Role Permissions
Roles can be used for fairly coarse-grained permissions control. They grant service-level permissions based on user responsibilities. GES does not support custom roles. The following system roles are available.
| Role Name | Description |
|---|---|
| Tenant Guest | Regular tenant users
|
| GES Administrator | GES administrator
|
| GES Manager | GES manager
|
| GES Operator | Regular GES users
NOTE:
|
| Operation | GES Administrator | GES Manager | GES Operator | Tenant Guest |
|---|---|---|---|---|
| Creating graphs | Yes | No | No | No |
| Deleting graphs | Yes | No | No | No |
| Querying graphs | Yes | Yes | Yes | Yes |
| Accessing graphs | Yes | Yes | Yes | No |
| Importing data | Yes | Yes | No | No |
| Creating metadata | Yes | Yes | No | No |
| Viewing metadata | Yes | Yes | Yes | Yes |
| Copying metadata | Yes | Yes | No | No |
| Editing metadata | Yes | Yes | No | No |
| Deleting metadata | Yes | Yes | No | No |
| Clearing data | Yes | Yes | No | No |
| Backing up graphs | Yes | Yes | No | No |
| Restoring graphs from backups | Yes | Yes | No | No |
| Deleting backups | Yes | Yes | No | No |
| Querying backups | Yes | Yes | Yes | Yes |
| Starting graphs | Yes | Yes | No | No |
| Stopping graphs | Yes | Yes | No | No |
| Upgrading graphs | Yes | Yes | No | No |
| Exporting graphs | Yes | Yes | No | No |
| Viewing results in the task center | Yes | Yes | Yes | Yes |
| Resizing a graph | √ | No | No | × |
| Expanding a graph | √ | No | No | × |
| Restarting a graph | √ | Yes | No | × |
| Configuring fine-grained permissions | √ | Yes | No | × |
| Configuring user groups | √ | Yes | No | × |
| Importing IAM users | √ | Yes | No | × |
| Viewing user details | √ | Yes | Yes | √ |
| GES Operation | Dependent OBS Permission |
|---|---|
| Viewing metadata | OBS Viewer policy or OBS Buckets Viewer role |
| Creating, importing, copying, editing, and deleting metadata | OBS Operator policy or Tenant Administrator role |
| Creating, importing, and exporting graphs | OBS Operator policy or Tenant Administrator role |
| GES Operation | Dependent IAM Permission |
|---|---|
| Importing IAM users | iam:users:listUsers (custom policy), IAM ReadOnlyAccess (system policy), or Server Administrator role |
| Creating or editing a user group | iam:users:listUsers (custom policy), IAM ReadOnlyAccess (system policy), or Server Administrator role |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.