Assign Roles for UI Access
- Capella Columnar
- how-to
Your level of access to the Capella UI is controlled using organization and project roles.
To interact with Capella Columnar using the Capella UI, you need an organization role and one or more project roles.
Prerequisites
-
You need to be the
Organization Owner
to invite new users to your organization and assign organization roles. -
To add collaborators to a project and assign project roles, you need to be a
Project Owner
for that project. If you’re theOrganization Owner
, you already have this role.
Assign Organization and Project Roles
To assign organization and project roles, complete the following steps:
-
Add the user to your organization.
-
Assign the user one or more organization roles.
-
-
Add the user as a collaborator to your project.
-
Assign the user one or more project roles.
-
Organization Roles and Columnar
Every user account in Couchbase Capella has an organization role that determines their privileges when working with the Capella UI at the organization level. For example, a user who’s an Organization Member cannot view any of the billing information inside the Capella UI, while an Organization Owner can.
Organization roles can control your level of access to both Columnar and operational resources in an organization.
A user with the Organization Owner role automatically has Project Owner
privileges and is a collaborator for all projects in the organization.
A user with the Project Creator role automatically has Project Owner
privileges and is a collaborator for all projects they create.
You can only view and work with projects where you’re a collaborator.
Project Roles and Columnar
Project roles are separate from organization roles, which grant overall privileges to Couchbase Capella. Project roles apply only at the project level and control your privileges in a project where you’re a collaborator.
Project roles control your level of access to both Columnar and operational resources in a project.
The following table describes the available project roles and their privileges as they apply to Capella Columnar. To see project roles as they apply to Capella operational, see Project Roles.
Role | Description |
---|---|
|
Provides complete Columnar cluster-management access. Users with this role can access data in any Columnar cluster in a project using the UI. A Project Owner has the following privileges when working with Capella Columnar:
A user with the |
|
Provides access to management actions for all Columnar clusters in a project. This role does not provide access to data. A Project Manager has the following privileges when working with Capella Columnar:
|
|
Provides read-only access to view all Columnar clusters in a project where you’re a collaborator. This role does not provide access to data. A Project Viewer has the following privileges for a project where you’re a collaborator:
|
|
Provides read-only access to view data in any Columnar cluster in a project where you’re a collaborator. This role allows the use of the Workbench to read data, but it cannot modify or write data. A Database Data Reader has the following privileges for a project where you’re a collaborator:
|
|
Provides read and write access to data in any Columnar cluster in a project where you’re a collaborator. This role allows the use of the Workbench to read and write data. A Database Data Reader/Writer has the following privileges for a project where you’re a collaborator:
|
Next Steps
-
To programmatically access data on a Columnar cluster, see Manage Access to Cluster Data.
-
To set up single sign-on (SSO) for your organization, see Add Federated and SSO Authentication.