Skip to main content
Version: 24.10

Additional considerations

Roles allow grouping different levels of access for various organizations and, at the same time, allow grouping different levels of access by module for simplified management.

Multiclient environments

The roles of an organization allow configuring access and visibility for the users of the organization, and also allow including the permissions to configure access and visibility to dependent organizations.

An organization is dependent when:

  • It is client type and the roles and users are in the partner organization at a higher level.
  • It is a sub-organization of a client organization.

Roles are assigned to users and contain the definition of access and visibility levels, being able to establish different configurations for the root organization and its sub-organizations within the same role. This can only be done in a descending manner; that is, from a higher-level organization, permissions can be assigned to the organization itself and the organizations that depend on it.

Levels of access by modules

permissions

The levels of access are also defined for each module of the solution:

Portal

In Portal the following roles exist:

  1. No access
  2. Organization administrator or 1 in the table below
  3. Read-only organization administrator or 2 in the table below
  4. User or 3 in the table below
  5. L1 support team or 4 in the table below
  6. L1 support team read-only or 5 in the table below
  7. L2 support team or 6 in the table below
  8. L2 support team read-only or 7 in the table below
  9. L3 Engineering Team or 8 in the table below
  10. L3 Engineering Team Read Only or 9 in the table below
  11. Billing or 10 in the table below

To access certain functionalities, in addition to access permissions in Portal, access to Workspaces is required, depending on the functionality, with role Level 1 or Level 2.

These roles by levels allow configuring visibility and segmented accesses according to the needs of each organization, the detail of the visibility and actions available for each level of access to Portal is defined in the table below:

SectionFunctionalityAction12345678910
HomeRead
OperationsRead
FlowsRead
Create⭐⭐
Refresh⭐⭐
Delete⭐⭐
ReportsListRead
DetailRead
Create
Delete
TenantsCreate
Read
Refresh
Delete
ActivationRead
MonitorActive alertsRead
WorkspacesRead
Refresh
GroupsRead
Create
Refresh
Delete
UpdatesRead
Create⭐⭐
Refresh⭐⭐
Delete⭐⭐
AnalyzerInstalled appsRead
Refresh
AnalyzerLicensesRead
Create
Refresh
Delete
SAMRead
MicroservicesCreate
Read
Refresh
EnabledRead
Refresh
BillingRead
Refresh
ProductRead
ReportRead
EnvironmentRead
Refresh
Agent SettingsRead
Refresh
IntegrationsCreate
Read
Refresh
ModulesCreate
Read
Refresh
InformationRead
Refresh
DirectivesCreate
Read
Refresh
Delete
Reporting GroupsCreate
Read
Refresh
Delete
Agent SettingsRead
Refresh
Magic linkCreate
Read
Refresh
RolesCreate
Read
Refresh
Delete
UsersCreate
Read
Refresh
Delete
info
  • ✅ Has access.
  • ⭐ Has access if additionally has L1 in Workspaces.
  • ⭐⭐ Has access if additionally has L2 in Workspaces.
  • ❌ No access.

Workspaces

In Workspaces, there are four roles with different levels of access available:

  • Level 1 or L1 in the table below
  • Level 1 read-only or L1 RO in the table below
  • Level 2 or L2 in the table below
  • Level 2 read-only or L2 RO in the table below

Available actions by each role:

FunctionalityActionL1L1 ROL2L2 RO
UX PanelView
WorkspacesView
WorkspacesExecute operations
SessionsView
SessionsExecute operations
Connection LogsView
JobsView
JobsCancel
AlertingView
AlertingOff
Profile StorageView
Profile StorageModify
Profile StorageDelete
Alert notification profilesView
Alert notification profilesModify
Alert notification profilesDelete
Alert SubscriptionsView
Alert SubscriptionsModify
Alert SubscriptionsDelete
Events LogView
Events LogModify
Events LogDelete
LocationsView
LocationsCreate
LocationsModify
NetworksView
NetworksModify
NotificationsView
NotificationsCreate
NotificationsModify
NotificationsDelete
Reporting GroupsView
ServersView
ServersExecute operations
Wireless networksView
Wireless networksModify
info
  • ✅ Has access.
  • ❌ No access.

Analyzer

Since Analyzer presents information and never allows modifications to the organization or its devices, it does not segment access to the functionalities it contains, therefore access is either granted or denied to users.

Therefore, the access options to Analyzer are:

  • ✅ Access
  • ❌ No access