Roles and Navigation
Roles and Navigation explains the four current SDM roles, the pages each role sees, and why hiding a menu item is not the only authorization check.
Where to find it: Documentation > DNS Manager > Roles and Navigation.
Available to: All authenticated users. Root manages non-root accounts from Users.
What this page does
SDM uses root, admin, operator, and viewer. Root owns server-wide administration. Admin receives DNS, Cloudflare, self-security, and license surfaces. Operator and viewer receive the smaller DNS and self-security workspace. The backend still validates the signed-in identity, role, zone ownership, and action on every request.
Before you start
Sign in with your own account. Do not share root credentials to make a menu item appear; assign the smallest role and zone access that matches the work.
Current role matrix
| Role | Sidebar pages | Intended use |
|---|---|---|
root | Dashboard, DNS Zones, Cluster Settings, Cluster Nodes, Monitor, API Sources, Cloudflare, Local Settings, Backup, Users, Audit, Logs, Version, License. | Provider/server ownership, topology, security policy, retention, recovery, and cross-user administration. |
admin | Dashboard, DNS Zones, Cloudflare, Security, License. | DNS and provider administration without root's cluster and operating-system controls. |
operator | Dashboard, DNS Zones, Security. | Scoped operational DNS work and management of the operator's own password, API key, 2FA, and IP rules. |
viewer | Dashboard, DNS Zones, Security. | Read-oriented access. Effective action permission and zone scope still determine which controls succeed. |
Navigation tools
- The sidebar search filters pages already available to the current role.
- The header search opens available modules without granting new access.
- The account control opens self-service Security; the theme control changes only presentation.
- AI Mode keeps the same authenticated role and cannot turn a hidden or forbidden operation into an allowed one.
- Logout revokes the native session where present and closes the browser session.
How to use it
- Confirm the username and expected role after sign-in.
- Compare the visible sidebar with the matrix above.
- Use sidebar or header search to open an allowed page.
- If an expected page is missing, ask root to review the account rather than guessing a direct URL.
- For DNS work, confirm the zone is assigned to the correct user before attempting a mutation.
Result and next check
The operator sees only the workspace intended for the account, and actions are additionally constrained by backend permission and ownership checks. SDM has no hosting-style reseller role; integrations should not invent one.
Theme color