Roles in CDM
List of roles and permissions in CDM.
Important: Starting with the Washington D.C. release, DevOps Config is being prepared for future deprecation. It will be hidden and no longer activated on new instances but will continue to be supported.
CDM roles
CDM role hierarchy
| Role title \[name\] | Permissions | Contains roles |
|---|---|---|
| CDM Viewer \[sn\_cdm.cdm\_viewer\] |
Note: If the Maintained by group is set at the application level to view config data, then this user must be a member of the group. | - \[sn\_pace.policy\_reader\] - \[itil\] - \[canvas\_user\] |
| Event Management user \[evt\_mgmt\_user\] |
| itil |
| CDM Editor \[sn\_cdm.cdm\_editor\] |
Note: The cdm_editor role doesn’t grant permission to create/update/delete an application and its deployables, or to change the Enforce validation setting on deployables. If the Maintained by group is set at the application level to view config data, then this user must be a member of the group. | cdm\_viewer |
| CDM Exporter Editor \[sn\_cdm.cdm\_exporter\_editor\] | Create/update/delete exporters. | cdm\_viewer |
| CDM Policy Editor \[sn\_cdm.cdm\_policy\_editor\] | - Create/update/delete policies. - Map policies to deployables. | - cdm\_viewer - \[sn\_pace.admin\] |
| CDM Secrets \[sn\_cdm.cdm\_secrets\] |
Note: The cdm_secrets role is effective only with the cdm_viewer, cdm_editor, or cdm_admin role. | None |
| Application Service Admin \[sn\_cdm.app\_service\_admin\] | Enables the CDM Admin to create an application service. | None |
| CDM Admin \[sn\_cdm.cdm\_admin\] | - Create/update/delete applications. - Create/update/delete deployables. - Create/update/delete config data. - Change settings on deployables to enforce snapshot validation. | - cdm\_editor - cdm\_exporter\_editor - cdm\_policy\_editor - app\_service\_admin - Model\_manager \(for create/update/delete of application model\) - \[itil\] \(for create/update/delete of SDLC components\) - \[itil admin\] |
| CDM All App Access \[sn\_cdm.cdm\_all\_app\_access\] | Note: The cdm_all_app_access role is effective only with the cdm_admin, cdm_editor, or cdm_viewer roles.
| None |
Parent Topic:DevOps Config roles