Privilege Category | Privilege Description | Comments |
Inventory | ||
Enables or restricts the ability to access to the Inventory tab. | Reports and templates available through the Inventory tab are individually controlled by Report specific privileges. | |
Enable Access to Objects | Enables or restricts the ability to access to Inventory objects. | |
• Arrays | Enables or restricts the access to the Array object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately. | |
• Azure Storage Account | Enables or restricts the access to the Azure Storage Accounts object. This includes the ability to export. | |
• Azure Virtual Machine | Enables or restricts the access to the Azure Virtual Machines object. This includes the ability to export. | |
• Backup Servers | Enables or restricts the access to the Backup Server object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately. | |
• Datastores | Enables or restricts the access to the Datastore object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately. | |
• Dedupe Appliances | Enables or restricts the access to the Dedupe Appliance object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately. | |
• File Shares & Volumes | Select to provide access to File Share & Volumes on the Inventory page. This includes the ability to export. | |
• EC2 Instances | Select to provide access to Amazon Web Services (AWS) EC2 Instances on the Inventory page. This includes the ability to export. | |
• Hosts | Enables or restricts the access to the Host object in the Inventory. This includes the ability to decommission, recommission, export and import objects. Assigning attributes and permanent deletion are permissioned separately. | |
• S3 Buckets | Select to provide access to Amazon Web Services (AWS) S3 Buckets on the Inventory page. This includes the ability to export. | |
• Switches | Enables or restricts the access to the Switch object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately. | |
• VM Guests | Enables or restricts the access to the VM Guest object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately. | |
• VM Servers | Enables or restricts the access to the VM Server object in the Inventory. This includes the ability to export. Assigning attributes and permanent deletion are permissioned separately. | |
Manage Objects | Enables or restricts the ability to manage to Inventory objects. | |
All Objects: Permanently Delete | Enables or restricts the ability to permanently delete objects from the Inventory view and the database. | |
All Objects: Assign Attribute Values | Enables or restricts the ability to assign attributes and change an object’s attribute values within the Inventory. | These privileges are specific to the Inventory tab. |
Hosts: Import from CSV | Enables the user to use a CSV file to add/update hosts from an external source and ultimately manage them from the Inventory. | |
Hosts: Add/Edit/Move | Enables or restricts access to add and modify Hosts. This includes moving (cutting and pasting) hosts from one Host Group to another. | |
Hosts: Recommission and Decommission | Enables or restricts he ability to recommission and decommission hosts and master servers. These are audited actions and the historical data is preserved in the database. Even with this privilege, a password is required for the action. | |
Host Groups: Add/Edit/Move | Enables or restricts access to add and modify Host Groups. This includes moving (cutting and pasting) one Host Group to another, allowing you to create sub groups. | |
Reports | ||
Enables or restricts the ability to access to the Reports tab. Access to reports within a product/group—for example, System Administration or Management Reports. | Access can be on a per-report basis or for an entire report menu group. New reports must be explicitly enabled for users. Access is automatically granted for Super Users and Admins. Note: Portal upgrades will automatically enable privileges for newly added reports and the display of the Inventory view along with all objects for all Administrators. Refer to the APTARE Release Notes for the list of reports and features introduced in a specific product release. | |
Enable Access to Cloud Reports | Enables access to new and updated reports delivered by APTARE through the Cloud. | The Cloud section is only displayed on the Reports tab when this privilege is enabled. |
Tools | ||
Designers | ||
Dynamic Template Designer | Enables or restricts access to the Dynamic Template Designer - a tool that does not require Structured Query Language (SQL) knowledge to create custom report templates. | |
SQL Template Designer | Enables or restricts access to the SQL Template Designer - a tool to create custom report templates using SQL. | |
Method Designer | Enables or restricts the access to the Method Designer, an advanced feature that requires experience in SQL (Structured Query Language) query development. Methods can be used only in report templates that have been created using the Dynamic Template Designer. | |
File List | ||
File List Export | Enables or restricts access to the File List Exporter - a utility for extracting the File Analytics collected metadata into a comma-separated values (.csv) file. | |
Admin | ||
Users | ||
Users and Privileges | Enables or restricts access to view, search and modify user details. This includes editing group memberships, privileges and password resets. | |
User Groups | Enables or restricts access to view, search and modify user group details. This includes adding, editing user membership, and privileges. User groups provide an efficient way of managing many users at once. | |
Domains | ||
Domains | Enables or restricts access to Domain administration. This includes the ability to add, edit and delete domains. | |
Chargeback | ||
Backup | Select to provide access to Backup Billing and Usage Policy administration functions including adding, editing and deleting. | |
Capacity | Select to provide access to Capacity Billing and Usage Policy administration functions including adding, editing and deleting. | |
SAN Fabric | Select to provide access to SAN Fabric Billing and Usage Policy administration functions including adding, editing and deleting. | |
Solutions | ||
Storage Optimization | Select to provide access to Storage Optimization and corresponding management functions. | |
Risk Mitigation | Select to provide access to Risk Mitigation and corresponding management functions. | |
Data Collection | ||
Collection Status | Select to provide access to monitor the health and status of Data Collectors. | |
Collector Administration | Select to provide access to create and configure Collectors and Collector policies. Stop, start, edit, and policy deletion is also permitted. On-Demand collection runs are also available for supported vendors. | |
Host Discovery and Collection | Select to provide the ability to configure Host Resources Data Collection and manage the Host Discovery and Collection. | |
Collector Updates | Select to enable or restrict the view of the current status for data collectors. This area also provides access to the update the Upgrade Manager and aptare.jars. | |
Reports | ||
Thresholds | Select to provide access to add, edit and delete Threshold Policies. Threshold Policies enable you to establish Low, Warning, and Critical levels from which to manage the state of your capacity utilization. | |
NetBackup Discovery | Select to provide access to the management and configuration of host discovery policies. The Discovery module is specific to NetBackup | |
Backup SLA | Select to provide access to add, edit and delete Backup Service Level Agreements (SLA) Group polices. When you establish an SLA, performance is tracked against objectives. The SLA policies are where objectives are set. | |
Master Schedules | Select to provide access to creating and editing Master schedules. Master schedules can be defined at a global level and then applied to specific saved reports, causing the reports to be emailed or exported on a regular basis. | |
Backup Windows | Select to provide access to add, edit and delete custom backup windows. | |
Email/Export on Schedule | Select to provide the ability to email or export user reports based on an establish schedule. | |
Share Reports | Select to provide the ability to share custom reports and templates with users and user groups. | |
Create Ticket | Select to provide the ability to create tickets associated with backup jobs. | |
Advanced | ||
Parameters | Select to provide the ability to add, edit, delete and download advanced parameters. Advanced parameters are a mechanism for customizing internal settings with the help of Global Support Services. | |
Attributes | Select to provide the ability to create, edit and delete attributes and modify their values. Attributes define a distinct data set based on a specific characteristic. | |
Publish Benchmark Data | Select to provide the ability to configure and enable sharing Performance Statistics with APTARE. This enables customers to compare their performance with similarly configured arrays in the broader community, for customers to gauge if their environmental metrics are within a normal performance range. | |
Object Maintenance | Select to provide the ability to manage Devices, Libraries and Drives. Permanently delete and the assignment of attribute values are permitted operations. | |
Support Tools | Select to provide the ability to download data collector logs, portal logs and configuration files for a specified time period. | |
System Notifications | Select to provide the ability to view and manage system level notifications. Notifications alert the user to any issues that require attention. |