Providing Portal Access and User Authentication > About User Privileges
  
Version 10.1.00
About User Privileges
Privileges can be set for both user groups and individual users.
See also:
About User Types
Assigning User Privileges
Managing Users and User Groups
Privileges are organized by areas in the portal: Inventory, Reports, Tools, Admin.
Note: Portal upgrades will automatically enable privileges for newly added reports and the display of the Inventory view, for all Administrators. Refer to the APTARE StorageConsole Release Notes for the list of reports and features introduced in a specific product release.
Various categories of privileges enable you to tailor user access capabilities:
Table 1 User Privileges
Privilege Category
Privilege Description
Comments
Inventory
 
Enables or restricts the ability to access to the Inventory tab.
Reports and templates available through the Inventory tab are individually controlled by Report specific privileges.
Enable Access to Objects
Enables or restricts the ability to access to Inventory objects.
 
Array
Enables or restricts the access to the Array object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately.
 
Backup Servers
Enables or restricts the access to the Backup Server object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately.
 
Datastores
Enables or restricts the access to the Datastore object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately.
 
Dedupe Appliances
Enables or restricts the access to the Dedupe Appliance object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately.
 
EC2 Instances
Select to provide access to Amazon Web Services (AWS) EC2 Instances on the Inventory page. This includes the ability to export.
 
Hosts
Enables or restricts the access to the Host object in the Inventory. This includes the ability to decommission, recommission, export and import objects. Assigning attributes and permanent deletion are permissioned separately.
 
S3 Buckets
Select to provide access to Amazon Web Services (AWS) S3 Buckets on the Inventory page. This includes the ability to export.
 
Switches
Enables or restricts the access to the Switch object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately.
 
VM Guests
Enables or restricts the access to the VM Guest object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately.
 
VM Servers
Enables or restricts the access to the VM Server object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately.
 
Manage Objects
Enables or restricts the ability to manage to Inventory objects.
 
All Objects: Permanently Delete
Enables or restricts the ability to permanently delete objects from the Inventory view and the database.
 
All Objects: Assign Attribute Values
Enables or restricts the ability to assign attributes and change an object’s attribute values within the Inventory.
These privileges are specific to the Inventory tab.
Hosts: Import from CSV
Enables the user to use a CSV file to add/update hosts from an external source and ultimately manage them from the Inventory.
 
Hosts: Add/Edit/Move
Enables or restricts access to add and modify Hosts. This includes moving (cutting and pasting) hosts from one Host Group to another.
 
Hosts: Recommission and Decommission
Enables or restricts he ability to recommission and decommission hosts and master servers. These are audited actions and the historical data is preserved in the database. Even with this privilege, a password is required for the action.
 
Host Groups: Add/Edit/Move
Enables or restricts access to add and modify Host Groups. This includes moving (cutting and pasting) one Host Group to another, allowing you to create sub groups.
 
Reports
 
Enables or restricts the ability to access to the Reports tab.
Access to reports within a product/group—for example, System Administration or Management Reports.
Access can be on a per-report basis or for an entire report menu group.
New reports must be explicitly enabled for users. Access is automatically granted for Super Users and Admins.
Note: Portal upgrades will automatically enable privileges for newly added reports and the display of the Inventory view, for all Administrators. Refer to the APTARE StorageConsole Release Notes for the list of reports and features introduced in a specific product release.
Enable Access to Cloud Reports
Enables access to new and updated reports delivered by APTARE through the Cloud.
The Cloud section is only displayed on the Reports tab when this privilege is enabled.
Tools
Designers
 
 
Dynamic Template Designer
Enables or restricts access to the Dynamic Template Designer - a tool that does not require Structured Query Language (SQL) knowledge to create custom report templates.
 
SQL Template Designer
Enables or restricts access to the SQL Template Designer - a tool to create custom report templates using SQL.
 
Method Designer
Enables or restricts the access to the Method Designer, an advanced feature that requires experience in SQL (Structured Query Language) query development. Methods can be used only in report templates that have been created using the Dynamic Template Designer.
 
File List
File List Export
Enables or restricts access to the File List Exporter - a utility for extracting the File Analytics collected metadata into a comma-separated values (.csv) file.
 
Admin
Users
 
 
Users and Privileges
Enables or restricts access to view, search and modify user details. This includes editing group memberships, privileges and password resets.
 
User Groups
Enables or restricts access to view, search and modify user group details. This includes adding, editing user membership, and privileges. User groups provide an efficient way of managing many users at once.
 
Domains
 
 
Domains
Enables or restricts access to Domain administration. This includes the ability to add, edit and delete domains.
 
Chargeback
 
 
Backup
Select to provide access to Backup Billing and Usage Policy administration functions including adding, editing and deleting.
 
Capacity
Select to provide access to Capacity Billing and Usage Policy administration functions including adding, editing and deleting.
 
SAN Fabric
Select to provide access to SAN Fabric Billing and Usage Policy administration functions including adding, editing and deleting.
 
Data Collection
Status
Select to provide access to monitor the health and status of Data Collectors.
 
Collectors
Select to provide access to create and configure Collectors and Collector policies. Enable, disable, edit, and policy deletion is also permitted.
 
Host Inventory
Select to provide the ability to configure Host Resources Data Collection and manage the Host Inventory.
 
Collector Updates
Select to enable or restrict the view of the current status for data collectors. This area also provides access to the update the Upgrade Manager and aptare.jars.
 
Reports
Thresholds
Select to provide access to add, edit and delete Threshold Policies. Threshold Policies enable you to establish Low, Warning, and Critical levels from which to manage the state of your capacity utilization.
 
NetBackup Discovery
Select to provide access to the management and configuration of host discovery policies. The Discovery module is specific to NetBackup
 
Backup SLA
Select to provide access to add, edit and delete Backup Service Level Agreements (SLA) Group polices. When you establish an SLA, performance is tracked against objectives. The SLA policies are where objectives are set.
 
Master Schedules
Select to provide access to creating and editing Master schedules. Master schedules can be defined at a global level and then applied to specific saved reports, causing the reports to be emailed or exported on a regular basis.
 
Backup Windows
Select to provide access to add, edit and delete custom backup windows.
 
Email/Export on Schedule
Select to provide the ability to email or export user reports based on an establish schedule.
 
Share Reports
Select to provide the ability to share custom reports and templates with users and user groups.
 
Create Ticket
Select to provide the ability to create tickets associated with backup jobs.
 
Advanced
Parameters
Select to provide the ability to add, edit, delete and download advanced parameters. Advanced parameters are a mechanism for customizing internal settings with the help of Global Support Services.
 
Attributes
Select to provide the ability to create, edit and delete attributes and modify their values. Attributes define a distinct data set based on a specific characteristic.
 
Publish Benchmark Data
Select to provide the ability to configure and enable sharing Performance Statistics with APTARE. This enables customers to compare their performance with similarly configured arrays in the broader community, for customers to gauge if their environmental metrics are within a normal performance range.
 
Object Maintenance
Select to provide the ability to manage Devices, Libraries and Drives. Permanently delete and the assignment of attribute values are permitted operations.
 
Support Tools
Select to provide the ability to download data collector logs, portal logs and configuration files for a specified time period.
 
System Notifications
Select to provide the ability to view and manage system level notifications. Notifications alert the user to any issues that require attention.