Manage roles
A role defines which resources and modules a user can access. NineData provides preset and custom roles. System administrators can manage all roles in an organization. When you enable Role Authorization for a role, members of that role can create and manage child roles within the authorized scope.
Before you begin
- Create or join an organization. For details, see Manage organizations.
- Make sure the NineData console is in organization mode. To switch from personal mode to organization mode, see Switch to organization.
- Your role is Administrator, or you are a member of a role with Role Authorization enabled. For details, see Roles.
Notes
- Among the preset roles, Administrator cannot be edited or deleted and cannot be used as the parent role for creating a child role.
- When you create or rename a role, the role name must be unique in the current organization.
- A role with role-management permission can manage only the child roles that it creates as a source role. It cannot edit the source role or create an independent organization-level role.
- A child role cannot have more permissions than its current source role. Deleting a source role also deletes its child roles and their role-member assignments.
- When a permission is removed from a parent role (source role), the corresponding permission is also removed from all child roles through the cascade. When a permission is added to a parent role, child roles can add and enable it as needed in their permission configuration.
Role-management permissions and visibility
System administrators have full access to all roles, permissions, and members in the organization. In Other Permission, they can enable Role Authorization for a role. Members of that role can then manage child roles within the authorized scope. New child roles do not have Role Authorization enabled by default.
| Role state | Visible scope | Available operations |
|---|---|---|
| System administrator | All roles, permissions, and members | Create independent roles; edit and delete all roles except Administrator; configure permissions; maintain members; manage role inheritance. |
| Member of a role with Role Authorization enabled | The role and its direct or multilevel child roles | Create a direct child role from the source role; edit child-role permissions within the source role's permission scope; maintain and delete child roles. To edit a descendant role, the operator must also be a member of its source role. |
| Member of a role without Role Authorization | No role-management entry | Cannot perform role-management operations. |
Delegation follows these rules:
- When Role Authorization is disabled, existing child roles are not deleted immediately, but members of the source role can no longer maintain them.
- New child roles have Role Authorization disabled by default. To let a child role manage the next level, enable Role Authorization for that child role in Other Permission.
- If you have more than one role-management entry, select one source role when creating a child role. Permissions from multiple source roles cannot be combined.
- The Administrator role does not support child-role creation. To create a role hierarchy, use another role with Role Authorization enabled as the source role.
Use cases for child roles
When an organization needs to divide role permissions further by department, project, or environment, create child roles within the permission scope of a parent (source) role. The parent role defines the maximum permission scope available to child roles. Each child role can carry a more focused permission combination and be assigned to its relevant members.
For example, an administrator can configure a parent role for a business scope, then create child roles for different teams, edit their permissions as needed, and assign members. A child role cannot manage the next level by default. To delegate role management further, enable Role Authorization for the child role in Other Permission.
Procedure
View or add roles
Sign in to the NineData Console.
Open Account > Role.
tipIf Account is not displayed, make sure the console is in organization mode. To switch from personal mode to organization mode, see Switch to organization.
Review role names and hierarchy in the role tree on the left. Expand a source role to view its child roles. Select a role to view its permission configuration and member list on the right.
- System administrators can view all roles.
- A role-management member can view the role for which they are a source and its child roles.
- Child roles appear nested under their source role so that the inheritance relationship is clear.
To create an independent role, a system administrator clicks Create Role above the role tree.
In the Create Role dialog, enter the Role Name. Use a meaningful name to identify the role. Role names support up to 16 characters.
Click OK to create the role. The new role appears in the role tree. Select it to configure its permissions for your team.
tipFor details about permission types, see Permissions.
Create a child role
A role-management member can create a direct child role only from a role for which they are a member and that role is the source role. The Administrator role cannot be used as the parent role for creating a child role. A role-management member can view direct or multilevel descendants; to edit a descendant role, the operator must be a member of its source role.
Follow View or add roles to open Role.
In the source role's action entry, click Duplicate.
In the Create Role dialog, confirm the source role, enter a child-role name, and click OK. The child role appears nested under the source role and does not inherit Role Authorization by default.
On the child role's permission configuration page, turn off any permissions that are not required. A child role can be configured only with permissions in the source role's current permission set. NineData validates this scope when you save.
To let the child role manage the next level, enable Role Authorization for the child role in Other Permission.
Edit an existing role
System administrators can edit all roles except Administrator. A role-management member can edit only its child roles and cannot edit the source role itself. Editable content includes the role name, permissions, and members.
Sign in to the NineData Console.
Open Account > Role, and select the target role in the role list.
tipIf Account is not displayed, make sure your console is in organization mode. To switch from personal mode to organization mode, see Switch to organization.
Rename a role: In the role list on the left side of the page, hover over the role, click the
icon, enter the new Role Name in the Edit Role dialog, and click OK. Role names support up to 16 characters.
tipThis icon does not appear to the right of the Administrator role because it cannot be changed.
Edit role permissions: In the role list on the left side of the page, click the target role name, edit the role permissions on the permission configuration page, and click Save in the lower-left corner of the page.
Permission configuration includes Service Permission, Datasource Permission, Other Permission, database/schema, table, and sensitive-column permissions. The Other Permission page includes Alert Permission, Role Authorization, and Sensitive Data Management. For child roles:
- A permission that is disabled for the source role cannot be enabled for a child role.
- A permission newly added to the source role enters the child role's available permission pool but is not enabled automatically.
- A permission removed from the source role is removed from all child roles through the cascade and cannot be enabled again.
cautionEditing the source role's permissions changes the available permission scope for its child roles. Confirm the permissions that should remain available before saving.
:::tip
For details about permission types, see Permissions.
:::
Delete a role
System administrators can delete all roles except Administrator. A role-management member can delete only its child roles; to delete a descendant role, the operator must be a member of its source role.
Sign in to the NineData Console.
Open Account > Role.
tipIf Account is not displayed, make sure your console is in organization mode. To switch from personal mode to organization mode, see Switch to organization.
In the role list on the left side of the page, hover over the role to delete, and click the
icon.
tipThis icon does not appear to the right of the Administrator role because it cannot be removed.
In the Edit Role dialog, click Delete in the lower-left corner.
cautionAfter a regular role is deleted, users assigned to that role lose the role and all permissions provided by it. This operation is irreversible.
If the role is a source role, NineData also deletes its child roles and removes the related role-member assignments. Confirm the impact before deleting it.
In the confirmation dialog, enter the role name and click Delete in the bottom right.
Assign roles to users
A role takes effect only after it is assigned to a user. Before assigning a role, make sure the target user has joined the organization. For details, see Invite users. System administrators can maintain members for any role. A role-management member can maintain members only for its child roles; to maintain a descendant role, the operator must be a member of its source role. The member selector follows the existing organization, tenant, and user visibility scope.
Sign in to the NineData Console.
Open Account > Role.
tipIf Account is not displayed, make sure your console is in organization mode. To switch from personal mode to organization mode, see Switch to organization.
In the role list, click the target role name. In the Members, click Add.
In the Add dialog, select the target users under Members. Select multiple users to assign the role in batches.
Click OK.
Source-role changes and inheritance
The role inheritance relationship automatically converges when the source role changes:
| Source-role change | Child-role result |
|---|---|
| Add a permission | The permission enters the child role's available permission pool and is not enabled automatically. |
| Remove a permission | The corresponding permission is removed from all child roles through the cascade and cannot be enabled again. |
| Disable Role Authorization | Members of the source role no longer see the Role entry or manage child roles. Existing child roles are not deleted immediately. |
| Create a child role | The child role has Role Authorization disabled by default. To manage the next level, enable Role Authorization for the child role in Other Permission. |
| Delete the source role | NineData cascades deletion to child roles, removes the related role-member assignments, and records the change in the audit log. |
Role, permission, member, and cascading-deletion changes are recorded in the audit log.
Result
The role configuration is saved for the organization. Users assigned to the role receive the permissions defined for that role.
Appendix: List of preset role permissions
The following tables show the default permissions for preset roles. A custom role with Role Authorization enabled can manage child roles within the source role's permission scope; this scope and delegation rule do not change the other default permissions shown below.
- Admin Permissions
- Service Permissions
- Datasource Permissions (PROD)
- Datasource Permissions (DEV)
- Other Permissions
| Module | Category | System Administrator | Production Environment Administrator | Production Environment Read-only | Development Environment Administrator | Regular Member |
|---|---|---|---|---|---|---|
| User Management | Invite Users/Create SSO Users | ✔️ | ❌ | ❌ | ❌ | ❌ |
| Remove Users | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Edit Users | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Disable/Enable Users | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Configure Permissions | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Role Management | Add New Role | ✔️ | ❌ | ❌ | ❌ | ❌ |
| Edit Role Permissions | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Edit User Roles | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Delete Role | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Organization Management | Change Organization Name|Logo | ✔️ | ❌ | ❌ | ❌ | ❌ |
| SSO Account Login Configuration | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Toggle Data Watermark | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Configure Session Timeout | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Delete Organization | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Audit Log | View Operation Logs | ✔️ | ❌ | ❌ | ❌ | ❌ |
| View SQL Execution Logs | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Message Center | Subscription Management | ✔️ | ❌ | ❌ | ❌ | ❌ |
| Module | Category | Administrator | Prod Admin | Prod Admin(RO) | Dev Admin | Common User |
|---|---|---|---|---|---|---|
| DevOps | SQL Console | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| SQL Task | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| Archive & Clean | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| Data Export | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| Data Import | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| SQL Code Review | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| Slow Query | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| DSQL | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| Backup | Backup | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Restore | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| Backup Set | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| Backup Query | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| Replication | Replication | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Comparison | Data | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Schema | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| Datasource | Datasource | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Policy & Process | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Sensitive Data Management | ✔️ | ❌ | ❌ | ❌ | ❌ | |
| Alert | Alert | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Module | Category | Administrator | Prod Admin | Prod Admin(RO) | Dev Admin | Common User |
|---|---|---|---|---|---|---|
| SQL Dev | Read-only | ✔️ | ✔️ | ✔️ | ❌ | ❌ |
| DML | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| DDL | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| SQL Task - Submit | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| SQL Task - Execute | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| Data Export - Submit | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| Data Export - Execute | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| Data Import - Submit | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| Data Import - Execute | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| Backup | Backup | ✔️ | ✔️ | ❌ | ❌ | ❌ |
| Restore | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| Replication | Data Replication | ✔️ | ✔️ | ❌ | ❌ | ❌ |
| Comparison | Data | ✔️ | ✔️ | ❌ | ❌ | ❌ |
| Schema | ✔️ | ✔️ | ❌ | ❌ | ❌ | |
| Datasource | Datasource | ✔️ | ✔️ | ❌ | ❌ | ❌ |
| Module | Category | Administrator | Prod Admin | Prod Admin(RO) | Dev Admin | Common User |
|---|---|---|---|---|---|---|
| SQL Dev | Read-only | ✔️ | ❌ | ❌ | ✔️ | ❌ |
| DML | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| DDL | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| SQL Task - Submit | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| SQL Task - Execute | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| Data Export - Submit | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| Data Export - Execute | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| Data Import - Submit | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| Data Import - Execute | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| Backup | Backup | ✔️ | ❌ | ❌ | ✔️ | ❌ |
| Restore | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| Replication | Data Replication | ✔️ | ❌ | ❌ | ✔️ | ❌ |
| Comparison | Data | ✔️ | ❌ | ❌ | ✔️ | ❌ |
| Schema | ✔️ | ❌ | ❌ | ✔️ | ❌ | |
| Datasource | Datasource | ✔️ | ❌ | ❌ | ✔️ | ❌ |
| Module | Category | Administrator | Prod Admin | Prod Admin(RO) | Dev Admin | Common User |
|---|---|---|---|---|---|---|
| Role Authorization | Role Authorization | ❌ | ❌ | ❌ | ❌ | ❌ |
| Alert Permissions | Alert Permissions | ✔️ | ✔️ | ❌ | ✔️ | ❌ |
| Sensitive Data Management | Sensitive Data Management | ✔️ | ❌ | ❌ | ❌ | ❌ |