The rights assigned to each role determine user access to dashboards and menus. Role rights determine the types of views that users can see and whether they can export data and customize settings.
Administrators can grant additional rights to users by editing their role. The Edit Role dialog lists role rights currently assigned to roles. And the Manage Users page shows the role assigned to each user.
Note: Do not remove the administrative role rights from your primary administrator account. Administrative access to the console is required.
The following list describes the available access rights to CA Performance Center features:
The following role rights give users access to administrative features. Limit the number of users with these role rights for increased security.
Lets users define and configure threshold profiles. Each user can only edit the profiles that he or she created. Unlike the Administer DA Threshold Profiles role right, this role right does not allow users to configure profiles that were created by other users, or to transfer ownership of profiles.
Lets users register new data sources, test data source connections, view data source status, change data source parameters, and remove data sources. Also lets users view the data source log.
Lets users without full administrative rights manage a specific branch of the Groups tree. With this role right, users can create, change, and delete groups only in the specified branch. The Administrator role and the Tenant Administrator role have this role right by default, allowing administration of All Groups and the Tenant root group, respectively.
Only the Administrator and the owner (creator) of the groups in the administered branch can delete groups in that branch. When an administered group is a child of another group (that is, a subgroup), the administered group is deleted when the parent group is deleted. Administered groups are not deleted when the user account of the owner is deleted.
Notes:
Lets users create, edit, and delete menus. This role right is required to assign new dashboards to menus. To assign menus to user accounts, the 'Administer Roles' role right is required.
Lets users create, edit, and delete user account roles. Lets users assign new menus to user accounts by editing roles.
Lets users manage their own and other users' dashboards. They can edit an existing dashboard page and save changes that are visible to other users.
Grants users administrative rights over the tenants that are selected in the user wizard. Users with this role have the rights to administer certain tenants while having limited access to the default tenant. This role is only used in multi-tenant environments. Tenant administration includes the ability to manage:
Lets users create, edit, and delete user accounts. Lets users assign new roles to user accounts.
Lets users define and configure threshold profiles. Each user can only edit the profiles that he or she created. Unlike the Administer DA Threshold Profiles role right, this role right does not allow users to configure profiles that were created by other users, or to transfer ownership of profiles.
Lets users create new dashboards and populate them with views. Other users cannot see these dashboards. To create dashboards for other users, the 'Administer Shared Dashboards' role right is required.
Lets users configure email notifications using the Create/Edit Notifications wizard from the Admin, Notification menu. Notifications are not supported for all data sources. The CA Performance Center Readme file contains an up-to-date list.
Lets users create, edit, and delete on-demand report templates. This role right is always assigned together with the Run On-Demand Report Templates right. Users can save on-demand report templates at the user level, which allows only the user to view the templates. Users can also save on-demand report templates at the tenant level, which allows all users within the tenant to view the template.
Lets a user with the Administrator role delete (unregister) a data source. Not assigned to any user or role by default. Can only be assigned to the Administrator role.
Lets a user access the Data Aggregator administrator page directly from a page that is associated with the Data Aggregator. For this role right to work properly, the user must also have the Administer Data Sources right. The ability to access the Data Aggregator administrator page is limited to views for Data Aggregator devices, interfaces, and components. Selecting a Data Aggregator interface or component causes the administrator page for the associated parent device to appear when clicking the gear
button and Device Admin.
Lets users edit, delete, add, or reorder tabs on context pages. A context is a managed item, such as a device, a router, a switch, or an interface. A context page resembles a dashboard with a fixed context. Only the Designer and Administrator roles have this right by default.
Lets users log in as a selected user to view and verify user account settings.
Lets users save edits they have made to the views on a shared page. Other users who can see these views can see the changes if they are applied as a 'Default for All Users'. The changes can also be saved to the user account so that they persist after logout.
Lets users troubleshoot SNMP profiles and view security information that is typically masked in clear text.
The following role rights give users access to reporting features. Most user accounts require these rights.
Lets users navigate to the data source interface during drilldown to see detailed data from a selected item.
Lets users drill in to a CA Performance Center context view to see detailed data from a selected item. Required to enable the 'Edit Context Pages' role right.
Lets users edit the views on a shared page for themselves. Other users who can see these views cannot see the changes. The changes can only be applied to the current login session or saved to the current user account.
Lets users edit their own time zone setting for data displayed in dashboards.
Lets users see specific client conversations.
Lets users see specific client host information.
Lets users see the display names or the aliases for items.
Note: Users who are given this role right can select which name to display in their dashboards and views in the My Settings, Display Settings menu item.
Lets users see only the aliases for items.
Determines whether users can access the Inventory tab and Search field to find items.
Lets users see protocol information where available.
Lets users see the Type of Service information in applicable views.
The following role rights give users the ability to export dashboard data in various formats:
Lets users export the contents of a selected view to a file in comma-separated values (CSV) format.
Lets users share views externally with a URL.
Lets users export the current dashboard page as a PDF and send it to a selected printer.
Lets users export dashboards as reports and send them to other users in email messages from the console.
Lets users set up schedules to export dashboards as reports and automatically send them by email on a recurring basis.
Note: This right also requires the 'Send Reports by Email' role right.
Lets users run on-demand report templates. This role right is always given together with the Create On-Demand Report Templates right. However, if the Create On-Demand Report Templates right is taken away, users do not lose the ability to edit and delete their on-demand dashboards. Users who have this right without the Create On-Demand Templates right can run on-demand report templates on the tenant level.
Lets users select higher resolutions when viewing dashboards. No roles in CA Performance Center are given this role right by default. Users with this role right can set and save the resolution to higher values than are typically allowed when reporting for longer time ranges. When users save the higher resolution at the tenant level, it is only visible to users with this role right.
Note: When a higher resolution is set, some charts may still display other resolutions for NULL data.
Role rights also include menus. You can grant access to selected custom and predefined menus by editing role rights.
|
Copyright © 2015 CA Technologies.
All rights reserved.
|
|