Role Permissions
Roles can be used for fairly coarse-grained permissions control. They grant service-level permissions based on user responsibilities. GES does not support custom roles. The following system roles are available.
Role Name | Description |
|---|---|
Tenant Guest | Regular tenant users
|
GES Administrator | GES administrator
|
GES Manager | GES manager
|
GES Operator | Regular GES users
NOTE:
|
Operation | GES Administrator | GES Manager | GES Operator | Tenant Guest |
|---|---|---|---|---|
Creating graphs | Yes | No | No | No |
Deleting graphs | Yes | No | No | No |
Querying graphs | Yes | Yes | Yes | Yes |
Accessing graphs | Yes | Yes | Yes | No |
Importing data | Yes | Yes | No | No |
Creating metadata | Yes | Yes | No | No |
Viewing metadata | Yes | Yes | Yes | Yes |
Copying metadata | Yes | Yes | No | No |
Editing metadata | Yes | Yes | No | No |
Deleting metadata | Yes | Yes | No | No |
Clearing data | Yes | Yes | No | No |
Backing up graphs | Yes | Yes | No | No |
Restoring graphs from backups | Yes | Yes | No | No |
Deleting backups | Yes | Yes | No | No |
Querying backups | Yes | Yes | Yes | Yes |
Starting graphs | Yes | Yes | No | No |
Stopping graphs | Yes | Yes | No | No |
Upgrading graphs | Yes | Yes | No | No |
Exporting graphs | Yes | Yes | No | No |
Viewing results in the task center | Yes | Yes | Yes | Yes |
Resizing a graph | √ | No | No | × |
Expanding a graph | √ | No | No | × |
Restarting a graph | √ | Yes | No | × |
Configuring fine-grained permissions | √ | Yes | No | × |
Configuring user groups | √ | Yes | No | × |
Importing IAM users | √ | Yes | No | × |
Viewing user details | √ | Yes | Yes | √ |
GES Operation | Dependent OBS Permission |
|---|---|
Viewing metadata | OBS Viewer policy or OBS Buckets Viewer role |
Creating, importing, copying, editing, and deleting metadata | OBS Operator policy or Tenant Administrator role |
Creating, importing, and exporting graphs | OBS Operator policy or Tenant Administrator role |
GES Operation | Dependent IAM Permission |
|---|---|
Importing IAM users | iam:users:listUsers (custom policy), IAM ReadOnlyAccess (system policy), or Server Administrator role |
Creating or editing a user group | iam:users:listUsers (custom policy), IAM ReadOnlyAccess (system policy), or Server Administrator role |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.

