Roles
=====

Configuring and managing PGD doesn’t require superuser access and we
recommend that you don’t use superuser access. Instead, the privileges
required to administer PGD are split across the following predefined
roles.

.. csv-table::
  :header: Role,Description
  :widths: 10,30
  :align: left
  :class: longtable

  :ref:`bdr_superuser<bdr_superuser>` ,"The highest-privileged role, having access to all PGD tables and functions."
  :ref:`bdr_read_all_stats<bdr_read_all_stats>` ,"The role having read-only access to the tables, views, and functions, sufficient to understand the state of PGD."
  :ref:`bdr_monitor<bdr_monitor>` ,"Includes the privileges of bdr_read_all_stats, with some extra privileges for monitoring."
  :ref:`bdr_application<bdr_application>` ,The minimal privileges required by applications running PGD.
  :ref:`pg_upgrade <PGD predefined roles>` ,Can view all conflicts in  :ref:``bdr.conflict_history`  columns<`bdr.conflict_history`  columns>` .

These roles are named to be analogous to PostgreSQL’s ``pg_``
 
`predefinedroles <https://www.postgresql.org/docs/current/predefined-roles.html>`_  .

The PGD ``bdr_`` roles are created when the BDR extension is installed.
See :ref:`PGD predefined roles <PGD predefined roles>`  for more details of the privileges each role has.

Managing PGD doesn’t require that administrators have access to user
data.

Arrangements for securing information about conflicts are discussed in
`Logging conflicts to a table <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/conflict_functions#logging-conflicts-to-a-table>`_  .

You can monitor conflicts using the `bdr.conflict_history_summary <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrconflict_history_summary>`_  view.

..  Note The BDR extension and superuser access::
   The one exception to the rule of not needing superuser access is in the management of PGD's underlying BDR extension. Only superusers can create the BDR extension. However, if you want, you can set up the `pgextwlist`  extension and configure it to allow a non-superuser to create a BDR extension.
