the role management is similar in cdot
for example
::> security login role create -role test_role -cmddirname volume -access readonly -query "vol1,cifs_1028,data_svm_root"
This creates the role "test_role" for the command "volume" with "readonly" access for query on volumes "vol1,cifs_1028,data_svm_root"
All other commands will not work or return empty results.
Regards
Emile