Built-In Roles and Privileges
On this page
The available Atlas built-in roles and specific privileges support a subset of MongoDB commands. See Unsupported Commands in M10+ Clusters for more information.
Built-in Roles
The following table describes the Atlas built-in roles and the MongoDB Roles they represent. Refer to Built-In Roles for a full description of the privilege actions that each role includes.
Note
Protected MongoDB Database Namespaces
The following databases are read-only for all users, including
those with the atlasAdmin
or clusterMonitor
role.
local
config
We discourage writing to the admin
database. Atlas manages multiple
collections in the admin
database, and these collections are read-only for
all users.
atlasAdmin
has the update
privilege on
the config.settings
collection to manage the balancer.
Atlas Built-in Role | MongoDB Role | Inherited Roles or Privilege Actions |
---|---|---|
| ||
| ||
| ||
| ||
| ||
| ||
| ||
| ||
| ||
| ||
|
To learn more about common commands that Atlas doesn't support with the current Atlas user privileges, see Unsupported Commands in M10+ Clusters
Specific Privileges
killOpSession
is specific to Atlas and applies to any user-configured database.
It inherits the following privilege actions: