slug: mongodb provider: MongoDB generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Software & Technology min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 19 edges: - tag: Custom Database Roles spec_file: mongodb-custom-database-roles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: createGroupCustomDbRoleRole "Create One Custom Role"; schemas DatabasePrivilegeAction, DatabasePermittedNamespaceResource, DatabaseInheritedRole reason: Defining custom roles with explicit privilege actions and inherited roles is authorisation/entitlement definition for access control — Identity & Access Management. - tag: Database Users spec_file: mongodb-database-users-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: createGroupDatabaseUser "Create One Database User in One Project"; schemas CloudDatabaseUser, DatabaseUserRole, UserScope reason: Lifecycle of database user accounts with assigned roles and scopes is technical identity and access provisioning, not HR employee records. - tag: Federated Authentication spec_file: mongodb-federated-authentication-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: createFederationSettingIdentityProvider "Create One Identity Provider"; createFederationSettingConnectedOrgConfigRoleMapping "Create One Role Mapping in One Organization Configuration"; schemas FederationSamlIdentityProvider, FederationOidcIdentityProvider reason: SAML/OIDC identity provider configuration and role mappings for organisations is identity federation and access management. - tag: LDAP Configuration spec_file: mongodb-ldap-configuration-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: '"Return LDAP or X.509 Configuration", "Remove LDAP User to DN Mapping", schema "LDAPSecuritySettings", "UserSecurity"' reason: Directory-based authentication configuration and user-to-DN mapping for database users is identity and access management. - tag: MongoDB Cloud Users spec_file: mongodb-mongodb-cloud-users-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: '"Add One MongoDB Cloud User to One Project", "Add One Project Role to One MongoDB Cloud User", schema "CloudAccessRoleAssignment"' reason: User membership in organizations/projects/teams and role assignment is platform identity and access management, not HR employee records. - tag: X.509 Authentication spec_file: mongodb-x-509-authentication-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: '"Create One X.509 Certificate for One Database User"; "Disable Customer-Managed X.509"; schemas DBUserTLSX509Settings, UserToDNMapping' reason: Operations issue and revoke client certificates for database users and manage customer-managed X.509 / LDAP security settings — authentication credential and access administration. - tag: Cloud Provider Access spec_file: mongodb-cloud-provider-access-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '''Authorize One Cloud Provider Access Role'' / ''Deauthorize One Cloud Provider Access Role''; schemas CloudProviderAccessAWSIAMRole, CloudProviderAccessGCPServiceAccount, CloudProviderAccessAzureServicePrincipal' reason: Lifecycle and authorisation of cross-cloud machine identities (IAM roles, service accounts, service principals) used by the platform — squarely Identity & Access Management. - tag: Clusters spec_file: mongodb-clusters-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: POST /api/atlas/v2/groups/{groupId}/clusters createGroupCluster "Create One Cluster in One Project"; schemas AWSCloudProviderSettings, ClusterComputeAutoScaling reason: Operations provision, resize, configure and delete cloud database clusters across cloud provider regions — this is cloud compute/storage infrastructure provisioning, i.e. IT Infrastructure Management, not a data-governance or industry capability. - tag: Flex Clusters spec_file: mongodb-flex-clusters-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: createGroupFlexCluster "Create One Flex Cluster in One Project"; schemas FlexProviderSettings20241113, ReplicationSpec20240805, DiskGBAutoScaling reason: Create/update/delete/upgrade of managed database cluster instances with provider hardware specs and autoscaling is cloud infrastructure provisioning and stewardship. - tag: Monitoring and Logs spec_file: mongodb-monitoring-and-logs-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.8 evidence: '"Download Logs for One Cluster Host in One Project", "Return Measurements for One Database in One MongoDB Process", schemas MetricsMeasurement, MetricDataPoint' reason: Log download and metric measurement retrieval for running database processes is observability of a running service (logs and metrics). - tag: Network Peering spec_file: mongodb-network-peering-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Create One Network Peering Connection", "Return All Network Peering Containers in One Project for One Cloud Provider", schemas AwsNetworkPeeringConnectionSettings' reason: VPC/VNet peering containers and connections are cloud network infrastructure configuration. - tag: Private Endpoint Services spec_file: mongodb-private-endpoint-services-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Create One Private Endpoint Service for One Provider", "Toggle Regionalized Private Endpoint Status", schema PrivateLinkEndpoint' reason: Private link / private endpoint provisioning per cloud provider is cloud network infrastructure management. - tag: Teams spec_file: mongodb-teams-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: '"Update Team Roles in One Project"; "Assign MongoDB Cloud Users in One Organization to One Team"; schemas TeamRole, CloudAccessRoleAssignment' reason: Despite the HR-sounding tag, operations group cloud platform users into teams and assign roles/access at org and project scope — access administration, i.e. Identity & Access Management, not workforce or talent management. - tag: Cloud Backups spec_file: mongodb-cloud-backups-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.75 evidence: schemas DiskBackupSnapshot, DiskBackupSnapshotRestoreJob, PaginatedCloudBackupRestoreJobView; 'Return Backup Compliance Policy Settings' reason: Snapshot creation, export and restore jobs plus backup retention/compliance policy for cloud database deployments — backup and restore, which the frame places under Disaster Recovery & Resilience. - tag: Invoices spec_file: mongodb-invoices-api-openapi.yml capability_id: BC-4250.30 capability_id_l1: BC-4250 capability_name: Invoicing & Statement Management confidence: 0.75 evidence: '"Return All Invoices for One Organization", "Return One Invoice as CSV", "Return All Line Items for One Invoice by Invoice ID", schemas BillingInvoice, BillingPayment, BillingRefund' reason: The operations expose subscription invoices, line items, cost-explorer usage and SKUs for the cloud service — invoicing and statement management within the SaaS billing model. Some ambiguity as it also carries usage/cost analytics, but invoicing dominates. - tag: Cluster Outage Simulation spec_file: mongodb-cluster-outage-simulation-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.72 evidence: '''Start One Outage Simulation'' / ''End One Outage Simulation''; schema AtlasClusterOutageSimulationOutageFilter' reason: Deliberately simulates regional/cluster outages to validate application failover behaviour — a disaster-recovery/resilience exercise, which BC-4220.60 explicitly covers ('failover orchestration, and disaster-recovery exercises'). - tag: Encryption at Rest using Customer Key Management spec_file: mongodb-encryption-at-rest-using-customer-key-management-api-openapi.yml capability_id: BC-620.50 capability_id_l1: BC-620 capability_name: Security Architecture Management confidence: 0.7 evidence: updateGroupEncryptionAtRest "Update Encryption at Rest Configuration in One Project"; schemas AWSKMSConfiguration, AzureKeyVault, GoogleCloudKMS reason: Configuring customer-managed key encryption and private endpoints to KMS providers is a security control/design mechanism — security architecture. Not privacy compliance since no data-subject or policy artefacts appear. - tag: Legacy Backup spec_file: mongodb-legacy-backup-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.7 evidence: '"Create One Legacy Backup Restore Job", "Return All Legacy Backup Snapshots", "Update Snapshot Schedule for One Cluster"' reason: Snapshot, checkpoint and restore-job operations are backup and restore of the running service — resilience/DR operations. Could alternatively be read as generic IT operations, hence 0.7. - tag: Push-Based Log Export spec_file: mongodb-push-based-log-export-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: '"Create One Log Integration", "Create One Push-Based Log Export Configuration in One Project"; schemas SplunkLogIntegrationRequest, DatadogLogIntegrationRequest, OtelLogIntegrationRequest' reason: Configures shipping of service logs to observability sinks (Splunk, Datadog, OpenTelemetry, S3/GCS), which realises log-based observability of the running service rather than any business function.