Built-in roles and privileges

Introduction

Neo4j provides a set of built-in roles that can be used to control access to the database. The PUBLIC role is the default role for all users. It does not give any rights or capabilities regarding the data, not even read privileges. The rest of the built-in roles are hierarchical, with the reader role at the bottom and the admin role at the top with all privileges.

A user may have more than one assigned role, and the union of these determines what action(s) on the data may be undertaken by the user. For instance, a user assigned to the reader role can execute procedures, because all users are also assigned to the PUBLIC role, which enables that capability.

The built-in roles have the following default privileges:

PUBLIC
  • Access to the home database.

  • Execute procedures with the users' own privileges.

  • Execute user-defined functions with the users' own privileges.

  • Load data.

reader
  • Access to all databases.

  • Traverse and read on the data graph (all nodes, relationships, properties).

  • Show indexes and constraints along with any other future schema constructs.

editor
  • Access to all databases.

  • Traverse, read, and write on the data graph.

  • Write access, limited to creating and changing existing property keys, node labels, and relationship types of the graph. In other words, the editor role cannot add to the schema but can only make changes to already existing objects.

  • Show indexes and constraints along with any other future schema constructs.

publisher
  • Access to all databases.

  • Traverse, read, and write on the data graph.

  • Show indexes and constraints along with any other future schema constructs.

architect
  • Access to all databases.

  • Traverse, read, and write on the data graph.

  • Create/drop/show indexes and constraints along with any other future schema constructs.

admin
  • Access to all databases.

  • Traverse, read, and write on the data graph.

  • Load data.

  • Create/drop/show indexes and constraints along with any other future schema constructs.

  • Execute procedures using boosted privileges.

  • Execute admin procedures.

  • Execute user-defined functions using boosted privileges.

  • View/terminate queries.

  • Manage databases, users, roles, and privileges.

When an administrator suspends or deletes another user, the following rules apply:

  • Administrators can suspend or delete any other user (including other administrators), but not themselves.

  • When suspended, the user is no longer able to log back in until re-activated by an administrator.

  • There is no need to remove assigned roles from a user before deleting the user.

Deleting a user does not automatically terminate associated connections, sessions, transactions, or queries.

Neo4j provides the following built-in roles with default privileges and capabilities. The subset of the functionality that is available with Community Edition is also included. All of the commands require that the user executing the commands has the rights to do so.

Table 1. Built-in roles capabilities
Action reader editor publisher architect admin PUBLIC Available in Community Edition

Change own password

View own details

View own transactions

Terminate own transactions

View own privileges

View all databases

Access home database

Access all databases

Read data

View index/constraint

Write/update/delete existing data

Create new types of properties key

Create new types of nodes labels

Create new types of relationship types

Create/drop index/constraint

Create/delete user

Change another user’s name

Change another user’s password

Change another user’s home database

Suspend/activate user

Create/drop roles

Change role names

Assign/remove role to/from user

Create/drop/alter databases

Start/stop databases

Manage database access

Grant/deny/revoke privileges

View all users

View all roles

View all roles for a user

View all users for a role

View another user’s privileges

View all transactions

Terminate all transactions

Load data

Execute procedures

Execute functions

Execute admin procedures

Dynamically change configuration [1]

1. For more information, see Update dynamic settings

The PUBLIC role

All users are granted the PUBLIC role, and it can not be revoked or dropped. By default, it gives access to the default database and allows loading data, executing all procedures and user-defined functions.

The PUBLIC role cannot be dropped or revoked from any user, but the specific privileges for the role can be modified. In contrast to the PUBLIC role, the other built-in roles can be granted, revoked, dropped, and re-created.

Listing PUBLIC role privileges

SHOW ROLE PUBLIC PRIVILEGES AS COMMANDS
Table 2. Result
command

"GRANT ACCESS ON HOME DATABASE TO `PUBLIC`"

"GRANT EXECUTE FUNCTION * ON DBMS TO `PUBLIC`"

"GRANT EXECUTE PROCEDURE * ON DBMS TO `PUBLIC`"

"GRANT LOAD ON ALL DATA TO `PUBLIC`"

Rows: 4

Recreating the PUBLIC role

The PUBLIC role can not be dropped and thus there is no need to recreate the role itself. To restore the role to its original capabilities, two steps are needed.

First, all GRANT or DENY privileges on this role should be revoked (see output of SHOW ROLE PUBLIC PRIVILEGES AS REVOKE COMMANDS on what to revoke). Secondly, run these queries:

GRANT ACCESS ON HOME DATABASE TO PUBLIC
GRANT EXECUTE PROCEDURES * ON DBMS TO PUBLIC
GRANT EXECUTE USER DEFINED FUNCTIONS * ON DBMS TO PUBLIC
GRANT LOAD ON ALL DATA TO PUBLIC

The resulting PUBLIC role now has the same privileges as the original built-in PUBLIC role.

The reader role

The reader role can perform read-only queries on all graphs except for the system database.

Listing reader role privileges

SHOW ROLE reader PRIVILEGES AS COMMANDS
Table 3. Result
command

"GRANT ACCESS ON DATABASE * TO `reader`"

"GRANT MATCH {*} ON GRAPH * NODE * TO `reader`"

"GRANT MATCH {*} ON GRAPH * RELATIONSHIP * TO `reader`"

"GRANT SHOW CONSTRAINT ON DATABASE * TO `reader`"

"GRANT SHOW INDEX ON DATABASE * TO `reader`"

Rows: 5

Recreating the reader role

To restore the role to its original capabilities two steps are needed. First, execute DROP ROLE reader. Secondly, run these queries:

CREATE ROLE reader
GRANT ACCESS ON DATABASE * TO reader
GRANT MATCH {*} ON GRAPH * TO reader
GRANT SHOW CONSTRAINT ON DATABASE * TO reader
GRANT SHOW INDEX ON DATABASE * TO reader

The resulting reader role now has the same privileges as the original built-in reader role.

The editor role

The editor role can perform read and write operations on all graphs except for the system database, but it cannot create new labels, property keys or relationship types.

Listing editor role privileges

SHOW ROLE editor PRIVILEGES AS COMMANDS
Table 4. Result
command

"GRANT ACCESS ON DATABASE * TO `editor`"

"GRANT MATCH {*} ON GRAPH * NODE * TO `editor`"

"GRANT MATCH {*} ON GRAPH * RELATIONSHIP * TO `editor`"

"GRANT SHOW CONSTRAINT ON DATABASE * TO `editor`"

"GRANT SHOW INDEX ON DATABASE * TO `editor`"

"GRANT WRITE ON GRAPH * TO `editor`"

Rows: 6

Recreating the editor role

To restore the role to its original capabilities two steps are needed. First, execute DROP ROLE editor. Secondly, run these queries:

CREATE ROLE editor
GRANT ACCESS ON DATABASE * TO editor
GRANT MATCH {*} ON GRAPH * TO editor
GRANT WRITE ON GRAPH * TO editor
GRANT SHOW CONSTRAINT ON DATABASE * TO editor
GRANT SHOW INDEX ON DATABASE * TO editor

The resulting editor role now has the same privileges as the original built-in editor role.

The publisher role

The publisher role can do the same as editor, as well as create new labels, property keys and relationship types.

Listing publisher role privileges

SHOW ROLE publisher PRIVILEGES AS COMMANDS
Table 5. Result
command

"GRANT ACCESS ON DATABASE * TO `publisher`"

"GRANT MATCH {*} ON GRAPH * NODE * TO `publisher`"

"GRANT MATCH {*} ON GRAPH * RELATIONSHIP * TO `publisher`"

"GRANT NAME MANAGEMENT ON DATABASE * TO `publisher`"

"GRANT SHOW CONSTRAINT ON DATABASE * TO `publisher`"

"GRANT SHOW INDEX ON DATABASE * TO `publisher`"

"GRANT WRITE ON GRAPH * TO `publisher`"

Rows: 7

Recreating the publisher role

To restore the role to its original capabilities two steps are needed. First, execute DROP ROLE publisher. Secondly, run these queries:

CREATE ROLE publisher
GRANT ACCESS ON DATABASE * TO publisher
GRANT MATCH {*} ON GRAPH * TO publisher
GRANT WRITE ON GRAPH * TO publisher
GRANT NAME MANAGEMENT ON DATABASE * TO publisher
GRANT SHOW CONSTRAINT ON DATABASE * TO publisher
GRANT SHOW INDEX ON DATABASE * TO publisher

The resulting publisher role now has the same privileges as the original built-in publisher role.

The architect role

The architect role can do the same as the publisher, as well as create and manage indexes and constraints.

Listing architect role privileges

SHOW ROLE architect PRIVILEGES AS COMMANDS
Table 6. Result
command

"GRANT ACCESS ON DATABASE * TO `architect`"

"GRANT CONSTRAINT MANAGEMENT ON DATABASE * TO `architect`"

"GRANT INDEX MANAGEMENT ON DATABASE * TO `architect`"

"GRANT MATCH {*} ON GRAPH * NODE * TO `architect`"

"GRANT MATCH {*} ON GRAPH * RELATIONSHIP * TO `architect`"

"GRANT NAME MANAGEMENT ON DATABASE * TO `architect`"

"GRANT SHOW CONSTRAINT ON DATABASE * TO `architect`"

"GRANT SHOW INDEX ON DATABASE * TO `architect`"

"GRANT WRITE ON GRAPH * TO `architect`"

Rows: 9

Recreating the architect role

To restore the role to its original capabilities two steps are needed. First, execute DROP ROLE architect. Secondly, run these queries:

CREATE ROLE architect
GRANT ACCESS ON DATABASE * TO architect
GRANT MATCH {*} ON GRAPH * TO architect
GRANT WRITE ON GRAPH * TO architect
GRANT NAME MANAGEMENT ON DATABASE * TO architect
GRANT SHOW CONSTRAINT ON DATABASE * TO architect
GRANT CONSTRAINT MANAGEMENT ON DATABASE * TO architect
GRANT SHOW INDEX ON DATABASE * TO architect
GRANT INDEX MANAGEMENT ON DATABASE * TO architect

The resulting architect role now has the same privileges as the original built-in architect role.

The admin role

The admin role can do the same as the architect, as well as manage databases, aliases, users, roles and privileges.

The admin role can perform administrative tasks. These include the rights to perform the following classes of tasks:

  • Manage database privileges to control the rights to perform actions on specific databases:

    • Manage access to a database and the right to start and stop a database.

    • Manage indexes and constraints.

    • Allow the creation of labels, relationship types, or property names.

    • Manage transactions.

  • Manage DBMS privileges to control the rights to perform actions on the entire system:

    • Manage multiple databases.

    • Manage users and roles.

    • Change configuration parameters.

    • Manage sub-graph privileges.

    • Manage procedure security.

    • Manage load privileges to control the rights to load data from external sources.

These rights are conferred using privileges that can be managed through the GRANT, DENY and REVOKE commands.

Listing admin role privileges

SHOW ROLE admin PRIVILEGES AS COMMANDS
Table 7. Result
command

"GRANT ACCESS ON DATABASE * TO `admin`"

"GRANT ALL DBMS PRIVILEGES ON DBMS TO `admin`"

"GRANT CONSTRAINT MANAGEMENT ON DATABASE * TO `admin`"

"GRANT INDEX MANAGEMENT ON DATABASE * TO `admin`"

"GRANT LOAD ON ALL DATA TO `admin`"

"GRANT MATCH {*} ON GRAPH * NODE * TO `admin`"

"GRANT MATCH {*} ON GRAPH * RELATIONSHIP * TO `admin`"

"GRANT NAME MANAGEMENT ON DATABASE * TO `admin`"

"GRANT SHOW CONSTRAINT ON DATABASE * TO `admin`"

"GRANT SHOW INDEX ON DATABASE * TO `admin`"

"GRANT START ON DATABASE * TO `admin`"

"GRANT STOP ON DATABASE * TO `admin`"

"GRANT TRANSACTION MANAGEMENT (*) ON DATABASE * TO `admin`"

"GRANT WRITE ON GRAPH * TO `admin`"

Rows: 14

If the built-in admin role has been altered or dropped and needs to be restored to its original state, see Password and user recovery.

Recreating the admin role

You might need to recreate the admin role, for example, because you want to revoke the role-user mappings, or because its privileges have been modified and you want to restore it to its original capabilities.

Recreate the admin role after being dropped

This example assumes that you want to revoke all role-user mappings of the admin role and then recreate it with the same capabilities.

  1. Using a client such as Cypher Shell or the Neo4j Browser, connect as a user with rights to manage roles and privileges:

    bin/cypher-shell -u <username> -p <password>
  2. Run the following command to list the privileges that are currently granted to the admin role as commands:

    SHOW ROLE admin PRIVILEGES AS COMMANDS;
    +-------------------------------------------------------------+
    | command                                                     |
    +-------------------------------------------------------------+
    | "GRANT ACCESS ON DATABASE * TO `admin`"                     |
    | "GRANT ALL DBMS PRIVILEGES ON DBMS TO `admin`"              |
    | "GRANT CONSTRAINT MANAGEMENT ON DATABASE * TO `admin`"      |
    | "GRANT INDEX MANAGEMENT ON DATABASE * TO `admin`"           |
    | "GRANT LOAD ON ALL DATA TO `admin`"                         |
    | "GRANT MATCH {*} ON GRAPH * NODE * TO `admin`"              |
    | "GRANT MATCH {*} ON GRAPH * RELATIONSHIP * TO `admin`"      |
    | "GRANT NAME MANAGEMENT ON DATABASE * TO `admin`"            |
    | "GRANT SHOW CONSTRAINT ON DATABASE * TO `admin`"            |
    | "GRANT SHOW INDEX ON DATABASE * TO `admin`"                 |
    | "GRANT START ON DATABASE * TO `admin`"                      |
    | "GRANT STOP ON DATABASE * TO `admin`"                       |
    | "GRANT TRANSACTION MANAGEMENT (*) ON DATABASE * TO `admin`" |
    | "GRANT WRITE ON GRAPH * TO `admin`"                         |
    +-------------------------------------------------------------+
    
    14 rows
    ready to start consuming query after 39 ms, results consumed after another 0 ms
  3. Drop the existing admin role:

    DROP ROLE admin;
  4. Create a new admin role:

    CREATE ROLE admin;
  5. Run the commands from step 2 to recreate the admin role with its original capabilities:

    GRANT ACCESS ON DATABASE * TO `admin`;
    GRANT ALL DBMS PRIVILEGES ON DBMS TO `admin`;
    GRANT CONSTRAINT MANAGEMENT ON DATABASE * TO `admin`;
    GRANT INDEX MANAGEMENT ON DATABASE * TO `admin`;
    GRANT LOAD ON ALL DATA TO `admin`;
    GRANT MATCH {*} ON GRAPH * NODE * TO `admin`;
    GRANT MATCH {*} ON GRAPH * RELATIONSHIP * TO `admin`;
    GRANT NAME MANAGEMENT ON DATABASE * TO `admin`;
    GRANT SHOW CONSTRAINT ON DATABASE * TO `admin`;
    GRANT SHOW INDEX ON DATABASE * TO `admin`;
    GRANT START ON DATABASE * TO `admin`;
    GRANT STOP ON DATABASE * TO `admin`;
    GRANT TRANSACTION MANAGEMENT (*) ON DATABASE * TO `admin`;
    GRANT WRITE ON GRAPH * TO `admin`;

    The resulting admin role now has the same effective privileges as the original admin role.

Additional information about restoring the admin role can be found in the Recover the admin role.

Recreate the admin role after being modified

This example assumes that the admin role still exists, but its privileges have been modified, and you want to restore it to the original capabilities of the built-in admin role.

  1. Using a client such as Cypher Shell or the Neo4j Browser, connect as a user with rights to manage roles and privileges:

    bin/cypher-shell -u <username> -p <password>
  2. Create a new admin2 role:

    CREATE ROLE admin2;
  3. Run the following commands to recreate the admin2 role with the original capabilities of the built-in admin role:

    GRANT ACCESS ON DATABASE * TO `admin2`;
    GRANT ALL DBMS PRIVILEGES ON DBMS TO `admin2`;
    GRANT CONSTRAINT MANAGEMENT ON DATABASE * TO `admin2`;
    GRANT INDEX MANAGEMENT ON DATABASE * TO `admin2`;
    GRANT LOAD ON ALL DATA TO `admin2`;
    GRANT MATCH {*} ON GRAPH * NODE * TO `admin2`;
    GRANT MATCH {*} ON GRAPH * RELATIONSHIP * TO `admin2`;
    GRANT NAME MANAGEMENT ON DATABASE * TO `admin2`;
    GRANT SHOW CONSTRAINT ON DATABASE * TO `admin2`;
    GRANT SHOW INDEX ON DATABASE * TO `admin2`;
    GRANT START ON DATABASE * TO `admin2`;
    GRANT STOP ON DATABASE * TO `admin2`;
    GRANT TRANSACTION MANAGEMENT (*) ON DATABASE * TO `admin2`;
    GRANT WRITE ON GRAPH * TO `admin2`;

    The resulting admin2 role now has the same effective privileges as the built-in admin role.

  4. Assign the admin2 role to the users that you want to have the same privileges as the original admin role:

    GRANT ROLE admin2 TO <user1>, <user2>, ...;

    The GRANT ROLE command requires the ASSIGN ROLE privilege. See Grant privilege to assign roles for details on how to grant this privilege.

  5. Drop the existing admin role:

    DROP ROLE admin;
  6. Finally, you can rename the admin2 role to admin:

    RENAME ROLE admin2 TO admin;

Additional information about restoring the admin role can be found in the Recover the admin role.

Glossary

allocator

A component in the cluster that allocates databases to servers according to the topology constraints specified and an allocation strategy.

asynchronous replication

Asynchronous replication is used by secondary copies to poll for new transactions, which means they cannot be guaranteed to have received the most recent transactions. This enables efficient scale-out of read-performance.

Aura instance

A fully-managed DBMS represented by a single instance ID, that is running in the Neo4j Aura cloud.

auto-commit transaction

An automatically committed transaction that contains a single query.

Bolt protocol

Bolt is a protocol used for interaction between Neo4j instances and drivers.

bookmark

A marker the client can request from the cluster to ensure that it is able to read its own writes so that the application’s state is consistent and only databases that have a copy of the bookmark are permitted to respond.

category (Bloom)

A category is based on a node label and is defined in a Perspective as a way of visually distinguishing nodes with the same label(s).

causal consistency

All servers in a cluster agree on the order in which transactions take place. The position of a server on the causal chain can be guaranteed using a bookmark.

cluster

A Neo4j DBMS that spans multiple servers working together to increase fault tolerance and/or read scalability. Databases on a cluster may be configured to replicate across servers in the cluster thus achieving read scalability or high availability.

client application

Software that interacts with a Neo4j server.

commit

A commit is the successful completion of a transaction, which ensures durability of any changes made. For more details, visit Operations Manual → Transaction management.

composite database

Composite databases are the means to access partitioned graph data with a single Cypher query.

constraint

Constraints are sets of data modeling rules that ensure the data is consistent and reliable.

Cypher®

Neo4j’s graph query language.

data model

A data model defines how information is organized in a database. A good data model will make querying and understanding your data easier. In Neo4j, the data models have a graph structure.

database

A database is a container used by the DBMS to manage and store graph data. The physical structure of data is controlled by the database.

database vs graph

Databases are the physical containers of graph data. Graphs are the logical structure of data in Neo4j.

Database Management System

Database Management System, or DBMS, capable of managing multiple databases. A DBMS may run on a single server, or span several servers configured as a cluster.

database schema

The prescribed property existence and datatypes for nodes and relationships.

deallocate

An act of removing a database from a server or a server from a cluster without loss of data or reduced fault tolerance.

degree (of a node)

The number of relationships of a specific node; loops are counted twice.

disaster recovery

A manual intervention to restore availability of a cluster, or databases within a cluster.

driver

A software library that provides access to Neo4j from a particular programming language.

election

In the event that the Raft leader becomes unresponsive, followers automatically trigger an election and vote for a new leader.

entity

A node or a relationship.

expression (Cypher)

A component of a Cypher query which produces values. It may be used in projections, as a predicate, or when setting properties on graph elements.

fabric

Fabric is the architectural design of a unified system that provides a single access point to local or distributed graph data.

fault tolerance

A guarantee that a cluster can maintain a database’s persistence and availability in the event of one or more servers failing.

follower

A primary copy of a database acting as a follower, receives and acknowledges synchronous writes from the leader.

Generative AI (GenAI)

A type of artificial intelligence (AI) system that generates text, images, or other media in response to prompts.

graph

A logical representation of a set of nodes where some pairs are connected by relationships.

index

Data structure that improves read performance of a database.

knowledge graph

A specific type of graph that has an organizing principle so that a user (or a computer system) can reason about the underlying data. The organizing principle provides an additional layer of structure that adds context to support knowledge discovery.

label

Marks a node as a member of a named and indexed subset. A node may be assigned zero or more labels.

leader

A single primary copy of a database is designated as the leader. It receives all write transactions from clients and replicates writes synchronously to followers and asynchronously to secondary copies of the database.

main database

In terms of Neo4j Enterprise Studio, the database(s) containing the user’s data. Can exist in the same Neo4j deployment as the tool asset database.

motif

A description of a specific pattern within a graph.

node

A node represents an entity or discrete object in your graph data model. Nodes can be connected by relationships, hold data in properties, and are classified by labels.

operator

A symbol representing a mathematical or logical operation.

parameter

Named value provided when running a Cypher statement.

path

A sequence of nodes and the relationships connecting them, that does not contain duplicate relationships. Several paths can match a pattern.

pattern

A specific arrangement of nodes and relationships that can be matched in a graph. A pattern follows a motif.

perspective (Bloom)

A Perspective defines a certain business view or domain that can be found in the target Neo4j graph. A single Neo4j graph can be viewed through different Perspectives, each tailored for a different business purpose.

primary

A copy of the database that is able to process write transactions and is eligible to be elected as a leader. It participates in fault tolerant writes as it is part of the majority required to acknowledge and commit write transactions.

primary vs secondary

In a cluster, databases can operate in either primary or secondary mode. Primary databases are able to process write and read transactions, ensuring fault tolerance. Secondary databases are replicated asynchronously from primaries, and their main purpose is to provide read scaling within the cluster.

project (Aura)

An isolated environment in the unified Aura console that contains its own database instances, configurations, and resources. Preceded by tenant in the classic Aura console.

property

Properties are key-value pairs that are used for storing data on nodes and relationships.

query (Cypher)

A statement that retrieves or writes information to a database.

Raft group

A group of servers that are participating in hosting a particular database in primary mode.

Raft group member

A server that is participating in a Raft group. A server can be a member of one or more groups.

Raft log

A shared log between all Raft group members that is guaranteed to be consistently updated and viewed by those members. The log contains both database data and operational state of the Raft group.

Raft protocol

The networking mechanism that enables a database to replicate its data across multiple servers to give high availability for accessing the data and high durability to the data stored.

read scaling

Distributing query load by creating additional database copies hosted in secondary mode (read-only).

relationship

A relationship represents a connection between nodes in your graph data model. Relationships connect a source node to a target node, hold data in properties, and are classified by type.

secondary

An asynchronously replicated copy of the database that provides read scaling within the cluster.

seed

A seed is a database dump or a full backup used to create a database on a cluster. This is sometimes called seeding.

server

A physical machine, a virtual machine, or a container running an instance of Neo4j. Servers can be standalone or part of a cluster.

session

A causally linked sequence of transactions.

session consistency

An alternative name for Neo4j’s causal consistency.

standalone

A single server running Neo4j and not part of a cluster.

synchronous replication

Synchronous replication requires the leader primary to replicate a transaction and block the commit until a quorum of the follower primaries acknowledges that the transaction is successfully replicated. Once the transaction is replicated, the commit is allowed to proceed. This ensures data durability and consistency within the cluster.

system database

A database used by Neo4j to store system information.

tenant (Aura)

An isolated environment in the classic Aura console that contains its own database instances, configurations, and resources. Replaced by project in the unified Aura console.

tool asset database

In terms of Neo4j Enterprise Studio, the database where tools' assets are stored. This can be in the same Neo4j deployment as the main database(s) or in a separate deployment.

topology

A configuration that describes how the copies of a database should be spread across the servers in a cluster, see primary mode and secondary mode.

transaction

A transaction comprises a unit of work performed against a database. It is treated in a coherent and reliable way, independent of other transactions. Transactions comply with the ACID consistency model (atomic, consistent, isolated, and durable).