CapitalKnowledge

Administering Domains, Roles and Users > External User Management Systems

Pluggable Roles

If you want to employ external control over user based authorization to carry out actions associated with certain roles in the software, you enable the process via a pluggable roles plugin.

Through use of the plugin, roles (and therefore the permissions assigned to that role) can be dynamically assigned depending on which project, if any, is currently open and being accessed by a user. Project based control of roles via a plugin means a user can be enabled to perform certain actions in one project, but be restricted from performing those actions in another project.

The following diagram summarizes the typical flow between a pluggable roles plugin and Capital software, and then shows the implications for a user at a project level.

Figure 26: Project Based User Authorization Using Pluggable Roles

Use Case

Using sample data, the following use case details the typical communication between a pluggable roles plugin, Capital software, and a user, with resulting implications for a user at a project level.

The sample user’s data, showing which roles they have depending on which project is open, as well as the associated roles/permissions relationship, is displayed below.

Figure 27: Externally Maintained Use Case User Data

Note

All users and roles referenced in external data must have previously been created or defined in Capital Access Manager.

Communication based on the above external data is displayed on the below sequence diagram:

Figure 28: Example Communication between the Pluggable Roles Plugin, Capital Software, and the User.

Note

At any given time, the roles associated with a user can be seen by hovering the mouse cursor over the user icon in the status bar.

For further information on creating and using pluggable roles, see the CustomSecurityPluginDevelopment.pdf document in the doc/plugin folder of your Capital installation for information on creating and deploying a plugin to allow communication with an external authorization service.

A sample pluggable roles plugin is provided in the following location:

%Capital_Home%\doc\plugin\examples\Java\src\com\example\plugin\roleprovider

Parent Topic:

External User Management Systems

Capital Access Manager User Guide, 2512.2606

Unpublished work. © 2026 Siemens

Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/idafdac739-a122-4240-9a9e-e75727517953 · retrieved 2026-07-18