Roles and permissions
DonkeyFleet recognizes three realm roles.
| Capability | read | approve | administer |
|---|---|---|---|
| View Home, Inventory, Capacity, Audit | Yes | Yes | Yes |
| View policies and infrastructure | Yes | Yes | Yes |
| Mark notifications read | Yes | Yes | Yes |
| Approve, reject, or move eligible work to backlog | No | Yes | Yes |
| Bind an adopted relationship to a profile | No | Yes | Yes |
| Register or archive infrastructure | No | No | Yes |
| Create or change policy | No | No | Yes |
| Change runtime safety controls | No | No | Yes |
| Reset local development data | No | No | Yes, when deployment unlocks it |
Assign only the lowest role needed. A person who approves deletion should not share accounts, and the identity provider should preserve stable subjects for audit.
ONTAP permissions
Use separate credentials or roles for source and destination clusters:
- source-role credentials need observation access only;
- destination-role credentials need observation plus the specific volume and SnapMirror operations DonkeyFleet manages.
The precise minimum ONTAP RBAC command set is not yet published as a stable product contract. Validate permissions in dry-run and a non-production destination before rollout.