System roles

更新时间:
复制 MD 格式
 System roles

System roles in Data Management (DMS) play a vital role in enforcing permission management, simplifying permission assignment, and ensuring data security and compliance. DMS supports the following system roles: regular user, DBA, DMS administrator, security administrator, schema read-only user, and technical support.

Purposes of system roles in DMS

  • Permission management

    Ensures that each user or group of users can access and operate only the resources within their authorized scope.

  • Simplified permission assignment

    Administrators can use the user management feature to grant resource permissions to all DMS users of a specific role at a time, without configuring permissions for each user.

  • Data security and compliance

    System roles help reduce the risk of data leaks or accidental operations caused by excessive permission assignment, which improves overall security.

System role descriptions

Role

Intended users

Function

Characteristics

Regular user

R&D engineers, testers, operations staff, and data analysts in an enterprise.

Note

By default, RAM users under the Alibaba Cloud account of the current tenant are regular users.

Regular users can query and change data and schemas in DMS to use data appropriately and securely within their authorized scope.

  • Low permissions

    Regular users must apply for database object permissions before they can perform operations in the SQL Console and data plans.

  • Limited feature access

    Regular users cannot use features such as instance management, user management, task management, or configuration management.

DBA

DBAs and O&M staff in an enterprise.

DBAs can manage and maintain database instance resources, database development standards, database development processes, and task execution.

Permissions are second only to those of the DMS administrator, but focus on database-level management and do not involve system-level configuration.

DMS administrator

Administrators of an enterprise.

Note
  • The Alibaba Cloud account of the current tenant is the DMS administrator by default, and this role cannot be revoked from the account.

  • A DMS administrator can assign the administrator role to other users. For more information, see Manage users.

The DMS administrator is the core manager of DMS. This role has management permissions on all database instances in the current DMS tenant and is responsible for advanced maintenance operations such as global system configuration, user management, and resource allocation.

Has the highest permissions. A DMS administrator can use all DMS features and perform operations such as database changes and exports in DMS.

Security administrator

Internal auditors and security administrators of an enterprise.

Performs operations in DMS such as security classification of data fields and auditing of user operations.

Permissions focus on security configuration and monitoring and do not involve database operations.

Schema read-only user

Data analysts and similar staff.

Views the metadata of instances, databases, and tables, including viewing table details and exporting entire database schemas.

Permissions are limited to viewing the metadata of instances, databases, and tables.

Technical support

Read-only O&M staff.

Views all tickets and their details.

Permissions are limited to viewing all tickets and their execution logs.

Permission map of each role

For information about the DMS feature modules that the six roles — regular user, DBA, DMS administrator, security administrator, schema read-only user, and technical support — can use, see Permissions of system roles.