Documentation for Axxon One 2.0. Documentation for other versions of Axxon One is available too.

Previous page Types of permissions to access hardware, archives and macros  LDAP catalogs Next page

On the page:


General information

A role is intended for assigning a group of users individual rights and permissions for administration, management and/or monitoring of individual components of Axxon One.

Creating a role

To create a new role, do the following:

  1. At the end of the list of system roles, click the Create link. The new role is added to the system, with its properties displayed on the right side.
  2. Configure the access permissions:

    ParametersAccess levelDescription
    Basic
    NameEnter a name for the role
    Map controlSelect the access level to the maps for users with this role
    Map managementNo accessUsers cannot view maps
    View onlyUsers can only view maps
    View/move/scaleUsers can views, move, and scale maps
    Full accessAll operations with map are available

    Other

    Archive depth viewing restrictionIf you need to limit the access of users of this role to all system archives, you can specify the archive depth limit in hours. If no limit is set, users can view all videos
    Access to Functions Set access permissions to Axxon One functions
    Access to confidential commentsYesAdd and view confidential comments
    No

    Access to Search in archive mode 

    Yes

    Archive search (see Video surveillance in the Archive Search mode)

    No
    Adding camera to layout in monitoring modeYes 

    Add a camera to a layout in the Live mode (see Adding cameras to cells)

    No
    Adding/editing presetsYes

    Add and edit presets for PTZ cameras (see Selecting a preset)

    No
    Alarms processing

    Alarms management (see Video surveillance in the Alarm management mode)

    No accessUsers have no access to alarm events
    View onlyUsers can view alarm events, but they can't assess them
    Full accessUsers can view alarm events and assess them
    Allow comments in archiveCreate comments in the archive (see Operator comments) and protected records (see Protecting video recordings from FIFO overwriting)
    No accessNo comments allowed
    CreateUsers can add comments to the archive
    Create/ProtectUsers can add comments to the archive, create protected records
    Create/Protect/ Edit and deleteUsers can add comments to the archive, create and edit protected records
    Allow to delete recordsYes

    Remove videos from the archive (see Deleting a part of archive)

    No
    Allow unprotected exportYes

    Export frames and videos without password protection (see Frame export, Standard video recordings export). Set No to require setting a password when exporting (see Exporting frames and video recordings)

    No
    ExportYes

    Export frames and videos (see Exporting frames and video recordings)

    No
    Layouts editingYes

    Edit layouts (see Editing layouts)

    No
    Minimize to taskbarYes

    Minimize the client to the tray (see Interface of Axxon One)

    No
    Operating domainYes

    Manage Axxon domain (see Operations with domains)

    No
    Permissions to access via WebUIYes

    Access to the Web-Server (see Working with Axxon One through the Web-Client)

    No
    Show captionsYes

    Display captions (see Viewing titles from POS terminals)

    No
    Show facesYes

    Showing faces (see Masking faces)

    No
    System logYes

    View the system log (see System log)

    No
    Unlock camera menu buttonYes

    Context menu of a camera (see Context Menu of the Surveillance window)

    No
    View masked videoYes

    View masked video (see Configuring privacy masking in archive, Configuring the People masking)

    No
    Access to InterfacesConfigure the access permissions to the interfaces
    Group panelsYes

    Configure the access permissions to camera groups on the Hardware tab and to the camera groups on the Layouts interface

    No
    Layouts tabYes

    Configure the access permissions to the Layouts tab. This parameter applies to both the client and the Web-Client (see Web-Client GUI)

    No
    Objects panel and Camera search panelYes

    Configure the access permissions to the Objects panel (see Objects Panel) and the Camera search panel (see Camera Search Panel)

    No
    Access to Settings
    Archive settingsYes
    • Configure the access permissions to the Settings tabs

    Attention!

      • If you select the Device access rights only value in the User Permission settings parameter, all users of the given role will have the permissions to change only the access permissions to the connected devices.
      • If the Programming setup is not available for the user role, the user will not be able to use the created macros until the appropriate permissions are granted.
    • Configure the access permissions to the system error messages

    Attention!

      • System error messages are displayed in real-time in the Layouts interface.

      • Critical error messages in the system are displayed regardless of the Show error messages parameter.
      • Critical errors include:
        • geomap connection error;
        • export error;
        • domain disconnection error;
        • insufficient network bandwidth error that is disabled by default. If necessary, you can enable it by adding the SHOW_INSUFFICIENT_BANDWIDTH_WARNING system variable with the TRUE value (see Appendix 9. Creating system variable).
    No
    Detection settingsYes
    No
    Device settingsYes
    No
    Options settingsYes
    No
    Programming setupYes
    No
    Show error messagesYes
    No
    User Permission settingsYes
    Device access rights only
    No
    Additional
    Comment

    Specify additional information about the user, if necessary

    Supervisor confirmation
    Supervisor for acccess to export
    • If the administrator has to confirm the launch of export for users of this role (see Exporting frames and video recordings), select the corresponding role in the list
    • If the administrator has to confirm the login of users of this role (see Starting the client), select the corresponding role in the list

    Attention!

    • If a user belongs to several roles and each of these roles has its own supervisor, the user can receive confirmation to access export or authorization from a single administrator.

      Note

      For example, a user can belong to several roles at the same time: Operator 1, Operator 2, Operator 3.
      Each of these roles has its own supervisor:

      • For Operator 1, the supervisor is Admin 1.
      • For Operator 2, the supervisor is Admin 2.
      • For Operator 3, the supervisor is Admin 3.

      The user needs to receive confirmation from only one of the three administrators.

    • If a user belongs to a regular role (such as Operator) and an administrator role at the same time, supervisor confirmation isn't required, provided that the administrator role can be used as supervisor.

      Note

      For example, a user belongs to the Operator 1 and Admin 1 roles at the same time. If Admin 1 is selected as supervisor in the Supervisor confirmation settings, the user doesn't need to receive confirmation to access export or authorization.

    Supervisor for authorization in client
    Time schedule management
    Time schedule

    If you need to grant the users in this role permissions only for a certain period of time, select a time schedule from the list. These users will not be able to use their permissions outside of the selected time schedule

    Video walls management
    ServerYes

    Configure the permissions to manage the connected clients' monitors by setting permissions for each server on Axxon domain. A user who has management permissions for the monitors of a particular server can manage monitors of any client connected to that server

    No
  3. On the Groups tab, configure the Default permissions (see Types of permissions to access hardware, archives and macros).

    Note

    When you create a new role, you cannot go to another tab until the role is saved. If you change any access permissions on any tab, you cannot go to another tab until the settings are saved.

    Device

    Access level

    Description

    Default permissionsConfigure the default permissions to devices

    Camera access

    No access

    No access to the device

    Archive only

    User can view only the archive

    Live in Armed mode

    User can view video from the camera only when the camera is armed

    Live

    User can view live video from the camera. Other functions and device configuration are not available

    Live/Archive

    User can view live and recorded video from the camera. User cannot arm/disarm/configure the camera

    Live/Archive/Control

    All functions available. User cannot configure the device

    Live/Archive/Control/Configure

    All functions and device configuration available

    Microphone access

    No access

    User cannot listen to live audio:

    • from the camera;
    • in the archive.

     Audio recording to an exported file is not available

    Live Audio

    User can listen to live audio from the camera (the microphone must be turned on). User cannot listen to audio in the archive

    Live Audio and Archive

    All functions are available

    PTZ priority

    No access

    User cannot control the PTZ device

    Minimum level

    User can control the PTZ device with the corresponding priority (see Controlling a PTZ сamera)

    Low level
    Medium level
    High level
    Maximum level
  4. On the Groups tab, configure the Group permissions if there are camera groups (see Configuring video camera groups).

    Device

    Access level

    Description

    Group permissionsConfigure group access permissions to cameras (see Types of permissions to access hardware, archives and macros)

    Camera group









    InheritedAccess permissions are inherited from the Default permissions tab Camera access

    No access

    No access to the device

    Archive only

    User can view only the archive

    Live in Armed mode

    User can view video from the camera only when the camera is armed

    Live

    User can view live video from the camera. Other functions and device configuration are not available

    Live/Archive

    User can view live and recorded video from the camera. User cannot arm/disarm/configure the camera

    Live/Archive/Control

    All functions available. User cannot configure the device

    Live/Archive/Control/Configure

    All functions and device configuration available

  5. If necessary, configure the access permissions to a specific device on the Devices tab.
    To do this, select the access level for a specific device (see Types of permissions to access hardware, archives and macros). 

    Access levelDeviceAccess level to device
    Inherited

    CameraAccess levels are inherited from the Default permissions tab Groups or from the group permissions
    MicrophoneAccess levels are inherited from the Default permissions tab Groups
    PTZ
    Archive only

    CameraArchive only
    MicrophoneLive audio and archive
    PTZMedium level
    Live in Armed mode

    CameraView in armed mode
    MicrophoneLive audio
    PTZMedium level
    Live

    CameraView live video
    MicrophoneLive audio
    PTZMedium level
    Live/Archive

    CameraView live video and archive
    MicrophoneLive audio and archive
    PTZMedium level
    Live/Archive/Control

    CameraAll functions, configuration isn't available
    MicrophoneLive audio and archive
    PTZMedium level
    Live/Archive/Control/ConfigureCameraAll functions, configuration is available
    MicrophoneLive audio and archive
    PTZMaximum level

    You can specify the access level to a specific camera and extend it to other cameras. To do this, do the following:

    1. Select the access level to a camera from a drop-down list on the Devices tab.
    2. Click the button and select the cameras, to which you want to specify the same access level.

    3. Click the Apply button.

    As a result, the specified access level is extended to the selected cameras.
    To quickly select multiple cameras, press down the Shift key, select the first and last camera, to which you want to specify the same access level. The checkboxes set for all selected cameras when you select any of them.

    Note

    Similarly, you can extend the access levels to microphones, PTZ devices and archives.

  6. Configure the Default permissions to domain archives or Archive permissions to a specific archive in the Archives section.

    DeviceAccess levelDescription
    Default permissionsConfigure the default access permissions to the archive (see Types of permissions to access hardware, archives and macros)
    Archive accessNo accessNo access to this archive

    Full accessFull access to the archive
    Archive permissionsConfigure the permissions to a specific archive (see Types of permissions to access hardware, archives and macros)
    Archive 

    InheritedAccess level is inherited from the Default permissions tab
    No accessNo access to this archive
    Full accessFull access to the archive
     
  7. Configure the Default permissions to macros or Macro permissions to a specific macro in the Macros section.

    Attention!

    Users outside the admin role can create macros, if they have the permissions to create them. They cannot use them until they have the permissions to use them.

    Macro typeAccess levelDescription
    Default permissionsConfigure the default permissions to macros (see Types of permissions to access hardware, archives and macros)
    Macro accessNo accessNo access to macros
    Full accessFull access to macros
    Macro permissionsConfigure the access permissions to a specific macro (see Types of permissions to access hardware, archives and macros)

    Automatic rules

    InheritedAccess level is inherited from the Default permissions tab
    No accessNo access to macros
    Full accessFull access to macros
    Event rulesInheritedAccess level is inherited from the Default permissions tab
    No accessNo access to macros
    Full accessFull access to macros
    Cycle rulesInheritedAccess level is inherited from the Default permissions tab
    No accessNo access to macros
    Full accessFull access to macros
  8. Click the Apply button to save the changes.

A new role is created.

Copying a role

You can copy a role. To do this, do the following:

  1. Click the name of the role that you want to copy.
  2. Click the Create button.

A new role is created with the same parameters as the selected role.

Note

To create an empty user role with no parameters specified, select the Roles common group, and click the Create button.

Removing a role

To remove a role, do the following:

  1. Select the role that you want to remove.

  2. Click the Remove  button.


    Note

    You cannot delete a role if the user who is logged in belongs to that role.

  3. Click the Apply button.

The role is removed. All users who belong to this role are also removed.

  • No labels