NEXT - multi-user system with access rights differentiation. A separate account can be created for each monitoring system operator, to be used for authorization in the web interface.
Access rights
Access rights depend on the user account role. There are following roles:
- Superadmin - assumes full access rights and is assigned by default to the "admin" user account. This role does not display anywhere, cannot be removed and cannot be assigned.
- Admin - NEXT administrator role. The role provides the following access rights:
- All operations with user accounts and user groups. The exception is "admin" user account.
- All operations with wireless devices.
- All operations with events.
- View monitoring system settings.
- Operator - provides the following access rights:
- View and manage wireless devices.
- View and manage events.
- View user accounts.
- Observer - assigned by default to all new NEXT user accounts. The role provides the following access rights:
- View wireless devices profiles.
- View and manage events.
- View user accounts.
Only one role can be assigned to one user at the same time.
Visibility Area
Visibility areas are a restrictive add-on for access rights. The visibility area limits the list of wireless devices that the user can access. The available devices list is determined by groups of devices assigned to a user account or group of accounts. Thus, the user will have access only to those devices that are included in the device groups assigned to him or the users group where he belongs. Visibility area is also determined by role:
- Superadmin and Admin - full visibility, a user will always see all devices.
- Operator and Observer - zero visibility, a user will only see devices included in groups assigned to him.
Let's look at the examples:
- Devices HostA and HostB included to the Group1 devices group.
- Devices HostC and HostD included to the Group2 devices group.
- User UserA has an Operator role the Group1 is assigned to him.
- User UserB has an Admin role the Group2 is assigned to him.
As a result:
- User UserA can manage the configuration of HostA and HostB devices. His role assumes the devices management, but the visibility area is limited only with devices group Group1.
- User UserB can perform all operations with all devices. His role allows any operation, and the visibility area is not limited. It means that assign device groups to a user with the admin role has no sense.
Superadmin account
NEXT by default has a super-administrator account with the name "admin". It has a following features:
- The administrator account login cannot be changed.
- An admin account can not re removed.
- The administrator account always has a Superadmin role.
User account management
Use the side menu to proceed to the user account management section:
By default, the section displays a list of groups and users accounts. For each account, the following values are displayed:
- "Role" - current user role.
- "Name" - user name.
- "Login" - user login.
- "Email" - user email address.
- "Source" - account source:
- NMS - local user account.
- LDAP - account obtained from the directory server using the LDAP protocol.
Users groups
Groups are necessary to effectively manage the NEXT users visibility areas. Each user group can be assigned one or more device groups. Thus, the visibility area of the group users will be extended to all devices included in the device groups assigned to this user group.
- Each user must be included in at least one user group.
- By default, in the monitoring system the "Administrators" group is created, and with "admin" user included. This group is required and cannot be removed.
User group creation
Для создания новой группы пользователей нажмите кнопку "Новая группа". На экране появится форма, содержащая следующие поля:
- "Название" - произвольное имя группы пользователей.
- "Описание" - произвольное описание группы.
Заполните эти поля и нажмите на кнопку "Сохранить" для создания новой группы.
Назначение групп устройств на группы пользователей
Удаление группы пользователей
Создание учетной записи пользователя
Для добавления новой учетной записи пользователя нажмите кнопку "Новый пользователь". На экране появится форма, содержащая две секции:
- Информация - основные параметры учетной записи пользователя:
- "Имя" - произвольное имя пользователя, например, его имя и фамилия.
- "Email" - адрес электронной почты пользователя, на который в дальнейшем будут отправляться уведомления.
- "Логин" - логин пользователя, используемый для аутентификации.
- "Пароль" и "Повтор пароля" - пароль учетной записи и его подтверждения.
- "Роль" - роль учетной записи.
- "Учетная запись активирована" - флаг активации/деактивации учетной записи пользователя. Пользователю с деактивированной учетной записью будет запрещен вход в web-интерфейс NEXT.
- Группы - группы пользователей, в которую включена данная учетная запись. В этой секции отображается список текущих групп. Для исключения учетной записи из группы или включения в новую нажмите кнопку "Выбрать группы", затем выберите или снимите выбор с соответствующих групп и нажмите кнопку "OK".
Для применения изменений нажмите кнопку "Сохранить".