A Role is a core component of the IAM module on the FPT Cloud Portal. Role Management enables system administrators to define and assign roles with specific permissions to users when accessing the FPT Database Engine service.
Using roles enhances security by enforcing fine-grained access control, supports the principle of least privilege, and enables clear separation of responsibilities based on operational requirements.
The following steps provide detailed instructions on how to create a new Role and assign the required access permissions to that role.
Log in to the FPT Cloud Portal. After logging successfully, from the main menu, select IAM > Roles. The Role Management interface will display the list of existing roles, along with options to create, edit, or delete a role.
On the Role Management page, click Create role. The Create New Role screen will appear as follows:

Enter the basic information:
The configuration process for a Permission is detailed in step 3.
Click See more to display the information required for a permission:

After selecting a service type, the system automatically displays all available actions in the Action section and updates the permission name accordingly.

After entering all required information, select Create role to complete the role creation process.
After the role is created successfully, the new role will appear in the management list with the status Active and will be ready to be assigned to users. For instructions on assigning permissions, refer to User Group Management.
When needed, you can perform the following actions on the created role:
Edit role: This function allows you to modify the role’s name, description, and permissions in case of access requirement or security policy changes. To access this feature, on the Role Management page, select Edit role action next to the role you want to modify. Make the necessary changes and click Save to apply.
Delete role: This function allows you to remove unused roles, keeping the access control system clean and accurate. On the Role Management page, select Delete next to the role you want to remove. Confirm the deletion in the warning dialog to complete the process. Warning: Deleting a role may impact the access permissions of users and user groups currently assigned to that role. Once the role is deleted, all associated permissions are revoked immediately, which may cause disruption to the management and operation of cloud and DBaaS resources. Ensure that the role is not assigned to any User Group or IAM User before proceeding with the deletion.