--- title: "CerteroX Role Permissions" canonical: "https://ai-docs.certero.com/space/CUP/118917234/CerteroX%20Role%20Permissions" format: markdown --- --- In <span style="color: #0000ff">Administration </span>> <span style="color: #0000ff">Roles </span>, you can build customised bundles of Certero application permissions to use as user security roles. The permissions are quite extensive and provide up to three levels of access to datagrids, data types, management objects, etc. The access levels are: - **No Access:**<span style="color: #000000"> </span>The data or management functionality is not visible to the Role. - **View: **The data or management functionality is visible but can’t be edited or otherwise managed. - **Edit:** The role has full access to see and manage the data or management function. If Edit permission is not available for an item, it means that the data is only designed to be viewed and there’s no possibility to modify, archive, assign ownership, change user-defined fields; or otherwise manage it. --- In the Role properties dialog, the sections down the left typically correspond to the Certero <span style="color: #0000ff">modules</span>. Modules are the units of functionality enablement in Certero customer licence keys. If, for example, a customer is licensed for <span style="color: #0000ff">Microsoft Licensing </span>, they will see the <span style="color: #0000ff">Microsoft Licensing Runtime and UI </span>section. On the right-hand pane of the currently selected section, you will see headings for <span style="color: #0000ff">permission groups</span>. The permissions in a group will have something in common. Let’s work through the pages, permissions groups and permissions to understand their characteristics. Any permission item referencing a <span style="color: #0000ff">Connector </span>means that the permission will control access to the data-grid for that Connector type. If there is No Access, then the main menu item to access the data-grid will not appear. If there is View access, the menu item will be available, the data-grid will be accessible for reporting, but no changes to the connectors can be made. We can now skip any further mention of Connectors permissions while we explore the permission sections. The table below explains the permissions for the sections <span style="color: #0000ff">Core Runtime </span>and <span style="color: #0000ff">Inventory Runtime </span>. These two sections are the most heavily populated with permissions and are the most challenging to understand. | | | | | | --- | --- | --- | --- | | <span style="color: #ffffff">Section </span> | <span style="color: #ffffff">Permission Group </span> | <span style="color: #ffffff">Permission </span> | <span style="color: #ffffff">Access Control Targets </span> | | <span style="color: #000000">Core Runtime </span> | <span style="color: #000000">Assets </span> | <span style="color: #000000">Computers </span> | <span style="color: #000000">Client Management > [all datagrids] </span><br><span style="color: #000000">Computer Systems > All Systems (no access to the OS-specific datagrids in Computer Systems) </span><br><span style="color: #000000">Miscellaneous > Duplicate Systems </span><br><span style="color: #000000">Miscellaneous > Operating Systems </span> | | | | <span style="color: #000000">Active Directory Objects </span> | <span style="color: #000000">All datagrids in the Active Directory menu that contain objects and data from AD Connectors. </span><span style="color: #0000ff">Drive Mappings </span><span style="color: #000000">, </span><span style="color: #0000ff">Printer Mappings </span><span style="color: #000000">and </span><span style="color: #0000ff">Profiles </span><span style="color: #000000">are not included as these come from Windows computer inventory. </span> | | | | <span style="color: #000000">Network Discovery Objects </span> | <span style="color: #000000">Network Devices > [all datagrids] </span> | | | | <span style="color: #000000">Data Groups </span> | <span style="color: #000000">Data Groups > [all items] </span><br><span style="color: #000000">(requires </span><span style="color: #0000ff">Active Directory Objects </span><span style="color: #000000">permission, above) </span> | | | | <span style="color: #000000">User-defined Assets </span> | <span style="color: #000000">User-defined Assets > [all items] </span><br><span style="color: #000000">Access to other main menu sections will be granted if where user-defined asset tables are configured to appear in them, but other items in such main menu sections will not appear unless granted by the relevant permissions. </span> | | | <span style="color: #000000">Administration </span> | <span style="color: #000000">Networks </span> | <span style="color: #000000">Administration > Networks </span> | | | | <span style="color: #000000">Logins and Roles </span> | <span style="color: #000000">Administration > Logins </span><br><span style="color: #000000">Administration > Roles </span><br><span style="color: #000000">Administration > User Profiles </span> | | | | <span style="color: #000000">DNS Servers </span> | <span style="color: #000000">Administration > DNS Servers </span> | | | | <span style="color: #000000">Plugin Tools </span> | <span style="color: #000000">Administration > Plugin Tools </span> | | | | <span style="color: #000000">Zones </span> | <span style="color: #000000">Administration > Zones </span> | | | | <span style="color: #000000">API Keys </span> | <span style="color: #000000">Administration > API Keys </span> | | | | <span style="color: #000000">Endpoint Servers </span> | <span style="color: #000000">Administration > Endpoint Servers </span><br><span style="color: #000000">Edit permissions are not available here and are bestowed by membership of the built-in SysAdmin Role </span> | | | | <span style="color: #000000">User-defined Fields/Assets </span> | <span style="color: #000000">Administration > User-defined Assets </span><br><span style="color: #000000">Administration > User-defined Fiels </span> | | | | <span style="color: #000000">Computer Configurations </span> | <span style="color: #000000">Computer Systems > Configurations </span> | | | | <span style="color: #000000">Reporting Levels </span> | <span style="color: #000000">[to be confirmed / deprecated] </span><br><span style="color: #000000">The ability to assign Reporting Levels to Roles is bestowed by the </span><span style="color: #0000ff">Logins and Roles </span><span style="color: #000000">permission, above. Access to manage Orgs and OUs requires access to the </span><span style="color: #0000ff">Global Settings </span><span style="color: #000000">menu via the </span><span style="color: #0000ff">SysAdmin </span><span style="color: #000000">Role. </span> | | | | <span style="color: #000000">Currencies </span> | <span style="color: #000000">Administration > Currencies </span> | | | | <span style="color: #000000">Rules </span> | <span style="color: #000000">Administration > Object Rules </span> | | | | <span style="color: #000000">Filters </span> | <span style="color: #000000">Governance > Filters </span> | | | | <span style="color: #000000">Policies </span> | <span style="color: #000000">Governance > Policies </span> | | | | <span style="color: #000000">Authentication Providers </span> | <span style="color: #000000">Administration > Authentication Providers </span> | | <span style="color: #000000">Inventory Runtime </span> | <span style="color: #000000">Assets </span> | <span style="color: #000000">Computers </span> | <span style="color: #000000">Computer Systems > [all except All Systems] </span><br><span style="color: #000000">Docker > [all datagrids] </span><br><span style="color: #000000">Miscellaneous > Monitors </span><br><span style="color: #000000">Software > [all except Autodesk Products] </span> | | | | <span style="color: #000000">SQL Servers </span> | <span style="color: #000000">Miscellaneous > SQL Instances </span> | | | | <span style="color: #000000">User Profile Information </span> | <span style="color: #000000">Active Directory > Drive Mappings </span><br><span style="color: #000000">Active Directory > Printer Mappings </span><br><span style="color: #000000">Active Directory > Profiles </span> | | | | <span style="color: #000000">Virtualization </span> | <span style="color: #000000">Virtualization > [all datagrids except for VMware Licences] </span> | | | | <span style="color: #000000">Product Keys </span> | <span style="color: #000000">Exposes the </span><span style="color: #0000ff">Product Keys </span><span style="color: #000000">properties group on the </span><span style="color: #0000ff">Software </span><span style="color: #000000">section of the properties dialog of a Microsoft Windows Computer System. Possibly also applies to other locations in Certero where product keys are displayed. </span> | | | | <span style="color: #000000">Microsoft Exchange </span> | <span style="color: #000000">Microsoft Exchange > [all datagrids] </span> | | | | <span style="color: #000000">Certificates </span> | <span style="color: #000000">Miscellaneous > Certificates </span> | | | <span style="color: #000000">Administration </span> | <span style="color: #000000">[per connector] </span> | <span style="color: #000000">[per connector] </span> | Full (edit) access to a data-grid doesn’t guarantee you will be able to see and do everything on that data-grid without permissions to additional, associated things. For example, access to a computer data-grid without access to AD data will prevent you from opening computer property pages or assigning ownership to users. Although it’s unlikely that Certero administrators would require such unusual splitting of permissions, the facility is there in Certero to achieve it; so be mindful of possible consequences. The permission sections not covered by the table above are for the other Certero modules, e.g. Distribution, Patching, Apps Monitor, Passworks, Cloud, and the range of general and specialist licensing modules. Most of these are straightforward and self-explanatory for users who understand the module. Where a module's permissions benefit from explanation, they are documented in their own section below. --- ## Apps Monitor The Apps Monitor permissions appear in the role dialog under the section labelled **AppsMonitor Runtime & UI**. That section contains a single permission group, **Apps Monitor**, with two permissions: | Permission | Access Control Targets | | --- | --- | | Monitoring Data | Governs access to the Apps Monitor screens: Files, Computers, Users and Tags. View makes the screens visible (read-only). Edit is required for management actions on those screens, including creating and applying Tags. Tag management is included here and is not separately restricted. The Computers and Users screens are inherently view-only. | | File Groups | Currently unused. This permission remains in the role dialog from an earlier version of Apps Monitor but has no corresponding feature in the current product, so it can be ignored. | The Apps Monitor section only appears if the customer is licensed for the Apps Monitor module. As with all permission changes, users must sign out and back in for the change to take effect. --- If there’s an administrative permission or function in the Certero application that’s not visibly managed by custom Roles, then the built-in <span style="color: #0000ff">SysAdmin </span>Role will bestow the access. A user with no permissions assigned, nor membership of the SysAdmin Role, will only see <span style="color: #0000ff">Reports </span>in the main menu; but reporting access to various data types will not be available unless the relevant permissions are assigned. If a user has multiple roles assigned, then they will receive the sum of the highest level of permissions for all the roles. For example, if one role gives the user read only permissions to a certain thing, and they are assigned another role that gives edit permissions to the same thing, then the user will have edit permissions for that thing. Users will typically need to sign out and back into Certero realize permission changes. ---