1. What Each Role Can Do
volumegroup_manager​
Can do:
- Create, edit, and delete volumes
- Manage VolumeGroups
- Create, edit, and delete Access Policies
- Create and restore snapshots
- Mount volumes with mass-ctl
Cannot do:
- Manage users or group members
- Change system settings
usergroup_manager​
Can do:
- Add and remove users from the group
- View group membership
Cannot do:
- Create or manage volumes
- Access volume data directly
- Change system settings
Both roles combined (Dept Manager)​
Combined capabilities:
- Create and manage volumes
- Create and manage Access Policies
- Create and restore snapshots
- Manage group members
- Mount volumes with mass-ctl
Still cannot do:
- Manage system-wide user accounts
- Change system settings