Atlas user roles define the actions Atlas users can perform in
organizations, projects, or both. Organization and project Owners
can manage Atlas users and their roles within their respective
organizations and projects.
You can apply these permissions only on the the organization level or the project level. So, you should carefully plan the hierarchy of your organizations and projects. To learn more, see Cluster Management.
Organization Roles
Organization Role (UI) | Organization Role (API, CLI) | Description |
|---|---|---|
| Grants root access to the organization, including:
| |
| Grants the following access:
| |
| Grants the following access:
| |
| Grants the following access:
| |
| Grants the following access:
| |
| Provides read-only access to the settings, users, and projects in the organization. | |
| Provides read-only access to the settings and users in the organization and the projects they belong to. Unlike For an |
Project Roles
The following roles grant privileges within a project. All the project
roles also grant all the privileges included with the Project Read Only role.
Project Role (UI) | Project Role (API, CLI) | Description |
|---|---|---|
| Grants the privileges to perform the following actions:
| |
| Grants the privileges to perform the following actions:
This role doesn't grant permissions to perform the following actions:
| |
| Grants the privileges to perform the following actions:
The
| |
| Grants the privileges to create clusters. | |
| Grants the privileges to perform the following actions:
| |
| Grants the privileges to test cluster resilience. | |
| Grants the privileges to perform the following actions:
The
| |
| Grants privileges to perform the following actions:
| |
| Grants access to the Data Explorer, with the privileges to perform the following actions through the Atlas UI:
This role doesn't grant privileges to initiate backup or restore jobs. | |
| Grants access to the Data Explorer, with the privileges to perform the following actions through the Atlas UI:
| |
| Grants access to the Data Explorer, with the privileges to perform the following actions through the Atlas UI:
| |
| Grants the privileges to perform the following actions:
This role doesn't grant access to do the following tasks: This role doesn't grant privileges to export snapshots. | |
| Grants the privileges to perform the following actions:
This role doesn't grant access to do the following tasks:
| |
| Grants privileges to perform the following actions on clusters that support backups:
| |
| Grants privileges to perform the following actions on clusters that support restoring from backups:
This role doesn't grant privileges to download or export backups. | |
| Grants privileges to perform the following actions on clusters that support exporting backups:
| |
| Grants privileges to update project network settings for the following:
| |
| Grants the privileges to perform the following actions:
This role doesn't grant access to do the following tasks: | |
| Grants privileges to create, update, and delete triggers. | |
| Grants view-only access to the project control plane metadata. The user can view all activity, operational data, users, and user roles. The user, however, cannot access the Data Explorer or retrieve process and audit logs. The user can view cluster metric charts. Grants access to view connection details for Stream Processing Workspaces. Grants access to MongoDB Charts only if invited
to the project by a | |
| Grants privileges to perform the following actions:
This role doesn't grant privileges to access data through Data Explorer or MongoDB Charts. | |
| Grants the privileges to perform the following actions: | |
| Grants privileges to run the database | |
| Grants users the ability to provide MongoDB support access to clusters and cluster logs. This doesn't include privileges to support access settings at the organization level. | |
| Grants privileges to perform the following actions:
| |
| Grants privileges to create and delete Model API keys for the project. |