Planning roles provide a flexible, least-privilege access model for planning items. Instead of assigning fixed permissions, plan automatically adjusts your role based on the actions you perform. With dynamic role assignment, you start with the minimum required access and gain more capabilities only when necessary.
Plan supports three roles:
Plan treats creating or editing PowerTable sheets and intelligence sheets as Stakeholder persona activities. These actions no longer upgrade your session to the Planner persona. Plan assigns the Planner persona only when you create or edit planning sheets.
Role permission matrix:
| Workload | Viewer | Stakeholder | Planner |
|---|---|---|---|
| Planning Budgets, forecasts, scenarios, allocations | Read | Contribute | Create |
| PowerTable Reference and master data management | Read | Create | Create |
| Intelligence Reports, dashboards, and analysis | Read | Create | Create |
Roles are flexible, and plan assigns them dynamically through time-bound sessions based on your actions. Roles adapt in real time based on how you contribute, without manual role reassignment.
Fabric workspace roles and planning roles are independent and serve different purposes. Fabric workspace roles determine your ability to access and manage workspace items. Planning roles determine the actions you can perform within a planning item.
Recommended Fabric workspace role mapping:
| Planning persona | Fabric workspace role |
|---|---|
| Viewer | Viewer |
| Stakeholder | Viewer, contributor, or member |
| Planner | Admin, member, or contributor |
This recommendation helps ensure that:
Plan assigns planning roles dynamically based on user activity. You typically begin in a Viewer session. As you perform actions that require extra privileges, plan automatically upgrades you to the appropriate role.
Examples:
| User action | Resulting role |
|---|---|
| Open and view a planning sheet | Viewer |
| Enter data, write back values, participate in approvals, or collaborate | Stakeholder |
| Edit planning items or perform authoring operations | Planner |
With this dynamic model, administrators don't need to manually assign roles. However, they can control which users can upgrade to Planner and Stakeholder sessions. To learn more, see Control session upgrades.
Upgrade your planning role by performing an action that requires Planner or Stakeholder permissions.
The planning toolbar shows your assigned role. Select the role indicator to display additional information, including current session type, session expiration details, and capabilities of the current role.

Planning roles operate through time-bound sessions. Plan creates a session when you perform a planning action, such as opening a planning sheet. Each session remains active for 30 days. When you perform an action that requires a higher privilege level, plan automatically creates a new session for the upgraded role. Role sessions help organizations implement least-privilege access while letting you transition between planning responsibilities.
Administrators can control which users can upgrade to Planner and Stakeholder sessions. They can also configure whether users receive a warning when creating or upgrading a session could result in capacity oversubscription.
The following tenant settings are available:

Capacity-level override: All three settings are configured at the tenant level and can be overridden at the capacity level for individual capacities by using Delegated Tenant Settings. This allows capacity administrators to apply different plan settings to specific capacities based on their governance and capacity requirements.
This setting controls whether users can upgrade to a Planner session.
Planners can create plan items, connect semantic models, build planning sheets, and publish planning applications.
Administrators can:
Planner access also includes Stakeholder access. If Planner access is enabled for the entire organization, all users in the organization can also upgrade to a Stakeholder session.
This setting controls whether users can upgrade to a Stakeholder session.
Stakeholders can enter data, write back changes, and collaborate on published plan items in Reading view.
Administrators can:
To upgrade to a Stakeholder session, users must either
Users who do not have either type of access cannot create or edit plan items, enter data, write back changes, or collaborate. They can only access plan items in Reading view.
This setting controls whether users receive a warning when creating or upgrading a session could result in capacity oversubscription.
Administrators can:
When enabled, the warning appears before users create or upgrade a session that is likely to cause capacity oversubscription. The warning helps users understand the potential capacity impact before they proceed.
This setting applies to the entire organization.
| Setting | Control | Tenant Scope | Capacity-Level Override |
|---|---|---|---|
| Users can upgrade to a Planner session | Enable + Select entire organization/security group | Entire organization or specific security groups | Yes—through Delegated Tenant Settings |
| Users can upgrade to a Stakeholder session | Enable + Select entire organization/security group | Entire organization or specific security groups | Yes—through Delegated Tenant Settings |
| Show Oversubscription Warning | Enable | Entire organization | Yes—through Delegated Tenant Settings |
Role upgrades: Plan assigns roles dynamically based on user actions through time‑bound sessions. Role upgrades occur when you perform valid plan actions. You can upgrade roles only to a higher privilege level:
Role downgrades: Plan doesn't support manual downgrades within an active session.
Session expiry: Each session automatically expires after 30 days. After the 30-day session expires, a new session begins only when you perform a new action on a plan item. The first successful action determines the persona for the new session:
| Capability | Planner | Stakeholder | Viewer |
|---|---|---|---|
| Change the layout | ✅ | ✅ | ✅ |
| Sort, search, filter, rank, and bookmark planning sheets | ✅ | ✅ | ✅ |
| Enable totals and subtotals | ✅ | ✅ | ✅ |
| Number formatting—convert to percentage, change scaling, and adjust decimal places | ✅ | ✅ | ✅ |
| Change the font style | ✅ | ✅ | ✅ |
| Change value alignment in cells | ✅ | ✅ | ✅ |
| Enable the ruler | ✅ | ✅ | ✅ |
| Configure conditional formatting | ✅ | ||
| Apply semantic formatting | ✅ | ||
| Undo/redo and reset formats, values, notes, header order, and row order | ✅ | ||
| Pivot data | ✅ | ✅ | |
| Add language translations | ✅ | ||
| Add page breaks and enable row highlights, gridlines, and table outline | ✅ |
| Capability | Planner | Stakeholder | Viewer |
|---|---|---|---|
| Insert rows | ✅ | ✅ | |
| Insert calculated and data input columns | ✅ | ||
| Enter values and distribute them to lower levels in the dimensional hierarchy | ✅ | ✅ | |
| Bulk edit values | ✅ | ✅ | |
| Extend time for data input fields | ✅ | ||
| Create and manage forecasts | ✅ | ||
| Close forecast periods, reforecast, and distribute deficits | ✅ | ||
| Insert simulation measures | ✅ | ✅ | |
| Create scenarios, update settings, copy to base, bulk edit, select input method, and pivot | ✅ | ✅ | |
| Compare scenarios | ✅ | ✅ | ✅ |
| Use Optimizer | ✅ | ✅ | |
| Use model builder | ✅ | ||
| Create locking, distribution, and min/max rules | ✅ |
| Capability | Planner | Stakeholder | Viewer |
|---|---|---|---|
| Export plans to Excel or PDF files | ✅ | ✅ | |
| Add and manage destinations | ✅ | ||
| Write back and save planning data | ✅ | ✅ | |
| Enable autowriteback | ✅ | ||
| Select the writeback type, create writeback filters, and rename columns | ✅ | ||
| View writeback logs | ✅ | ✅ | |
| Export writeback logs | ✅ | ||
| Writeback scenarios and view logs | ✅ | ✅ | |
| Add destination to writeback scenarios | ✅ |
| Capability | Planner | Stakeholder | Viewer |
|---|---|---|---|
| Add notes | ✅ | ✅ | |
| Add and assign comments, tag users, and enable the comments column | ✅ | ✅ | |
| Add report-level comments | ✅ | ✅ | |
| Edit comments settings | ✅ | ||
| Enable the comments pane to view all comments | ✅ | ✅ |
| Capability | Planner | Stakeholder | Viewer |
|---|---|---|---|
| Connect the planning workspace directly to enterprise semantic models in Power BI/Fabric | ✅ | ||
| Browse the organizational semantic model catalog (metadata) natively within the planning interface | ✅ | ||
| Create planning, PowerTable, and intelligence sheets | ✅ | ||
| Visualize planning sheets with Intelligence | ✅ | ||
| Import and save data from internal sources such as Planning and PowerTable sheets, as well as external sources such as CSV, Excel, and JSON | ✅ | ✅ |
For plan items that contain only PowerTable sheets, only the Stakeholder and Viewer roles are available.
| Capability | Stakeholder | Viewer |
|---|---|---|
| Browse reference data and PowerTable grids. | ✅ | ✅ |
| Build and edit no-code reference data apps. | ✅ | |
| Integrate multilevel approval workflows. | ✅ | |
| Configure event-driven automation. | ✅ | |
| Control row and column access permissions. | ✅ | |
| Integrate with plan and intelligence. | ✅ | |
| Participate in approval workflows. | ✅ | |
| Fill data collection forms. | ✅ | |
| Update status and contribute project and time entries. | ✅ |
For plan items that contain only intelligence sheets, only the Stakeholder and Viewer roles are available.
| Capability | Stakeholder | Viewer |
|---|---|---|
| View intelligence sheets in read-only mode. | ✅ | ✅ |
| Build and edit dashboards and reports. | ✅ | |
| Perform ad-hoc analysis. | ✅ | |
| Use more than 100 chart types in dashboards. | ✅ | |
| Run plan vs. actual variances. | ✅ | |
| Use annotations. | ✅ | |
| Filter data. | ✅ | |
| Apply bookmarks. | ✅ |
No. Each capacity evaluates roles independently.
No, plan doesn't support downgrades. You can only upgrade roles to higher privilege levels; however, your assigned role automatically expires after 30 days.
The next time you interact with a planning item, plan creates a new session. Your first successful action determines the role for the new session.
No. Planning roles and Fabric workspace roles are independent security models that Fabric evaluates separately.