All Products
Search
Document Center

Data Management:Permissions of system roles

Last Updated:Mar 28, 2026

Data Management (DMS) uses a role-based access model. Each user is assigned one of five system roles, which determines which features they can access across the DMS console.

System roles

RoleDescription
Regular userStandard access to day-to-day database development and data operations. Cannot manage instances, configure platform-level security settings, or administer other users.
Security administratorAll regular user access, plus control over sensitive data policies, permission templates, and operation auditing.
Database administrator (DBA)All regular user access, plus full SQL Console permissions, instance registration, database grouping, and task management.
DMS administratorFull access to all DMS features, including user management, platform configuration, security rules, and approval workflows.
Schema read-only userRead-only access to schema structures. Supports database development and DTS operations, but cannot register instances or manage platform-level security configuration (such as security rules, approval processes, or access IP whitelists).

Role permissions

The following tables list which features each role can access. For features that require database-level permissions — such as SQL Console and Database Development — the system role alone is not sufficient. You also need the appropriate permissions granted on the specific database.

Home page

All roles can access all home page features.

FeatureRegular userSecurity administratorDBADMS administratorSchema read-only user
My TicketsSupportedSupportedSupportedSupportedSupported
Followed AssetsSupportedSupportedSupportedSupportedSupported
My AssetsSupportedSupportedSupportedSupportedSupported
Accessible AssetsSupportedSupportedSupportedSupportedSupported
Recently Accessed AssetsSupportedSupportedSupportedSupportedSupported
Release NotesSupportedSupportedSupportedSupportedSupported
Instance ListSupportedSupportedSupportedSupportedSupported
Database ListSupportedSupportedSupportedSupportedSupported
Logical DB ListSupportedSupportedSupportedSupportedSupported
ShortcutsSupportedSupportedSupportedSupportedSupported

Data assets

FeatureRegular userSecurity administratorDBADMS administratorSchema read-only user
InstancesNot supportedNot supportedSupportedSupportedNot supported
CategoriesSupportedSupportedSupportedSupportedSupported

SQL Console

Note

Before running queries or making data changes in the SQL Console, make sure you have the required permissions on the target database.

FeatureRegular userSecurity administratorDBADMS administratorSchema read-only user
SQL ConsoleSupportedSupportedSupported (all features)Supported (all features)Supported

DBA and DMS administrator roles have permissions on all SQL Console features. Other roles access the SQL Console based on the permissions granted to them on specific databases.

Database development

Note

Database development features operate within the boundaries of your database permissions. Before submitting a ticket to modify a database, make sure you have the required permissions on that database or table. For example, to use Test Data Generation to insert records into a table, you need change permission on the database or the specific table.

CategoryFeatureRegular userSecurity administratorDBADMS administratorSchema read-only user
Schema changeSchema DesignSupportedSupportedSupportedSupportedSupported
Schema SynchronizationSupportedSupportedSupportedSupportedSupported
Shadow Table SynchronizationSupportedSupportedSupportedSupportedSupported
Empty Database InitializationSupportedSupportedSupportedSupportedSupported
Table Consistency RepairingSupportedSupportedSupportedSupportedSupported
Data changeNormal Data ModifySupportedSupportedSupportedSupportedSupported
Lockless ChangeSupportedSupportedSupportedSupportedSupported
Historical Data CleanupSupportedSupportedSupportedSupportedSupported
Data ImportSupportedSupportedSupportedSupportedSupported
Programmable Object PermissionsSupportedSupportedSupportedSupportedSupported
Data exportSQL Result Set ExportSupportedSupportedSupportedSupportedSupported
Database ExportSupportedSupportedSupportedSupportedSupported
SQL reviewSQL Audit TicketSupportedSupportedSupportedSupportedSupported
Environment constructionDatabase CloneSupportedSupportedSupportedSupportedSupported
Test Data GenerationSupportedSupportedSupportedSupportedSupported
Data trackingData Tracking TicketSupportedSupportedSupportedSupportedSupported
R&D SpaceDevOpsSupportedSupportedSupportedSupportedSupported
My TicketsSupportedSupportedSupportedSupportedSupported

DTS

CategoryFeatureRegular userSecurity administratorDBADMS administratorSchema read-only user
DTSData SynchronizationSupportedSupportedSupportedSupportedSupported
Data MigrationSupportedSupportedSupportedSupportedSupported
Change TrackingSupportedSupportedSupportedSupportedSupported
Data VerificationSupportedSupportedSupportedSupportedSupported
Data developmentTask OrchestrationSupportedSupportedSupportedSupportedSupported
Heterogeneous Database Migration (ADAM)Database EvaluationSupportedSupportedSupportedSupportedSupported
Application Evaluation and TransformationSupportedSupportedSupportedSupportedSupported
SQL ConversionSupportedSupportedSupportedSupportedSupported

Primary Features

Sub-feature

Regular user

Security administrator

DBA

Administrator

Schema read-only

Data Transmission Service (DTS)

Data synchronization

Supported

Support

Support

Support

Support

Data migration

Support

Support

Support

Support

Supported

Change tracking

Support

Support

Supported

Support

Support

Change tracking

Support

Support

Support

Support

Support

Data Development

Task orchestration

Support

Supported

Support

Supported

Support

Heterogeneous database migration (ADAM)

Database evaluation

Support

Support

Support

Support

Support

Application evaluation and transformation

Support

Support

Support

Support

Support

SQL conversion

Supported

Support

Support

Support

Support

Security and specifications

CategoryFeatureRegular userSecurity administratorDBADMS administratorSchema read-only user
Permission CenterPermission TicketsSupportedSupportedSupportedSupportedSupported
PermissionsSupportedSupportedSupportedSupportedSupported
Permission TemplatesNot supportedSupportedSupportedSupportedNot supported
Security RulesNot supportedNot supportedSupportedSupportedNot supported
Approval ProcessesNot supportedNot supportedSupportedSupportedNot supported
Access IP WhitelistNot supportedNot supportedNot supportedSupportedNot supported
Operation AuditSupportedSupportedSupportedSupportedSupported
Sensitive dataSensitive Data AssetsNot supportedSupportedSupportedSupportedNot supported
Rule ConfigurationsNot supportedSupportedSupportedSupportedNot supported
Sensitive Data AuditNot supportedSupportedSupportedSupportedNot supported
Data WatermarkSupportedSupportedSupportedSupportedSupported

Solutions

O&M

FeatureRegular userSecurity administratorDBADMS administratorSchema read-only user
UsersNot supportedNot supportedNot supportedSupportedNot supported
Configuration ManagementNot supportedNot supportedNot supportedSupportedNot supported
Database GroupingNot supportedNot supportedSupportedSupportedSupported
TaskNot supportedNot supportedSupportedSupportedNot supported
NotificationNot supportedNot supportedSupportedSupportedNot supported
Intelligent OperationNot supportedSupportedSupportedSupportedNot supported
Task Orchestration Operation CenterSupportedSupportedSupportedSupportedSupported