There are three fixed roles in the community edition of Couchbase providing coarser access control: Bucket Full Access ( bucket_full_access[*] ), Admin ( admin ), and Read Only Admin ( ro_admin ).
You should be able to use the “Bucket Full Access” and “Read Only Admin” roles for Sync Gateway in this scenario.