Unify and manage your data

ROLE_ADMIN_USER Access permissions

Learn about ROLE_ADMIN_USER role to manage access permissions for managing user operations.

Assign roles to user and group accounts to grant them permissions (access rights and privileges). For more information, see User Management at a glance.

ROLE_ADMIN_USER is a critical high-privilege system role for customer-scoped user management. It grants access to manage users, groups, roles, and related user management operations within the same customer.

In the role hierarchy, lower roles are those assigned below ROLE_ADMIN_USER.

Role assignment limits

A user with ROLE_ADMIN_USER can assign ROLE_ADMIN_USER, ROLE_ADMIN_TENANT, and lower roles only within the same customer for which that role is granted.

ROLE_ADMIN_USER cannot assign ROLE_ADMIN_CUSTOMER.

This role can manage customer-scoped users, groups, and roles, but it does not grant the higher customer-scoped administrative role.

Access permissions

This table identifies the Reltio access permissions for Reltio services, resources, and sub resources defined for the ROLE_ADMIN_USER system role.

Permissions forAccess rights (service/ resource/ sub resource)Access privileges
Accessing all APIs related to client managementAuth.customer.clients
  • CREATE/READ/UPDATE/DELETE
Accessing APIs that manage the customer specific groupsAuth.customer.groups
  • CREATE/READ/UPDATE/DELETE
Accessing APIs that manage the customer specific rolesAuth.customer.roles
  • CREATE/READ/UPDATE/DELETE
Accessing all APIs related to user management Auth.customer.user
  • CREATE/READ/UPDATE/DELETE
Accessing the authentication audit logAuth.monitoring
  • READ
Accessing all Reltio system rolesAuth.globalRoles
  • READ
Accessing all Reltio servicesAuth.reltioServices
  • READ
Accessing UI modeler details in the consoleconsole.uimodeler
  • READ/UPDATE
Using APIs for tenant physical configurationMDM.config.physical
  • READ
Accessing recommendation service management for search facetsrecommender.management
  • CREATE/READ/UPDATE/DELETE
Accessing recommendation queryingrecommender.recommendation
  • CREATE/READ
Accessing recommendation service statusrecommender.status
  • READ