Managing roles

About roles

Define roles and configure permissions to control access to database resources for authenticated users.

Add a superuser role

After enabling role-based access control, create your own superuser role, and then disable or drop the default cassandra role.

Creating roles for internal mode

Set up the primary login roles for users and accounts that are authenticated against the DSE database.

Creating roles for LDAP mode

Create roles that match group names in the LDAP server to manage role assignment with LDAP.

Creating roles for Kerberos principals

Create roles to match Kerberos principal name.

Binding a role to an authentication scheme

Prevent unintentional role assignment when a group name or user name is found in multiple schemes.

Configuring proxy roles for applications

Proxy roles allow an authenticated role to run CQL statements using a different role.

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM