Role Privileges

The following lists privileges that can be assigned to user roles.

  • DeviceAdvancedRead and DeviceAdvancedWrite are required to upload drivers. DeviceAdvancedWrite is required to manage assignments of driver packages.

  • The DriverDownload permissions that enable downloading of drivers and packages are automatically allocated to users who can access the download URL.

Item

Description

AddressBookRead

  • Display Address Book contents

AuditRead

  • Display software settings audit logs

SysConfigRead

  • Display the system settings information

DeviceBasicRead

  • Display all information related to devices other than tasks, templates and notifications

DeviceAdvancedRead

  • Display all information related to devices such as tasks, templates and notifications

  • Display structure change notification policies

SecurityRead

  • View the role, user, LDAP/Kerberos profile of a user

AddressBookWrite

  • Create/update/delete Address Book contents

AuditWrite

  • Delete software settings audit logs

SysConfigWrite

  • Update system settings (other than the role, user, LDAP/Kerberos profile of a user)

DeviceBasicWrite

  • Create/update/delete discovery profiles, polling tasks and related tasks

  • Create/update/delete device groups

  • Change device access accounts and custom properties

  • Update e-mail address lists

DeviceAdvancedWrite

  • Create/update/delete device settings, SDK/J Platform and Embedded Applications

  • Add/update/delete structure change notification policies

  • Update device drivers

SecurityWrite

  • Create/update/delete the role, use, LDAP/ Kerberos profile of a user

LogDelete

  • Delete logs

ReportRead

  • Display reports

ReportWrite

  • Create/update/delete/configure schedules for reports

@RemoteAdmin

  • Read all @Remote setting items and update partial @Remote setting items

@RemoteCE

  • Read and update all @Remote setting items

DriverDownload

  • Download device drivers and driver packages

TemporaryCardChange

  • Change the use day of a temporary card

WorkflowOperationRead

  • Display General Settings of Workflows, Shared Connector Settings, Design of Workflows, Device Applications, Workflow Profile, and Connectors

PrintOperationRead

  • Display Print Rules

 

AccountingOperationRead

  • Display Pricing Table

  • Display Accounting Tasks

SlnxUserOperationRead

  • Display Groups, Departments, Cost Centers, Users, Permissions, and Synchronization Tasks of User Management

  • Display User Management and Accounting Settings of System Settings

CardOperationRead

  • Display Card Information

EmbeddedOperationRead

  • Display Streamline NX Embedded Applications Information (related to authentication function)

WorkflowOperationWrite

  • Create/update/delete General Settings of Workflows, Shared Connector Settings, Design of Workflows, Device Applications, Workflow Profile, and Connectors

PrintOperationWrite

  • Create/update/delete Print Rules

AccountingOperationWrite

  • Create/update/delete Pricing Table

  • Create/update/delete Accounting Tasks

SlnxUserOperationWrite

  • Create/update/delete Groups, Departments, Cost Centers, Users, Permissions, and Synchronization Tasks of User Management

  • Update User Management and Accounting Settings of System Settings

CardOperationWrite

  • Create/update/delete Card Information

EmbeddedOperationWrite

  • Create/update/delete Streamline NX Embedded Applications Information (related to authentication function)

DisplayMessageRead

  • Obtain device display messages

DisplayMessageWrite

  • Update device display messages

QuotaOperationWrite

  • Enable/disable Enforce Color Page Limit, Enforce Account Limit, Adjust Color Page Limit, Adjust Accounting Limit, Adjust Color Page Balance, and Adjust Account Balance

ViewAllInitiatedDownload

  • View all downloads initiated within SLNX for security purposes

SecurityAnalystRead

  • View the Security Analyst Dashboards within the Management Console.

SecurityAnalystWrite

  • Configure and view the Security Analyst Dashboards within the Management Console.

DeviceMemoryErase

  • Ability to configure and execute the Remote Erase All Memory task that will reset all devices to the factory state.  Note that this privilege is available to the Customer Engineer Role only. When this privilege is enabled, the "Remote Erase All Memory" option appears on the Configuration Task, General Tab as a template type. This task type cannot be scheduled and must be run immediately.