Skip to main content
Version: 24.9

Additional considerations

Roles allow grouping different levels of access for various organizations and, at the same time, allow grouping different levels of access by module for simplified management.

Multiclient environments

The roles of an organization allow configuring access and visibility for the users of the organization, and also allow including the permissions to configure access and visibility to dependent organizations.

An organization is dependent when:

  • It is client type and the roles and users are in the partner organization at a higher level.
  • It is a sub-organization of a client organization.

Roles are assigned to users and contain the definition of levels of access and visibility, being able to establish different configurations for the root organization and its sub-organizations in the same role. This can only be done in a descending manner; that is, from a higher-level organization, permissions can be assigned to the organization itself and the organizations that depend on it.

Levels of access by modules

The levels of access are also defined for each module of the solution:

Portal

In Portal, there are two roles available: User and Organization Admin. The first allows viewing actions; and the second can turn functionalities on or off and make changes at a general level.

To access certain functionalities, in addition to the user role in the Portal, access to Workspaces is required, depending on the functionality, with Level 1 or Level 2 roles.

Available actions by each role:

FunctionalityActionOrganization AdminUser
ActivationsViewX
Operations logViewXX
MicroservicesCreateXOnly if L2 in Workspaces
MicroservicesViewXOnly if L1 or L2 in Workspaces
MicroservicesModifyXOnly if L2 in Workspaces
MicroservicesDeleteXOnly if L2 in Workspaces
Enabled microservicesViewXOnly if L1 or L2 in Workspaces
Enabled microservicesModifyXOnly if L2 in Workspaces
FlexxAgent ConfigurationViewXX
FlexxAgent ConfigurationModifyX
FlowsCreateXOnly if L2 in Workspaces
FlowsViewXOnly if L2 in Workspaces
FlowsModifyXOnly if L2 in Workspaces
IntegrationsCreateX
ModulesCreateX
ModulesViewX
ModulesModifyX
OperationsViewXOnly if L1 or L2 in Workspaces
Patch ManagementCreateXOnly if L2 in Workspaces
Patch ManagementViewXOnly if L1 or L2 in Workspaces
Patch ManagementModifyXOnly if L2 in Workspaces
Patch ManagementDeleteXOnly if L2 in Workspaces
PoliciesCreateX
PoliciesViewXX
PoliciesModifyX
PoliciesDeleteX
Reporting GroupsCreateX
Reporting GroupsViewX
Reporting GroupsModifyX
RolesCreateX
RolesViewX
RolesModifyX
RolesDeleteX
OrganizationsCreateX
OrganizationsViewX
OrganizationsModifyX
OrganizationsDeleteX
UsersCreateX
UsersViewX
UsersModifyX
UsersDeleteX
WorkspacesViewXOnly if L1 or L2 in Workspaces
Workspace GroupsCreateX
Workspace GroupsViewXOnly if L1 or L2 in Workspaces
Workspace GroupsModifyX
Workspace GroupsDeleteX

Workspaces

In Workspaces, there are two roles available: Level 1 and Level 2. The first allows the most common support actions, such as providing remote assistance, sending microservices, power actions, or consulting device information and, the second, includes all the support functionalities of Level 1 plus server management, networks, locations, wifi networks, and alert configuration.

Available actions by each role:

FunctionalityActionLevel 1Level 1 Read OnlyLevel 2Level 2 Read Only
UX PanelViewXXXX
WorkspacesViewXXXX
WorkspacesExecute operationsXX
SessionsViewXXXX
SessionsExecute operationsXX
Connection LogsViewXXXX
JobsViewXXXX
JobsCancelXX
AlertingViewXXXX
AlertingOffXX
Profile StorageViewXXXX
Profile StorageModifyXX
Profile StorageDeleteXX
Alert notification profilesViewXX
Alert notification profilesModifyX
Alert notification profilesDeleteX
Alert SubscriptionsViewXX
Alert SubscriptionsModifyX
Alert SubscriptionsDeleteX
Events LogViewXX
Events LogModifyX
Events LogDeleteX
LocationsViewXX
LocationsCreateX
LocationsModifyX
NetworksViewXX
NetworksModifyX
NotificationsViewXX
NotificationsCreateX
NotificationsModifyX
NotificationsDeleteX
Reporting GroupsViewXX
ServersViewXX
ServersExecute operationsX
Wireless networksViewXX
Wireless networksModifyX

Analyzer

Since Analyzer presents information and never allows modifications to the organization or its devices, it does not segment access to the functionalities it contains, therefore access is either granted or denied to users.

The access options for Analyzer are Access and No Access.