a semantic model and the bridge-table or relationship design each one needs.
How data volume, transformation needs, skills and latency decide which Fabric tool should copy data into OneLake.