Members have all capabilities
and cannot be denied any permissions in the metadata environment.1
|
|
Members can create,
update, and delete users, groups, roles (other than the unrestricted
role), internal accounts, logins, and authentication domains.2
|
|
Members can administer
the metadata server (monitor, stop, pause, resume, quiesce) and its
repositories (add, initialize, register, unregister, delete).3
|
|
1Unrestricted users are subject to denials in other authorization layers, can use only those logins that are assigned to them (or to groups to which they belong), and do not have implicit capabilities that are provided by components other than the metadata server. | |
2Restricted user administrators cannot update identities for which they have an explicit (white) or ACT (green) denial of WriteMetadata. | |
3Only someone who has an external user ID that is listed in the adminUsers.txt file with a preceding asterisk can delete, unregister, add, or initialize a foundation repository. Only an unrestricted user can analyze and repair metadata or perform tasks when the metadata server is paused for administration. |