DocsRoles and Navigation

Roles and Navigation

Roles and Navigation explains the four current SDM roles, the pages each role sees, and why hiding a menu item is not the only authorization check.

Where to find it: Documentation > DNS Manager > Roles and Navigation.

Available to: All authenticated users. Root manages non-root accounts from Users.

What this page does

SDM uses root, admin, operator, and viewer. Root owns server-wide administration. Admin receives DNS, Cloudflare, self-security, and license surfaces. Operator and viewer receive the smaller DNS and self-security workspace. The backend still validates the signed-in identity, role, zone ownership, and action on every request.

Before you start

Sign in with your own account. Do not share root credentials to make a menu item appear; assign the smallest role and zone access that matches the work.

Current role matrix

RoleSidebar pagesIntended use
rootDashboard, DNS Zones, Cluster Settings, Cluster Nodes, Monitor, API Sources, Cloudflare, Local Settings, Backup, Users, Audit, Logs, Version, License.Provider/server ownership, topology, security policy, retention, recovery, and cross-user administration.
adminDashboard, DNS Zones, Cloudflare, Security, License.DNS and provider administration without root's cluster and operating-system controls.
operatorDashboard, DNS Zones, Security.Scoped operational DNS work and management of the operator's own password, API key, 2FA, and IP rules.
viewerDashboard, DNS Zones, Security.Read-oriented access. Effective action permission and zone scope still determine which controls succeed.
  • The sidebar search filters pages already available to the current role.
  • The header search opens available modules without granting new access.
  • The account control opens self-service Security; the theme control changes only presentation.
  • AI Mode keeps the same authenticated role and cannot turn a hidden or forbidden operation into an allowed one.
  • Logout revokes the native session where present and closes the browser session.

How to use it

  1. Confirm the username and expected role after sign-in.
  2. Compare the visible sidebar with the matrix above.
  3. Use sidebar or header search to open an allowed page.
  4. If an expected page is missing, ask root to review the account rather than guessing a direct URL.
  5. For DNS work, confirm the zone is assigned to the correct user before attempting a mutation.

Result and next check

The operator sees only the workspace intended for the account, and actions are additionally constrained by backend permission and ownership checks. SDM has no hosting-style reseller role; integrations should not invent one.

Theme color