System roles in Data Management (DMS) play a vital role in enforcing permission management, simplifying permission assignment, and ensuring data security and compliance. DMS supports the following system roles: regular user, DBA, DMS administrator, security administrator, schema read-only user, and technical support.
Purposes of system roles in DMS
-
Permission management
Ensures that each user or group of users can access and operate only the resources within their authorized scope.
-
Simplified permission assignment
Administrators can use the user management feature to grant resource permissions to all DMS users of a specific role at a time, without configuring permissions for each user.
-
Data security and compliance
System roles help reduce the risk of data leaks or accidental operations caused by excessive permission assignment, which improves overall security.
System role descriptions
|
Role |
Intended users |
Function |
Characteristics |
|
Regular user |
R&D engineers, testers, operations staff, and data analysts in an enterprise. Note
By default, RAM users under the Alibaba Cloud account of the current tenant are regular users. |
Regular users can query and change data and schemas in DMS to use data appropriately and securely within their authorized scope. |
|
|
DBA |
DBAs and O&M staff in an enterprise. |
DBAs can manage and maintain database instance resources, database development standards, database development processes, and task execution. |
Permissions are second only to those of the DMS administrator, but focus on database-level management and do not involve system-level configuration. |
|
DMS administrator |
Administrators of an enterprise. Note
|
The DMS administrator is the core manager of DMS. This role has management permissions on all database instances in the current DMS tenant and is responsible for advanced maintenance operations such as global system configuration, user management, and resource allocation. |
Has the highest permissions. A DMS administrator can use all DMS features and perform operations such as database changes and exports in DMS. |
|
Security administrator |
Internal auditors and security administrators of an enterprise. |
Performs operations in DMS such as security classification of data fields and auditing of user operations. |
Permissions focus on security configuration and monitoring and do not involve database operations. |
|
Schema read-only user |
Data analysts and similar staff. |
Views the metadata of instances, databases, and tables, including viewing table details and exporting entire database schemas. |
Permissions are limited to viewing the metadata of instances, databases, and tables. |
|
Technical support |
Read-only O&M staff. |
Views all tickets and their details. |
Permissions are limited to viewing all tickets and their execution logs. |
Permission map of each role
For information about the DMS feature modules that the six roles — regular user, DBA, DMS administrator, security administrator, schema read-only user, and technical support — can use, see Permissions of system roles.