Skip to main content

Administrating MarkLogic Server

Creating a Role

To create a role, follow these steps:

  1. Click the Security icon in the left tree menu.

  2. Click the Roles icon.

  3. Click the Create tab. The Role Configuration page appears.

  4. Type in a name for the role in the Role Name field.

  5. [OPTIONAL] Type in a description for the role.

  6. If you want to place the role into the named compartment, enter name of the compartment in the Compartment field. Compartments provide an additional level of organization and control by grouping together related roles. They act as a higher-level container for roles and can be used to define access privileges for a specific set of resources. For example, you may have a compartment called "Finance" that contains roles such as "Finance Manager," "Accountant," and "Auditor."

    If a document has any permissions (role/capability pairs) with roles that have a compartment, then the user must have those roles with each of the compartments (regardless of which permission they are in) to perform any of the capabilities.

  7. If the role is to be mapped for external security purposes, enter one or more External Names. See External Security in Securing MarkLogic Server.

  8. Under the Roles section, select the roles from which this role will inherit.

  9. Under the Execute Privileges section, select from the available execute privileges to be associated with the role.

  10. Under the URI privileges section, select from the available URI privileges to be associated with the role.

  11. [OPTIONAL] Create default permissions for this role. Select a role and pair the role with the appropriate capability (read, insert, update). Click more permissions to add more permissions.

  12. [OPTIONAL] Create default collections for this role. Type in the collection URI for each collection you want to add to the role’s default collections. Click more collections to add more collections.

  13. Click OK.

The role is now added to the system and the Role Configuration page appears. If you want to add more default permissions or collections to the role, scroll down to the section for default permissions or collections.