Creating a Standalone Role

Add a new standalone role to the database.

Prerequisites
Database Version Role-Based Standalone Role Privileges
SAP Sybase IQ 15.3 and 15.4 Not supported.
SAP Sybase IQ 16.0 Create a role – you must have the MANAGE ROLES system privilege.
Grant a role during standalone role creation – you must have one of:
  • Administrative rights over the role being granted (role administrator)
  • MANAGE ROLES system privilege if the role being granted has a global role administrator

Grant a system privilege during standalone creation – you must have administrative rights over the system privilege being granted.

Task
  1. In the Perspective Resources view, select the resource, and select Resource > Administration Console.
  2. In the left pane, expand IQ Servers > Security > Role-Based, and then select Standalone Roles.
  3. Click the arrow next to Standalone Roles and select New.
    The Create Standalone Role Wizard appears.
  4. On the Welcome page, specify
    Option Description
    Select a resource on which the user will be created. Select a resource from the list.
    Note: If the selected resource does not support role-based security, an error message appears.
    What do you want to name the new user? Enter a unique user ID.
  5. Click Next.
  6. (Optional) On the Administrators page, select one or more administrators.
    Note: It is strongly recommended that you do not select any role administrators when creating a new role; add them once the creation process is complete. If at least one role administrator is specified during creation, global role administrators will be unable to manage the role because the MANAGE ROLES system privilege is not automatically granted to the role.
    1. (Optional) If an administrator is selected, indicate whether the administrator is to be granted membership in the role along with administrative rights (Administrative and role) or administrative rights only (default).
      Note: Only one privilege level can be defined for all selected administrators when specified during the create process. However, the privilege level can be later modified. See
  7. Click Next.
  8. (Optional) On the Roles page, highlight a role to be granted. Click in the Grant Option column, click the arrow, and select the administrative rights to be granted.
    Grant Option Description
    Role only (default) Grantee can use the underlying system privileges of the role only.
    Administrative only Grantee can grant and revoke the selected role to other users and roles, but cannot use its underlying system privileges.
    Administrative and role Grantee can grant and revoke the selected role to other users and roles and use its underlying system privileges.
    When you grant a role to a user, user-extended role, or standalone role, unless otherwise noted, any underlying system privileges of the role being granted are automatically inherited by the user, user-extended role, or standalone role.
  9. Repeat step 8 to grant additional roles.
  10. Click Next.
  11. (Optional) On the System Privileges page, highlight a system privilege to be granted. Click in the Grant Option column, click the arrow, and select the administrative rights to be granted.
    Grant Option Description
    Privilege only (default) Grantees can perform authorized tasks requiring the selected privilege, but cannot grant the system privilege to other users and roles.
    Administrative only Grantees can grant and revoke the selected system privilege to other users and roles, but cannot perform authorized tasks requiring the selected system privilege.
    Administrative and privilege Grantees can grant and revoke the selected system privilege to other users and roles and can perform authorized tasks requiring the selected system privilege.
  12. Repeat step 11 to grant additional privileges.
  13. (Optional) On the Comment page, enter a comment for this user.
  14. Click Finish.
Related concepts
Manage Standalone Role Administrators
Manage Global Role Administrators of a Standalone Role
Related tasks
Deleting a Standalone Role
Adding a Grantee to a Standalone Role
Changing a Grantee's Administrative Rights on a Standalone Role
Removing a Grantee from a Standalone Role
Adding a Role to a Standalone Role
Changing Administrative Rights on an Underlying Role of a Standalone Role
Removing a Role from a Standalone Role
Adding a System Privilege to a Standalone Role
Changing Administrative Rights on a Privilege Granted to a Standalone Role
Removing a System Privilege from a Standalone Role
Generating Standalone Role DDL Commands
Viewing or Modifying Role-Based Standalone Role Properties
Authenticating a Login Account for a Managed Resource
Related reference
Role-Based Standalone Role Privilege Summary