Previous Topic: Predefined RolesNext Topic: Data Source-Specific Role Rights


Role Rights

The rights assigned to each role determine user access to dashboards and menus. Role rights determine the types of views that users can see and whether they can export data and customize settings.

Administrators can grant additional rights to users by editing their role. The Edit Role dialog lists role rights currently assigned to roles. And the Manage Users page shows the role assigned to each user.

Note: Do not remove the administrative role rights from your primary administrator account. Administrative access to the console is required.

The following list describes the available access rights to CA Performance Center features:

Administrative Role Rights

The following role rights give users access to administrative features. Limit the number of users with these role rights for increased security.

Administer Data Sources

Lets users register new data sources, test data source connections, view data source status, change data source parameters, and remove data sources. Also lets users view the data source log.

Administer Groups

Lets users without full administrative rights manage a specific branch of the Groups tree. With this role right, users can create, change, and delete groups only in the specified branch. The Administrator role and the Tenant Administrator role have this role right by default, allowing administration of All Groups and the Tenant root group, respectively.

Only the Administrator and the owner (creator) of the groups in the administered branch can delete groups in that branch. When an administered group is a child of another group (that is, a subgroup), the administered group is deleted when the parent group is deleted. Administered groups are not deleted when the user account of the owner is deleted.

Notes:

Administer Menus

Lets users create, edit, and delete menus. This role right is required to assign new dashboards to menus. To assign menus to user accounts, the 'Administer Roles' role right is required.

Administer Roles

Lets users create, edit, and delete user account roles. Lets users assign new menus to user accounts by editing roles.

Administer Shared Dashboards

Lets users manage their own and other users' dashboards. They can edit an existing dashboard page and save changes that are visible to other users.

Administer Users

Lets users create, edit, and delete user accounts. Lets users assign new roles to user accounts.

Create a Dashboard

Lets users create new dashboards and populate them with views. Other users cannot see these dashboards. To create dashboards for other users, the 'Administer Shared Dashboards' role right is required.

Create Notifications

Lets users configure email notifications using the Create/Edit Notifications wizard from the Admin, Notification menu. Notifications are not supported for all data sources. The CA Performance Center Readme file contains an up-to-date list.

Delete Data Sources

Lets a user with the Administrator role delete (unregister) a data source. Not assigned to any user or role by default. Can only be assigned to the Administrator role.

Edit Context Pages

Lets users edit, delete, add, or reorder tabs on context pages. A context is a managed item, such as a device, a router, a switch, or an interface. A context page resembles a dashboard with a fixed context. Only the Designer and Administrator roles have this right by default.

Proxy Users

Lets users log in as a selected user to view and verify user account settings.

Save Changes to Shared Views

Lets users save edits they have made to the views on a shared page. Other users who can see these views can see the changes if they are applied as a 'Default for All Users'. The changes can also be saved to the user account so that they persist after logout.

SNMP Clear Text

Lets users troubleshoot SNMP profiles and view security information that is typically masked in clear text.

Role Rights for Dashboard and View Access

The following role rights give users access to reporting features. Most user accounts require these rights.

Browse to Device

Lets users navigate to the web page of a selected device.

Drill into Data Sources

Lets users navigate to the data source interface during drilldown to see detailed data from a selected item.

Drill into Views

Lets users drill in to a CA Performance Center context view to see detailed data from a selected item. Required to enable the 'Edit Context Pages' role right.

Edit Shared Views

Lets users edit the views on a shared page for themselves. Other users who can see these views cannot see the changes. The changes can only be applied to the current login session or saved to the current user account.

Edit Time Zone

Lets users edit their own time zone setting for data displayed in dashboards.

Set a Home Page

Lets users select a dashboard to set as the default page displayed when they log in.

View Analysis Pages

Lets users view and interact with the Analysis tab.

View Conversations

Lets users see specific client conversations.

View Hosts

Lets users see specific client host information.

View Inventory and Search

Determines whether users can access the Inventory tab and Search field to find items.

View Protocols

Lets users see protocol information where available.

View ToS

Lets users see the Type of Service information in applicable views.

Role Rights to Export and Print

The following role rights give users the ability to export dashboard data in various formats:

Export to CSV

Lets users export the contents of a selected view to a file in comma-separated values (CSV) format.

Generate URLs for views

Lets users share views externally with a URL.

Print a Dashboard

Lets users export the current dashboard page as a PDF and send it to a selected printer.

Send Reports by Email

Lets users export dashboards as reports and send them to other users in email messages from the console.

Send Reports on a Schedule

Lets users set up schedules to export dashboards as reports and automatically send them by email on a recurring basis.

Note: This right also requires the 'Send Reports by Email' role right.

Role rights also include menus. You can grant access to selected custom and predefined menus by editing role rights.

More information:

Add a Role

Data Source-Specific Role Rights

Predefined Roles