Skip to main content
Administrators assign roles to users based on assignments and responsibilities. Set these roles in the application or map them from your identity provider if you have SSO integration enabled. If you start with a completely new Domino installation, the first user to log in is assigned the SysAdmin and Practitioner roles. The available roles are:
  • SysAdmin - Administers instance with full administrative access (not available on Domino Cloud).
  • CloudAdmin - Administers Domino Cloud instance with limited administrative access (Domino Cloud only).
  • ProjectManager - Manages organizations and project tags.
  • SupportStaff - Manages compute-related functionality.
  • Practitioner - Uses compute and file storage.
  • ReadOnlySupportStaff - View compute-related configuration.
  • Librarian - Manages project library.
  • LimitedAdmin - SysAdmin without access to projects and data.
  • LicenseReviewer - Views license-related content.
  • Lite User - A user with no role. See Lite User.
  • GovernanceAdmin - Manages policies with Domino Governance. See GovernanceAdmin role.
LimitedAdmin and LicenseReviewer roles do not grant any permissions to Projects or Data.
By default, all new users are assigned the Practitioner role.

Edit roles

When multiple roles are assigned to a user, permissions are additive. To grant users roles, you must be a SysAdmin or a CloudAdmin. SysAdmins can grant any role to any user. CloudAdmins can grant the CloudAdmin and Practitioner roles to CloudAdmins and Practitioners.
  1. In the Admin application, click Users.
  2. Search for the username to grant permissions.
  3. Click Edit and select the roles.
  4. Click Save.

Actions for specific roles

Project overview actions

File actions

Workspace actions

Job actions

Project settings actions

Experiment management actions

Model Registry actions

Domino endpoint actions

App actions

Launcher actions

Dataset actions

See Dataset permissions and Dataset roles for more information.

Environment actions

As a reminder, your organization incurs costs when anyone creates or stores environments.
*Only admins can edit global environments. Practitioner users can only edit a global environment if they are an owner.

Administrator actions

*CloudAdmins can only manage hardware tiers if the configuration records key com.cerebro.domino.dominoCloud.cloudAdmin.canManageHwTiers is set to true. **MongoDB access is disabled in Domino Cloud.

Organization actions

You cannot delete organizations after you create them.

More information about specific roles

Project manager role

When Project Managers are members of organizations, their role grants them owner-level access to all projects that are owned by other members of the organizations. This allows the Project Manager to see these projects and their assets in the Projects Portfolio and Assets Portfolio. The Project Manager might also have the ability to add users to these organizations, thereby gaining contributor access to those users’ projects. For this reason, the Project Manager must be treated as a highly privileged role, similar to System Administrator.

CloudAdmin role

CloudAdmins are given most of the access SysAdmins have, but not all. CloudAdmins are only available on Domino Cloud. CloudAdmins cannot do the following:
  • Manage configuration records
  • Manage feature flags
  • Manage email configuration
  • Manage search index
  • Manage API keys
  • Run MongoDB commands
  • View Kubernetes dashboard
  • Restart Nucleus
CloudAdmins have full user management capabilities with one restriction: they cannot manage users with the SysAdmin role or assign the SysAdmin role to any user.

Lite user role

A user with no roles is called a Lite User or, in some contexts, a Results Consumer. They have restricted feature access and may have a different licensing status. Lite Users have permission to do the following:
  • View the project list.
  • View files in a project.
  • View Workspace history.
  • View Job history.
  • Be added as collaborators of Domino endpoints.
  • View Apps.
  • View and run Launchers (if permitted in project settings).
  • List and view Environments.
  • View experiments.

Data analyst role

The Data Analyst role is for users who have some technical background and coding experience in Python and R, but who do not need access to all the MLOps features of Domino. For more information, see Data Analyst role.

GovernanceAdmin role

The GovernanceAdmin role has permission to do the following:
  • View bundles.
  • View approvals.
  • Query audit events.
  • View policy overviews.
  • Manage policies evidence templates.
For more information, see Domino Governance policies.