Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Hermes Messaging Service roles

Hermes Messaging Service is installed with these roles.

To learn more about managing subscriptions, see Managing per-user subscriptions in Subscription Management and contact your account representative.

Parent Topic:Hermes Messaging Service reference

Related topics

Hermes Messaging Service components

Hermes Messaging Service security model

Hermes Messaging Service system properties

Hermes background jobs

Hermes Messaging Service domain separation

Hermes Messaging Service viewer [hermes_viewer]

Enables users to view topics and namespaces in Hermes

Contains Roles

List of roles contained within the role.

None.

Groups

List of groups this role is assigned to by default.

None.

Special considerations

None.

Hermes Messaging Service administrator [hermes_admin]

Enables users to access the Hermes Messaging Service Topic Inspector.

Contains Roles

List of roles contained within the role.

  • kafka_namespace_admin
  • hermes_viewer

Groups

List of groups this role is assigned to by default.

None.

Special considerations

Note: Avoid granting an admin role when more specialized roles are available.

Kafka administrator [kafka_admin]

Enables users to manage the integration with Apache Kafka, including topics and settings related to Kafka subscriptions.

Contains Roles

List of roles contained within the role.

  • hermes_viewer
  • stream_connect_alert_viewer
  • view_changer
  • fd_read_flows

Groups

List of groups this role is assigned to by default.

None.

Special considerations

Note: Avoid granting an admin role when more specialized roles are available.

Kafka namespace administrator [kafka_namespace_admin]

Enables users to manage Kafka namespace definitions.

Contains Roles

List of roles contained within the role: kafka_admin.

Groups

List of groups this role is assigned to by default.

None.

Special considerations

Stream Connect administrators with the kafka_namespace_admin role can view message data across different domains.

For example, in a Managed Service Provider (MSP) instance with Kafka integrations in multiple domains, managing namespace definitions properly is important to maintain separation between domains, so don't grant this role to administrators within a single domain.