1,774
edits
Changes
m
no edit summary
== Overview ==
A central design point of Veloopti security is that no user has permission to perform any operation unless they have been specifically granted it. The purpose of granting a permission is to enable a user to perform a specific action. Permissions either extend globally to the whole of Veloopti, or locally to a single application. Each application has total control of its own permissions and they do not interfere with another application.
== Design considerations ==
A central design point of Veloopti permissions is to empower the owner of an application to have everything they need to monitor their application. They should be able to write and deploy any monitoring for their application without being interfered by another application.
== Roles and permissions ==
Permissions are bundled together and can appear in one or more roles.
Global permissions and application permissions
Global permissions reach to the entire Veloopti organisation and can extend into every application. Application permissions exist only in the application.
== Global permissions ==
| [[file:slider_right.png|30px]]
| Install
| xThe user can install an agent on a server by providing their username and password.
|-
| [[file:slider_right.png|30px]]
| Create installation tokenUpgrade| xThe user can initiate an agent to upgrade
|-
| [[file:slider_right.png|30px]]
| None requiredRestart| xThe users can stop an start the Veloopti agent
|-
| [[file:slider_right.png|30px]]
| UninstallCreate installation token| x|-| [[file:slider_rightThe user can create an installation token that can be used to install an agent that does not require a username and password.png|30px]]| Upgrade| x|-| [[file:slider_right.png|30px]]| View| x
|-
|}
{|
| [[file:slider_right.png|30px]]
| ListallList all| xThe user is able to view the complete list of applications in the application list view.
|-
| [[file:slider_right.png|30px]]
| View all
| xThe user is able to enter all applications in the application list view. This gives the user a read only view of the Dashboards, users and nodes in the application.
|-
| [[file:slider_right.png|30px]]
| Create and Rename
| xThe user can create a new application and rename an existing one
|-
| [[file:slider_right.png|30px]]
| Change application owner
| xUser can change an application owner to another user.NOTE: This permission allows the user to assume full rights over any application. As the Owner of an application is the only user that is able to delete an application that means that this permission is also the "Delete Application" permission.
|-
|}
| [[file:slider_right.png|30px]]
| View all
| xThe user can view all events for all applications
|-
| [[file:slider_right.png|30px]]
| Manage all
| xThe user can change the status and set the event to closed
|-
| [[file:slider_right.png|30px]]
| View internal Veloopti events
| xUser can view events that have been created internally by server agents. These can be used to help diagnosing agent issues.
|-
|}
| [[file:slider_right.png|30px]]
| View Audit Logs
| xThe user can view the logs that are created any time a change is made in Veloopti
|-
| [[file:slider_right.png|30px]]
| View Notification Logs
| xThe user can view the logs that are created any time a notification is sent.
|-
| [[file:slider_right.png|30px]]
| View Security Logs
| xThe user can view logs that are created any time a user does something in Veloopti. This included logon and logout activities.
|-
| [[file:slider_right.png|30px]]
| View Billing Logs
| xThe user can view the logs that relate to billing
|-
|}
| [[file:slider_right.png|30px]]
| View all
| xThe user can view all nodes in the node list. They also can view the node properties.
|-
| [[file:slider_right.png|30px]]
| Deploy policies
| xThe user can deploy all application policies to servers whether they have access to the application or not.
|-
| [[file:slider_right.png|30px]]
| Add Node to Applications
| xThe user can add a node to any application in the organisation.NOTE: The user does not need to have permission to view the application to add it.
|-
| [[file:slider_right.png|30px]]
| Relabel Nodes
| xThe user is able to change the label of the node
|-
| [[file:slider_right.png|30px]]
| Remove Nodes
|The user is able to remove the node from the organisation|-
|}
| [[file:slider_right.png|30px]]
| Manage Node Billing Plan
| xThe user is able to change the billing plans for any node that they can see
|-
| [[file:slider_right.png|30px]]
| View Organisation Billing Details
| xThe user is able to view the invoices for the organisation
|-
| [[file:slider_right.png|30px]]
| [[file:slider_right.png|30px]]
| Change Default Settings
| xThe user can change the organisation default settings of: Language; Time Zone and Default new node plan.
|-
| [[file:slider_right.png|30px]]
| Manage Schedules
| xThe user can change the schedules
|-
| [[file:slider_right.png|30px]]
| Add Users to Global and Application Roles
| xUser can add and remove users in Global and Application roles.NOTE: The user needs to be granted access to the application before they can add or remove users from the applications roles.
|-
| [[file:slider_right.png|30px]]
| Edit Global and Application Role Permissions
| xUser can edit a role by adding or removing permissions from it. They also can create new roles.NOTE: The user needs to be granted access to the application before they can add or remove permissions from the applications roles.
|-
| [[file:slider_right.png|30px]]
| Manage Auto Discovery
| xThe user can manage the auto discovery options for discovering application on servers
|-
|}
| [[file:slider_right.png|30px]]
| View All
| xThe user can view storm rules
|-
| [[file:slider_right.png|30px]]
| Manage All
| xThe user can create and edit storm rules
|-
|}
| [[file:slider_right.png|30px]]
| Manage all
| xAllows the user full permissions to policies for any application that they are able to view. Can be used in conjunction with the application "View all" global permission to empower a user to enter any application and modify the policies.
|}
| [[file:slider_right.png|30px]]
| Add Users to Global Roles
| xThe user can add and remove users from global roles
|-
| [[file:slider_right.png|30px]]
| Invite User to Organisation
| xThe user can send an invitation to an external email address to add them to their organisation
|-
| [[file:slider_right.png|30px]]
| Remove User from Organisation
| xThe user can remove any user, except for the organisation owner, from the organisation
|-
| [[file:slider_right.png|30px]]
| View Active User Sessions
| xThe user can view active user sessions for all users
|-
| [[file:slider_right.png|30px]]
| View Expired User Sessions
| xThe user can view expired user sessions for all users
|-
| [[file:slider_right.png|30px]]
| Kill any Users Session
| xThe user can kill any users active session.
|-
| [[file:slider_right.png|30px]]
| Add User to Application
| xThe user can add another user to any application that they can view
|-
| [[file:slider_right.png|30px]]
| Add / Remove user from Application User Group
| xThe user can add or remove a user from an application user group that they can view
|-
| [[file:slider_right.png|30px]]
| Add Other Users to this Role
| xAllows any member of the role to add another user to the role. This means that the members of the role are able to self manage rather than having to rely on someone with the Global "Assign User to Global Role" role.
|-
|}
| [[file:slider_right.png|30px]]
| Manage all
| x Can be used in conjunction with the application "View all" global permission to empower a user to enter any application and modify the dashboards.
|-
|}
| [[file:slider_right.png|30px]]
| View all actions
| xThe user can view all of actions in the application
|-
| [[file:slider_right.png|30px]]
| Run Operator Actions
| xThe user can run actions that have an operator level permission.
|-
| [[file:slider_right.png|30px]]
| Run Power User Actions
| xThe user can run actions that have a Power User level permission.Note: This does not mean that users have permission to run an operator level action.
|-
| [[file:slider_right.png|30px]]
| Run Administrator Actions
| xUser can run actions that have an Administrator level permission.Note: This does not mean that users have permission to run an Operator or Power User level action.
|-
| [[file:slider_right.png|30px]]
| Manage Actions
| xThe user is able to create, edit and delete actions.
|-
| [[file:slider_right.png|30px]]
| Assign Action to Action Group
| xThe user can add actions to actions group. This allows the action to be available to be run on any server in the application.
|-
| [[file:slider_right.png|30px]]
| Manage Groups
| xThe user can add and remove action groups
|-
|}
| [[file:slider_right.png|30px]]
| View Events
| xThe user can view events for the application
|-
| [[file:slider_right.png|30px]]
| Edit Event Description
| xThe user can change the event description for an open event.NOTE: Under no circumstances can the description for a closed event be changed.
|-
| [[file:slider_right.png|30px]]
| Change Event Severity
| xThe user can change the event severity for an open event.NOTE: Under no circumstances can the severity for a closed event be changed.
|-
| [[file:slider_right.png|30px]]
| Run Action from Event
| xThe user is able to run an action on a node from an event.NOTE: The user also needs to have the run Operator/Power User/Administrator permission in order for the action to be available to them.
|-
| [[file:slider_right.png|30px]]
| Close Events
| xUser can close an open event.NOTE: Once closed an event cannot be re-opened.
|-
|}
=== Owner ===
The role of owner has permanent permissions that cannot be revoked. Even if all roles are lost to everyone else in the organisation the owner is still able to access the ones below. Once the role of owner is given to another user it cannot be taken back. If the role of owner is somehow lost to an organisation then contact Veloopti.
{| class="wikitable" style="text-align: left; color: black;"
|
|-
| Assign permissionsEdit Global and Application Role Permissions
| [https://ap1.veloopti.com.au/permissions ap1.veloopti.com.au/permissions]
|
| style="text-align:center;" | Menu item
|-
| Assign Add Users to Global and Application Roles| [https://ap1.veloopti.com.au/roles/index/ ap1.veloopti.com.au//roles/index/<Global role name>]
|
|