A role is intended for assigning a group of users individual rights and permissions for administration, management and/or monitoring of individual components of Axxon One.
To register a new role, perform the following:
Select priority of PTZ cameras control for users with the current role.
Select priority of map access for users with the current role (2).
Access level | Description |
View only | You can only view maps |
View/move/scale | You can move and scale maps |
Full access | All options available |
If you need to limit access of users of a given role to all system archives, you can specify the retention time (archive depth) limit in the Archive depth viewing restriction field (3). If no limit is set, users may access the entire Video Footage.
Creating comments (see Operator comments) and protected records in Video Footage (see Protecting video footage from FIFO overwriting).
Access level | Description |
No access | No comments allowed |
Create | Add comments to archives |
Create / Protect | Add comments to archives, create protected records |
Create / Protect / Edit / Delete | Add comments to archives, create and edit protected records |
Editing layouts (see Configuring Layouts).
Access to the Web server (see Working with Axxon One Through the Web-Client).
Context menu of a video camera in a viewing tile (see Viewing Tile Context Menu).
Configure access rights to the Settings tabs and to system error messages (5).
Attention!
If you set the User Permission Settings parameter to Device access rights only, all users of the given role will be permitted to change only access rights to connected devices.
Note
Error messages are displayed in real time in the Layouts interface
Set access permissions for Layouts in Axxon One (6). This setting is related to both primary and web clients.
Set the parameters to apply the four-eyes principle (7):
If the administrator has to confirm the login of users of this role, select the corresponding role in the Supervisor for authorization in client list.
If you need to grant the users in this role permissions only for a certain period of time, select a Time schedule (8) from the list. These users will not be able to use their permissions outside of the selected time schedule.
Configure rights to manage connected Clients' monitors by setting permissions for each Server on an Axxon domain (9). A user who has management permissions for the monitors of a particular Server can manage monitors of any Client connected to that Server.
Set permissions for access to hardware and archives on an Axxon domain (10).
Device | Access permissions | Description |
---|---|---|
Video camera | No access | You cannot access the device. |
Archive only | You can only view video footage in archive. | |
Live in Armed mode | You can view video from the camera only when the camera is armed. | |
Live | You can live video from the camera. Other functions and device configuration are not available. | |
Live/Archive | You can view live and recorded video from the camera. You cannot arm/disarm/configure the camera. | |
Live/Archive/Control | All functions available. You cannot configure the device. | |
Live/Archive/Control/Configure | All functions and settings available. | |
Microphone | No access | The user is unable to listen to live sound from the video camera. The user is unable to listen to sound recordings from the archive. |
Live Audio | The user is able to listen to live sound from the video camera (the microphone must be turned on). The user is unable to listen to sound recordings from the archive. | |
Live Audio and Archive | All functions are accessible. | |
PTZ | No access | The user cannot control the PTZ device. |
Minimum level | The user can control the PTZ device with the corresponding priority (see Controlling a PTZ Camera). | |
Low level | ||
Medium level | ||
High level | ||
Maximum level | ||
Archive | No access | Access is not provided to this archive. |
Full access | Archive is available for all functions. |
You can configure group rights for accessing devices and archives of a particular Server. To do so, select an access level for the Server object. Depending on the level that is chosen, particular access levels are automatically configured for the devices and archives of the relevant Server (see table).
Server access level | Device/archive | Device/archive access level |
Custom | - | Access levels for devices and archives are set manually. |
No access | - | No access to devices and archives. |
Archive Only | Video camera | Archive only. |
Microphone | Live Audio and Archive. | |
PTZ | Medium level. | |
Archive | Full access. | |
Live in Armed Mode | Video camera | You can view armed cameras. |
Microphone | Live Audio. | |
PTZ | Medium level. | |
Archive | No access. | |
Live | Video camera | You can view live video. |
Microphone | Live Audio. | |
PTZ | Medium level. | |
Archive | No access. | |
Live/Archive | Video camera | You can view live and recorded video. |
Microphone | Live Audio and Archive. | |
PTZ | Medium level. | |
Archive | Full access. | |
Live/Archive/Control | Video camera | All functions. Settings not available. |
Microphone | Live Audio and Archive. | |
PTZ | Medium level. | |
Archive | Full access. | |
Live/Archive/Control/Configure | Video camera | All functions + settings available. |
Microphone | Live Audio and Archive. | |
PTZ | Maximum level. | |
Archive | Full access. |
Select the appropriate access level to set the ability to manually run all or some macros (see Configuring Macros) from the Layouts interface:
Attention!
By default, created macros are available only to users from the admin group.
Users outside the admin group can create macros if they have the permissions to create them, but they cannot use them until they have the permissions to use them.
Click the Apply button to save the role.
The new role has now been created.
You can copy Roles. To do it, follow the steps below:
This creates a new identical role.
Note
To create an empty user role with no parameters specified, select the Roles common group, and click Create.
To delete a role, perform the following:
Select the role to delete.
Click Delete.
Note
You cannot delete a role if the user through which you logged into the system belongs to that role.
The role has now been deleted. All users under this role will also be deleted.