Custom roles
- Last Updated: October 6, 2026
- 4 minute read
- Progress Data Cloud
- Documentation
PDC's built-in roles are sufficient for most users. However, a tenant administrator may want to grant a user just enough access to perform a function without the additional permissions granted by a built-in role. For example, perhaps a user should be able to call a MarkLogic management endpoint without the broader access provided by the MarkLogic Developer role.
Video
This video illustrates how to add a custom role.
Add a custom role
This procedure explains how to add a custom role.
To add a custom role:
-
Click the Configure menu.
-
Click Roles.
-
Click Add custom role.
-
Enter a role name.
-
Select the service category. The service category determines where a role is located when a user is added, default roles are set, or a service account is created.
-
Enter the service role name. This is the actual role name (text) passed to the service. The exact text specified in this field will be passed to the hosted application. For details on MarkLogic, see MarkLogic. For details on Semaphore, see Semaphore.
-
Enter a description.
-
Choose where the role is assigned:
- If you select Progress Data Cloud, the role will be assigned within Progress Data Cloud.
- If you select Microsoft Entra ID, the role will be assigned using Entra role mapping. Entra role mapping allows you to preconfigure role assignments so that Progress Data Cloud automatically applies a role based on your Entra ID app role assignments during sign-in. See Microsoft Entra ID app roles for details. Any role assigned through Entra ID appears on the Role Group with
after it. This indicates that the role is assigned through an external service provider when a user signs in.
-
Click Save.
-
The role appears in the service category you specified. The
indicates that the role is a custom role.

ml-custom-role will appear in the MarkLogic service category and is assigned to users in Progress Data Cloud.

ml-custom-role appears on the MarkLogic tab of the Users screen.
MarkLogic
For MarkLogic, the service role name maps to the MarkLogic Server External Name set for a security role.


TestRole maps to the MarkLogic Server
External Name set for a security role.
Manage MarkLogic Server Service roles
After you create a Progress Data Cloud role for a MarkLogic Server Service instance, and if you also have the MarkLogic Administrator role, you can manage the new role directly in the MarkLogic Server Service Admin UI by clicking
for that role. In the sidebar that appears, you can create, edit, and delete the MarkLogic Server Service role that you want to associate with the new Progress Data Cloud role.
Semaphore
If the service category is Semaphore then the role value specified in Service Role Name is passed to Semaphore Studio. However, Semaphore Studio needs to be manually configured. To do this, contact Customer support.

TestRole2 will be passed to Semaphore Studio. Contact
Customer support to configure this functionality.