Go to documentation repository
Page History
Section | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
General information
A role is intended for assigning a group of users individual rights and permissions for administration, management and/or monitoring of individual components of Axxon One.
Creating a role
To create a new role, do the following:
- At the end of the list of system roles, click the Create link. The new role will be
- is added to the system, with its properties displayed on the right side.
Configure the access permissions:
Parameters Access level Description Basic Name − Enter a name for the role in the corresponding field (1).Map control Select the access level to the maps for users with the current role this role Map management No access Users cannot view maps (2). View only You Users can only view maps View/move/scale You Users can views, move, and scale maps Full access All options availableoperations with map are available Other
Archive depth viewing restriction − If you need to limit the access of users of a given this role to all system archives, you can specify the archive depth limit in hours in the Archive depth viewing restriction field (3). If no limit is set, users may access the entire video footage.can view all videos Access to Functions Set access permissions for Axxon One features (4). Access can be restricted to such features as:to Axxon One functions Access to confidential comments Yes Add and view confidential comments No Access to Search in archive mode
Yes Archive search
Archive search - .
No Adding camera to layout in monitoring mode Yes Add a camera to a layout in
live video the Live mode (
see - .
No Adding and editing /editing presets Yes Add and edit presets for PTZ cameras (see
Creating and editing presets).No Alarms processing − Alarms management
Alarms Management - Management
- .
No access −users Users have no access to alarm videos.events View only −users Users can view alarm videos events, but they can't evaluate alarms.assess them Full access − users Users can view alarm videos and evaluate alarms. Creating comments (see events and assess them Allow comments in archive − Create comments in the archive (see Operator comments) and protected records in video footage (see Protecting video footage - .
No access No comments allowed Create Add Users can add comments to the archive Create/Protect Add Users can add comments to the archive, create protected records Create/Protect/ Edit / Deleteand delete Users can add Add comments to the archive, create and edit protected records Removing Allow to delete records Yes Remove videos from the
footage archive (see
Delete - an
- .
No Allow unprotected export Yes Export frames and videos without password protection (see Frame export, Standard video recordings export). Set No to require setting a password
for exported images and video when exporting (see Exporting
Frames - Video Recordings).Exporting frames and video recordings
No Export Yes Export frames and videos (see Exporting
Frames - Video Recordings).
No Layouts editing Yes Edit
Editing layouts (see
Configuring Layouts).No Minimize to taskbar Yes Minimize the client to the
Minimizing the Client to the system tray (see Interface of
the - Software Package).Managing an
)
No Operating domain Yes Manage Axxon domain (see
Axxon Domain operations).No Permissions to access via WebUI Yes Access to the Web
server -Server (see Working with Axxon One
Through - .Displaying
No Show captions Yes Display captions (see Viewing titles from POS terminals)
.No Show faces Yes Showing faces (see Masking faces)
.No System log Yes View
Viewing the system log (see
The - Log).
log)
No Unlock camera menu button Yes Context menu of a
video camera
in a viewing tile (see Viewing Tile (see Context Menu
).No View masked video Yes View masked video (see
Setting up - Video Footage).Configure access rights to the Settings tabs and to the system error messages (5).
No Access to Interfaces Configure the access permissions to the interfaces Group panels Yes Configure the access permissions to camera groups on the Hardware tab and to the camera groups on the Layouts interface
No Layouts tab Yes Configure the access permissions to the Layouts tab. This parameter applies to both the client and the Web-Client (see Web-Client GUI)
No Objects panel and Camera search panel Yes Configure the access permissions to the Objects panel (see Objects Panel) and the Camera search panel (see Camera Search Panel)
No Access to Settings Archive settings Yes - Configure the access permissions to the Settings tabs
Note title Attention! - If you
set - select the Device access rights only value in the User Permission settings parameter
to Device access rights only- , all users of the given role will
be permitted - have the permissions to change only the access
rights - permissions to the connected devices.
info- If the Programming setup is not available for the user role, the user will not be able to use the created macros until the appropriate permissions are granted.
- Configure the access permissions to the system error messages
Note title NoteAttention! Error - System error messages are displayed in real-time in the Layouts interface.
- System error messages are displayed in real-time in the Layouts interface.
- Critical error messages in the system are displayed regardless of the Show error messages parameter.
- Critical errors include:
- geomap connection error;
- export error;
- domain disconnection error;
- insufficient network bandwidth error that is disabled by default. Ifnecessary, you can enable it by adding the SHOW_INSUFFICIENT_BANDWIDTH_WARNING system variable with the TRUE value (see Appendix 9. Creating system variable).
No Detection settings Yes No Device settings Yes No Options settings Yes No Programming setup Yes No Show error messages Yes No User Permission settings Yes Device access rights only No Additional Comment − Specify additional information about the user, if necessary
Supervisor confirmation Supervisor for acccess to export − Set access permissions for Layouts in Axxon One (6). This parameter applies to both the Client and the Web Client (see Web-Client's GUI).
Set the parameters to apply the four-eye principle (7):- If the administrator has to confirm the launch of export for users of this role (see Exporting
Frames - Video Recordings
- video recordings), select the
appropriate - corresponding role in the
Supervisor for access to export list.- list
- If the administrator has to confirm the login of users of this role (see Starting
an Axxon One Client- the client), select the corresponding role in the list
Note title Attention! - If a user belongs to several roles and each of these roles has its own supervisor, the user can receive confirmation to access export or authorization from a single administrator.
Info title Note For example, a user can belong to several roles at the same time: Operator 1, Operator 2, Operator 3.
Each of these roles has its own supervisor:- For Operator 1, the supervisor is Admin 1.
- For Operator 2, the supervisor is Admin 2.
- For Operator 3, the supervisor is Admin 3.
The user needs to receive confirmation from only one of the three administrators.
- If a user belongs to a regular role (such as Operator) and an administrator role at the same time, supervisor confirmation isn't required, provided that the administrator role can be used as supervisor.
Info title Note For example, a user belongs to the Operator 1 and Admin 1 roles at the same time. If Admin 1 is selected as supervisor in the Supervisor confirmation settings, the user doesn't need to receive confirmation to access export or authorization.
Supervisor for authorization in client list.− Time schedule management Time schedule − If you need to grant the users in this role permissions only for a certain period of time, select a
Time schedule (8) from time schedule from the list. These users will not be able to use their permissions outside of the selected time schedule
.Video walls management Server Yes Configure
rights the permissions to manage the connected
Clientsclients' monitors by setting permissions for each
Server server on
an Axxon domain
(9). A user who has management permissions for the monitors of a particular
Server server can manage monitors of any
Client client connected to that
Server.server
No On the Groups tab, configure the Default permissions (seeTypes of permissions to access hardware, archives and macros).
Info title Note When you create a new role, you cannot go to another tab until the role is saved. If you change any access permissions on any tab, you cannot go to another tab until the settings are saved
Set access permissions to hardware and archives on an Axxon domain (10).
Device
Access level
Description
Default permissions Configure the default permissions to devices Camera access
No access
You cannot No access to the device
Archive only You User can view only
view video footage in the archive
Live in Armed mode
You User can view video from the camera only when the camera is armed
Live
You User can view live video from the camera. Other functions and device configuration are not available
Live/Archive
You User can view live and recorded video from the camera.
You User cannot arm/disarm/configure the camera
Live/Archive/Control
All functions available.
You User cannot configure the device
Live/Archive/Control/Configure All functions and
settings device configuration available
Microphone access
No access
You User cannot listen to live
sound audio:
- from the
video - camera
. You cannot listen to sound recordings from the archive- ;
- in the archive.
Audio recording to an exported file is not available
Live Audio
You User can listen to live
sound audio from the
video camera (the microphone
should must be turned on).
You User cannot listen to
sound recordings from audio in the archive
Live Audio and Archive
All functions are available
PTZ priority
No access
You User cannot control the PTZ device
Minimum level
You User can control the PTZ device with the corresponding priority (see Controlling a PTZ
CameraLow level Medium level High level Maximum level ArchiveOn the Groups tab, configure the Group permissions if there are camera groups (see Configuring video camera groups).
Device
Access level
Description
Group permissions Configure group access permissions to cameras (see Types of permissions to access hardware, archives and macros) Camera group
Inherited Access permissions are inherited from the Default permissions tab → Camera access No access
No access to the device
Archive only User can view only the archive
Live in Armed mode
User can view video from the camera only when the camera is armed
Live
User can view live video from the camera. Other functions and device configuration are not available
Live/Archive
User can view live and recorded video from the camera. User cannot arm/disarm/configure the camera
Live/Archive/Control
All functions available. User cannot configure the device
Live/Archive/Control/Configure All functions and device configuration available
If necessary, configure the access permissions to a specific device on the Devices tab.
To do this, select the access level for a specific device (see Types of permissions to access hardware, archives and macros).Access level Device Access level to device Inherited Camera Access levels are inherited from the Default permissions tab →Groups or from the group permissions Microphone Access levels are inherited from the Default permissions tab → Groups PTZ Archive only Camera Archive only Microphone Live Audio audio and Archivearchive PTZ Medium level ArchiveLive in Armed Modemode Camera View in armed mode You can view armed camerasMicrophone Live Audio.audio PTZ Medium level .Live Camera View You can view live video Microphone Live Audioaudio PTZ Medium level Live/Archive Camera View live video and archive Microphone Live Audio audio and Archivearchive PTZ Medium level ArchiveLive/Archive/Control Video cameraCamera All functions . Configuration not , configuration isn't available Microphone Live Audio audio and Archivearchive PTZ Medium level Live/Archive/Control/Configure Video cameraCamera All functions + configuration , configuration is available Microphone Live Audio audio and Archivearchive PTZ Maximum level You can specify the access level to a specific camera and extend it to other cameras. To do this, do the following:
- Select the access level to a camera from a drop-down list on the Devices tab.
Click the button and select the cameras, to which you want to specify the same access level.
Click the Apply button.
As a result, the specified access level is extended to the selected cameras.
To quickly select multiple cameras, press down the Shift key, select the first and last camera, to which you want to specify the same access level. The checkboxes set for all selected cameras when you select any of them.Info title Note Similarly, you can extend the access levels to microphones, PTZ devices and archives.
Configure the Default permissions to domain archives or Archive permissions to a specific archive in the Archives section.
Device Access level Description Default permissions Configure the default access permissions to the archive (see Types of permissions to access hardware, archives and macros) Archive access No access No access to this archive Full access Full access to the archive Archive permissions Configure the permissions to a specific archive (see Types of permissions to access hardware, archives and macros) Archive Inherited Access level is inherited from the Default permissions tab No access No access to this archive Full access Full access to the archive - Configure the Default permissions to macros or Macro permissions to a specific macro in the Macros section interface (11)
- .
Note title Attention! By default, created macros are available only to users from the admin group. Users outside the admin
group can role can create macros, if they have the permissions to create them. They cannot use them until they have the permissions to use them.
Macro type Access level Description Default permissions Configure the default permissions to macros (see Types of permissions to access hardware, archives and macros) Macro access No access No access to macros Full access Full access to macros Macro permissions Configure the access permissions to a specific macro (see Types of permissions to access hardware, archives and macros) Automatic rules
Inherited Access level is inherited from the Default permissions tab No access No access to macros Full access Full access to macros Event rules Inherited Access level is inherited from the Default permissions tab No access No access to macros Full access Full access to macros Cycle rules Inherited Access level is inherited from the Default permissions tab No access No access to macros Full access Full access to macros Click the Apply
button button to save the
rolechanges.
Access level
Access level
Description
Description
You can configure group rights for accessing devices and archives of a particular Server. To do so, select an access level for the Server object. Depending on the selected level, particular access levels are automatically configured for the devices and archives of the relevant Server:
Server access level
Device/archive
Device/archive access level
Custom
-
Access levels for devices and archives are set manually
No access
-
No access to devices and archives
Video camera
Archive
No access
Video camera
Archive
Video camera
Full access
Archive
Full access
The A new role has been is created.
Copying a role
You can copy Rolesa role. To do itthis, follow do the steps belowfollowing:
- Select
- Click the name of the role that you want to copy.
- Click the Create button.
This creates a new identical A new role is created with the same parameters as the selected role.
Info | ||
---|---|---|
| ||
To create an empty user role with no parameters specified, select the Roles common group, and click the Create button. |
Removing a role
To delete remove a role, do the following:
Select the role that you want to
deleteremove.
Click the
Delete Remove button.
Info title Note You cannot delete a role if the user who is logged in belongs to that role.
- Click the Apply button to save the changes
- .
The role has been deletedis removed. All users who belong to this role will are also be deletedremoved.