These are the different roles and authorizations for users of Net Search Extender:
The DB2 instance owner user can start and stop the instance services for DB2 Net Search Extender and control the locking services. In addition, the DB2 instance user becomes DBADM for each enabled database. This enables a central point of control for all database changes driven by DB2 Net Search Extender.
The commands are only allowed on the server. In a distributed DB2 environment, this can be any of the servers. Each command checks if the user running the command is the DB2 instance owner. Note that using a separate fenced user ID on UNIX systems does not influence Net Search Extender processing in terms of authorization or performance.
Database administrators can enable and disable databases for use with DB2 Net Search Extender.
The text table owner can create, drop, and change indexes. Note that they must be able to control the location of indexes and updates to the full-text indexes.
Note that the command implementation partially runs under the user ID of the DB2 instance owner. Therefore, grant the instance owner the necessary file system access before creating or altering the text indexes.