A role is intended for assigning a group of users individual rights and permissions for administration, management and/or monitoring of individual components of Axxon One.
To create a new role, do the following:
At the end of the list of system roles, click the Create link. The new role will be added to the system, with its properties displayed on the right side.
Configure the access permissions.
Parameters
Access level
Description
Basic
Name
−
Enter a name for the role (1)
Map control
Select the access level to the maps for users with the current role (2)
Map management
No access
Users cannot view maps
View only
Users can only view maps
View/move/scale
Users can views, move, and scale maps
Full access
All operations with map are available
Other
Archive depth viewing restriction
−
If you need to limit the access of users of a given role to all system archives, you can specify the archive depth limit in hours (3). If no limit is set, users may view all video recordings
Add comments to the archive, create protected records
Create/Protect/ Edit and delete
Add comments to the archive, create and edit protected records
Allow to delete records
Yes
Remove video recordings from the archive (see 아카이브 파일 일부 삭제)
No
Allow unprotected export
Yes
Export frames and video recordings without password protection (see 프레임 내보내기, 표준 비디오 녹화 내보내기). Set No to require setting a password when exporting (see 프레임 및 비디오 내보내기)
Configure the access permissions to the interfaces (5)
Group panels
Yes
Configure the access permissions to video camera groups in the Hardware tab and to the video camera groups in the Layouts interface
No
Layouts tab
Yes
Configure the access permissions to the Layouts tab. This parameter applies to both the Client and the Web-Client (see 웹 클라이언트 GUI)
No
Objects panel and Camera search panel
Yes
Configure the access permissions to the Objects panel (see 객체 패널) and the Camera search panel (see 카메라 검색 패널)
No
Access to Settings
Archive settings
Yes
Configure the access permissions to the Settings tabs and to the system error messages (6).
Attention!
Error messages are displayed in real-time in the Layouts interface.
If you set the User Permission settings parameter to Device access rights only, all users of the given role will have the rights to change only the access rights to the connected devices.
If the Programming setup is not available for the user role, the user will not be able to use the created macros until the appropriate rights are granted.
Critical error messages in the system, such as "Insufficient network bandwidth", are displayed regardless of the Show error messages setting.
No
Detection settings
Yes
No
Device settings
Yes
No
Options settings
Yes
No
Programming settings
Yes
No
Show error messages
Yes
No
User Permission settings
Yes
No
Additional
Comment
−
Specify additional information about the user, if necessary (7). If no value is specified, users can view all videos
Supervisor confirmation
Set the parameters to apply the four-eye principle (8)
Supervisor for acccess to export
−
If the administrator has to confirm the launch of export for users of this role (see 프레임 및 비디오 내보내기), select the corresponding role in the list
Supervisor for authorization in client
−
If the administrator has to confirm the login of users of this role (see Axxon One 클라이언트 시작), select the corresponding role in the list
Time schedule management
Time schedule
−
If you need to grant the users in this role permissions only for a certain period of time, select a time schedule (9) from the list. These users will not be able to use their permissions outside of the selected time schedule
Video walls management
Server
Yes
Configure the rights to manage the connected Clients' monitors by setting permissions for each Server on Axxon domain (10). A user who has management permissions for the monitors of a particular Server can manage monitors of any Client connected to that Server
No
On the Groups tab, configure the default permissions (11, see사용자 권한 설정).
Note
When you create a new role, you cannot go to another tab until the role is saved. If you change any access permissions on any tab, you cannot go to another tab until the settings are saved.
Device
Access level
Description
Default permissions
Configure the default permissions to devices
Camera access
No access
No access to the device
Archive only
User can view only the archive
Live in Armed mode
User can view video from the camera only when the camera is armed
Live
User can view live video from the camera. Other functions and device configuration are not available
Live/Archive
User can view live and recorded video from the camera. User cannot arm/disarm/configure the camera
Live/Archive/Control
All functions available. User cannot configure the device
Live/Archive/Control/Configure
All functions and device configuration available
Microphone access
No access
User cannot listen to live audio from the camera. User cannot listen to audio in the archive. Audio recording to an exported file is not available
Live Audio
User can listen to live audio from the camera (the microphone must be turned on). User cannot listen to audio in the archive
Live Audio and Archive
All functions are available
PTZ priority
No access
User cannot control the PTZ device
Minimum level
User can control the PTZ device with the corresponding priority (see PTZ 카메라 제어)
Low level
Medium level
High level
Maximum level
On the Groups tab, configure the group permissions if there are camera groups (12, see 비디오 카메라 그룹 구성).
Device
Access level
Description
Misc
Configure group access permissions to cameras (see 사용자 권한 설정)
Camera group
Inherited
Access permissions are inherited from the "Default permissions" tab Camera access (see the previous step)
No access
No access to the device
Archive only
User can view only the archive
Live in Armed mode
User can view video from the camera only when the camera is armed
Live
User can view live video from the camera. Other functions and device configuration are not available
Live/Archive
User can view live and recorded video from the camera. User cannot arm/disarm/configure the camera
Live/Archive/Control
All functions available. User cannot configure the device
Live/Archive/Control/Configure
All functions and device configuration available
If necessary, configure the access permissions to a specific device (the Devices tab, 13). To do this, select the access level for the individual device (see 사용자 권한 설정).
Access level
Device
Access level to device
Inherited
Camera
Access levels are inherited from the Groups tab "Default permissions" or from the group permissions
Microphone
Access levels are inherited from the Groups tab "Default permissions"
PTZ
Archive only
Camera
Archive only
Microphone
Live audio and archive
PTZ
Medium level
Live in Armed mode
Camera
View in armed mode
Microphone
Live audio
PTZ
Medium level
Live
Camera
View live video
Microphone
Live audio
PTZ
Medium level
Live/Archive
Camera
View live video and archive
Microphone
Live audio and archive
PTZ
Medium level
Live/Archive/Control
Camera
All functions, configuration isn't available
Microphone
Live audio and archive
PTZ
Medium level
Live/Archive/Control/Configure
Camera
All functions, configuration is available
Microphone
Live audio and archive
PTZ
Maximum level
You can specify the access level to an individual camera and extend it to other cameras. To do it, do the following:
Select the access level to a camera from a drop-down list on the Devices tab.
Click the button and select the cameras to which you want to specify the same access level.
Click the Apply button. As a result, the the specified access level will be extended to the selected cameras. To quickly select multiple cameras, hold down the Shift key, select the first and last camera to which you want to specify the same access level. The checkbox will set for all selected cameras when you select any of them.
Note
Similarly, you can extend the access levels to microphones, PTZ devices and archives.
Configure the access permissions to domain archives. You can set the permissions to all archives (14) or to a specific archive (15).
Device
Access level
Description
Default permissions
Configure the default access permissions to the archive (see 사용자 권한 설정)
Archive access
No access
No access to this archive
Full access
Full access to the archive
Archive permissions
Configure the permissions to a specific archive (see 사용자 권한 설정)
Archive
Inherited
Access level is inherited from the Default permissions tab
No access
No access to this archive
Full access
Full access to the archive
Set the possibility to manually run all or some macros (see매크로 설정) from theLayoutsinterface by selecting the corresponding access level.
Attention!
Users outside the admin group can create macros, if they have the permissions to create them. They cannot use them until they have the permissions to use them.
Macro type
Access level
Description
Default permissions
Configure the default permissions to macros (16, see 사용자 권한 설정)
Macro access
No access
No access to macros
Full access
Full access to macros
Macro permissions
Configure the access permissions to a specific macro (17, see 사용자 권한 설정)
Automatic rules
Inherited
Access level is inherited from the Default permissions tab
No access
No access to macros
Full access
Full access to macros
Event rules
Inherited
Access level is inherited from the Default permissions tab
No access
No access to macros
Full access
Full access to macros
Cycle rules
Inherited
Access level is inherited from the Default permissions tab
No access
No access to macros
Full access
Full access to macros
Click the Apply button to save the role.
The new role has been created.
You can copy a role. To do it, do the following:
Select the role to copy.
Click the Create button.
A new role will be created with the same parameters as the selected role.
Note
To create an empty user role with no parameters specified, select the Roles common group, and click the Create button.
To delete a role, do the following:
Select the role to delete.
Click the Delete button.
Note
You cannot delete a role if the user who is logged in belongs to that role.
Click the Apply button to save the changes.
The role has been deleted. All users who belong to this role will also be deleted.