Roles in CDM
- UpdatedJul 31, 2025
- 3 minutes to read
- Zurich
- DevOps
List of roles and permissions in CDM.
Important: DevOps Config is now deprecated and no longer supported or available for new activation.
CDM roles

| Role title [name] | Permissions | Contains roles |
|---|---|---|
CDM Viewer [sn_cdm.cdm_viewer] |
Note: If the Maintained by group is set at the application level to view config data, then this user must be a member of the group. |
|
| Event Management user [evt_mgmt_user] |
|
itil |
CDM Editor [sn_cdm.cdm_editor] |
Note: The cdm_editor role doesn’t grant permission to create/update/delete an application and its deployables, or to change the Enforce validation
setting on deployables. If the Maintained by group is set at the application level to view config data, then this user must be a member of the group. |
cdm_viewer |
CDM Exporter Editor [sn_cdm.cdm_exporter_editor] |
Create/update/delete exporters. | cdm_viewer |
CDM Policy Editor [sn_cdm.cdm_policy_editor] |
|
|
CDM Secrets [sn_cdm.cdm_secrets] |
Note: The cdm_secrets role is effective only with the cdm_viewer, cdm_editor, or cdm_admin role. |
None |
Application Service Admin [sn_cdm.app_service_admin] |
Enables the CDM Admin to create an application service. | None |
CDM Admin [sn_cdm.cdm_admin] |
|
|
CDM All App Access [sn_cdm.cdm_all_app_access] |
Note: The cdm_all_app_access role is effective only with the cdm_admin, cdm_editor, or cdm_viewer roles.
|
None |