Administering Domains, Roles and Users > External User Management Systems
Pluggable Roles
If you want to employ external control over user based authorization to carry out actions associated with certain roles in the software, you enable the process via a pluggable roles plugin.
Through use of the plugin, roles (and therefore the permissions assigned to that role) can be dynamically assigned depending on which project, if any, is currently open and being accessed by a user. Project based control of roles via a plugin means a user can be enabled to perform certain actions in one project, but be restricted from performing those actions in another project.
The following diagram summarizes the typical flow between a pluggable roles plugin and Capital software, and then shows the implications for a user at a project level.
Figure 26: Project Based User Authorization Using Pluggable Roles
Use Case
Using sample data, the following use case details the typical communication between a pluggable roles plugin, Capital software, and a user, with resulting implications for a user at a project level.
The sample user’s data, showing which roles they have depending on which project is open, as well as the associated roles/permissions relationship, is displayed below.
Figure 27: Externally Maintained Use Case User Data
Note
All users and roles referenced in external data must have previously been created or defined in Capital Access Manager.
Communication based on the above external data is displayed on the below sequence diagram:
Figure 28: Example Communication between the Pluggable Roles Plugin, Capital Software, and the User.
Note
At any given time, the roles associated with a user can be seen by hovering the mouse cursor over the user icon in the status bar.
For further information on creating and using pluggable roles, see the CustomSecurityPluginDevelopment.pdf document in the doc/plugin folder of your Capital installation for information on creating and deploying a plugin to allow communication with an external authorization service.
A sample pluggable roles plugin is provided in the following location:
%Capital_Home%\doc\plugin\examples\Java\src\com\example\plugin\roleprovider
Parent Topic:
External User Management Systems
Capital Access Manager User Guide, 2512.2606
Unpublished work. © 2026 Siemens
Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/idafdac739-a122-4240-9a9e-e75727517953 · retrieved 2026-07-18