Atlas User Roles
On this page
Atlas user roles define the actions Atlas users can perform in
organizations, projects, or both. Organization and project Owners
can manage Atlas users and their roles within their respective
organizations and projects.
You can apply these permissions only on the the organization level or the project level. So, you should carefully plan the hierarchy of your organizations and projects. To learn more, see Cluster Management.
Organization Roles
Organization Role (UI) | Organization Role (API) | Description |
---|---|---|
ORG_OWNER | Grants root access to the organization, including:
| |
ORG_GROUP_CREATOR | Grants the following access:
| |
ORG_BILLING_ADMIN | Grants the following access:
| |
ORG_BILLING_READ_ONLY | Grants the following access:
| |
ORG_READ_ONLY | Provides read-only access to the settings, users, and projects
in the organization. | |
ORG_MEMBER | Provides read-only access to the settings and users in the organization and the projects they belong to. Unlike For an |
Project Roles
The following roles grant privileges within a project.
Project Role (UI) | Project Role (API) | Description |
---|---|---|
GROUP_OWNER | Grants the privileges to perform the following actions:
| |
GROUP_CLUSTER_MANAGER | A user with the
The
| |
GROUP_STREAM_PROCESSING_OWNER | A user with the
The
| |
GROUP_DATA_ACCESS_ADMIN | Grants access to the Data Explorer. This
role also grants privileges of Allows the user to perform the following Data Explorer actions:
The | |
GROUP_DATA_ACCESS_READ_WRITE | Grants access to the Data Explorer; specifically, the privileges to perform the following through the Atlas UI:
| |
GROUP_DATA_ACCESS_READ_ONLY | Grants access to the Data Explorer; specifically, to perform the following actions through the Atlas UI:
| |
GROUP_READ_ONLY | Grants metadata view-only access to the project control pane for all of the projects in the organization, including: all activity, operational data, users, and user roles. The user, however, cannot access the Data Explorer or retrieve process and audit logs. The user can view cluster metric charts. Grants access to MongoDB Charts only if invited
to the project by a | |
GROUP_SEARCH_INDEX_EDITOR | Grants the privileges to perform the following actions: |