Administrators assign roles to users based on assignments and responsibilities. Set these roles in the application or map them from your identity provider if you have SSO integration enabled. If you start with a completely new Domino installation, the first user to log in is assigned the SysAdmin and Practitioner roles.
The available roles are:
-
SysAdmin - Administers instance with full administrative access.
-
ProjectManager - Manages organizations and project tags.
-
SupportStaff - Manages compute-related functionality.
-
Practitioner - Uses compute and file storage.
-
ReadOnlySupportStaff - View compute-related configuration.
-
Librarian - Manages project library.
-
LimitedAdmin - SysAdmin without access to projects and data.
-
LicenseReviewer - Views license-related content.
-
Lite User - A user with no role. See Lite User.
Tip
| LimitedAdmin and LicenseReviewer roles do not grant any permissions to Projects or Data. |
By default, all new users are assigned the Practitioner role. You can change this with central configuration options.
When multiple roles are assigned to a user, permissions are additive. To grant users roles, you must be a SysAdmin.
-
In the Admin application, click Users.
-
Search for the username to grant permissions.
-
Click Edit and select the roles.
-
Click Save.
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
Create Project | ✓ | ||||||
View Project List | ✓ | ✓ | ✓ | ✓ | ✓ | ||
Fork Project | ✓ | ||||||
Archive Project | ✓ | ✓ | ✓ |
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
List and View Files | ✓ | ✓ | ✓ | ✓ | |||
Edit Files | ✓ | ||||||
Upload Files | ✓ |
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
Start Workspace | ✓ | ||||||
Stop Workspace | ✓ | ✓ | ✓ | ||||
Open Workspace | ✓ | ||||||
View Workspace History | ✓ | ✓ | ✓ | ✓ | ✓ | ||
Archive Workspace | ✓ | ✓ |
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
Start Job | ✓ | ✓ | |||||
Stop Job | ✓ | ✓ | ✓ | ✓ (Public projects only) | |||
View Job History | ✓ | ✓ | ✓ | ||||
Create Scheduled Job | ✓ | ||||||
Edit Scheduled Job | ✓ | ✓ | |||||
Delete Scheduled Job | ✓ | ✓ |
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
View Project Settings | ✓ | ✓ | ✓ | ✓ | ✓ | ||
Edit Project Settings | ✓ | ✓ | ✓ | ✓ |
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
Register a new experiment or a new run of an experiment | ✓ | ✓ | |||||
View/list/search experiments and runs (including metadata and artifacts) | ✓ | ✓ | ✓ | ||||
Delete (archive) an experiment or experiment run | ✓ | ✓ | |||||
Update an experiment or experiment run (includes logging artifacts, adding tags, etc.) | ✓ | ✓ |
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
Create model API | ✓ | ||||||
Be a model API "Owner" | ✓ | ||||||
Be a model API "Editor" | ✓ | ✓ | ✓ | ||||
Be a model API "Viewer" | ✓ | ||||||
Stop a model version | ✓ | ✓ | ✓ | ||||
View model settings | ✓ | ✓ | ✓ | ✓ | |||
Edit model settings | ✓ | ✓ | ✓ | ||||
Promote a model version to Prod | ✓ |
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
Publish or Start App | ✓ | ||||||
Stop App | ✓ | ✓ | ✓ | ||||
View App | ✓ | ✓ | ✓ |
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
View Launchers | ✓ | ✓ | ✓ | ||||
Create or Edit Launcher | ✓ | ||||||
Delete Launcher | ✓ | ||||||
Run Launcher | ✓ |
See Dataset permissions and Dataset Roles for more information.
Permission | Practitioner | SysAdmin | SupportStaff | ReadOnlySupportStaff | Librarian | Limited Admin | License Reviewer |
---|---|---|---|---|---|---|---|
Create Dataset | ✓ | ||||||
Mount/Unmount Dataset | ✓ | ||||||
Delete Dataset Snapshot | ✓ | ✓ | |||||
List All Datasets on Global Data Page | ✓ | ✓ | |||||
List All Datasets and Snapshots in Admin Application |