Skip to main content
NetApp Console local deployment

NetApp Console local deployment access roles

Contributors netapp-tonias netapp-ml94669

Identity and access management (IAM) in NetApp Console local deployment provides predefined roles that you can assign to the members of your organization across different levels of your resource hierarchy. Before you assign these roles, you should understand the permissions that each role includes. Roles fall into the following categories: platform, application, and data service.

Platform roles

Platform roles grant NetApp Console local deployment administration permissions, including role assignment and user management. The Console local deployment has several platform roles.

Platform role Responsibilities

Organization admin

Allows a user unrestricted access to all fleets and folders within an organization, add members to any fleet or folder, as well as perform any task and use any data service that does not have an explicit role associated with it.

Users with this role manage your organization by creating folders and fleets, assigning roles, adding users, and managing systems if they have the proper credentials.

Folder or fleet admin

Allows a user unrestricted access to assigned fleets and folders. Can add members to folders or fleets they manage, as well as perform any task and use any data service or application on resources within the folder or fleet they are assigned.

Federation admin

Allows a user to create and manage directory service federations with the Console so users can authenticate with their existing directory credentials.

Federation viewer

Allows a user to view existing directory service federations with the Console. Cannot create or manage federations.

Super admin

Gives the user all of admin roles. This role is designed for smaller organizations that may not need to distribute Console responsibilities across multiple users.

Super viewer

Gives the user all viewer roles. This role is designed for smaller organizations that may not need to distribute Console responsibilities across multiple users.

Application roles

The following is a list of roles in the application category. Each role grants specific permissions within its designated scope. Users without the required application or platform role cannot access the respective application.

Application role Responsibilities

Operation support analyst

Provides access to alerts and monitoring tools such as the Audit page.

Storage admin

Administer storage health and governance functions, discover storage resources, as well as modify and delete existing systems.

Storage viewer

View storage health and governance functions, as well as view previously discovered storage resources. Cannot discover, modify, or delete existing storage systems.

System health specialist

Administer storage and health and governance functions, all permissions of the Storage admin except cannot modify or delete existing systems.

Data service roles

The following is a list of roles in the data service category. Each role grants specific permissions within its designated scope. Users who do not have the required data service role or a platform role will be unable to access the data service.

Data service role Responsibilities

Backup and recovery super admin

Perform any actions in NetApp Backup and Recovery.

Backup and recovery admin

Perform backups to local snapshots, replicate to secondary storage, and back up to object storage.

Backup and recovery restore admin

Restore workloads in the Backup and Recovery.

Backup and recovery clone admin

Clone applications and data in the Backup and Recovery.

Backup and recovery viewer

View Backup and Recovery information.

Classification viewer

Allows users to view NetApp Data Classification scan results.


Users with this role can view compliance information and generate reports for resources that they have permission to access. These users can't enable or disable scanning of volumes, buckets, or database schemas. Data Classification does not have an admin role.

SnapCenter admin

Provides the ability to back up snapshots from on-premises ONTAP clusters using NetApp Backup and Recovery for applications. A member who has this role can complete the following actions:

* Complete any action from Backup and Recovery > Applications
* Manage all systems in the fleets and folders for which they have permissions
* Use all NetApp Console services

SnapCenter does not have a viewer role.