Skip to main content

Manage Platform Roles

This guide introduces the two types of platform roles in Zilliz Cloud: organization roles and project roles, and explains how to manage them.

Manage organization roles

Organization roles control organization-level access. Use organization roles to manage permissions for members, groups, organization settings, billing and subscriptions, security settings, organization alerts, platform audit log visibility, API keys, project management, and recycle bin operations.

📘Note

Organization roles are for organization-level resources only. They do not define cluster, database, or collection permissions.

Predefined organization roles

The following table explains the 3 predefined organization roles.

RoleDescriptionCan be edited?
Organization OwnerFull organization-level administration, including access control, settings, billing, security, service principals, and project role assignments.No
Billing AdminManage billing and subscriptions with read-only access to relevant organization and project context.No
PublicBaseline login-only role automatically granted to every organization member.No

Manage project roles

Project roles control access within a specific project. Use project roles to manage project members, cluster lifecycle operations, on-demand compute access, integrations, backups, migrations, alerts, volumes, and project-scoped data access.

📘Note

A project role belongs to a specific project. When you assign a project role, the assignment applies only to the selected project.

Predefined project roles

The following table explains the 4 pre-defined project roles.

RoleBest forTypical permissions
Project AdminProject owners and platform administrators.Full project administration, including collaborators, roles, cluster lifecycle, compute, and data access.
Data AdminDatabase administrators and platform engineers.Data administration, such as scaling, backup, cluster operations, and data access.
Data OperatorApplication teams and data engineers.Read and write data operations with limited project administration.
Data ViewerAnalysts, developers, and read-only applications.Read-only access for viewing, querying, and search workflows.

Custom project roles

Create a custom project role when predefined roles do not match your team's responsibilities. A custom project role can combine platform permissions, compute permissions, and data access permissions within the project.

Create a custom project role

1

Open the target project.

2

Go to Access Control.

3

Open the Project Roles tab.

4

Click + Project Role.

IlOjwjvJwhqzu4bUqodcngrtnCg

5

Select a role template and click Next.

ReCmbb1xmoBkZJxbzFScSkewnLb

6

Enter the custom role name and description.

MQf2wvFB2hzZ36bqtqlc8gLqnWg

7

Configure role access and click Create. For a full list of the privileges you can add to a custom project role, see Resource Privilege Reference.

Q7qSb7glyojMIfxjpLrcBrX5naf

Edit a custom project role

Edit a custom project role when the permission set needs to change. Changes apply to all users, groups, or customized API keys that are granted the role.

1

Open the target project.

2

Go to Access Control.

3

Open the Project Roles tab.

4

Find the target custom role, and select Edit from the Actions menu.

HMbXwwXMvhE92KbOheUcaxIGnud

5

Update the role details or permissions and click Save.

JoE9bvCe8ofqBPxIqo9cP1lPnZf

Delete a custom project role

📘Note

You cannot delete a project role that is still assigned to users, groups, or service principals. Remove existing assignments before deleting the role.

L4qGwxOVch3VRRbDLdRczHiZnBc

1

Open the target project.

2

Go to Access Control.

3

Open the Project Roles tab.

4

Find the target custom role, and select Delete from the Actions menu.

5

Confirm the deletion.

Ctrl I