On the page:


General information

A role is intended for assigning a group of users individual rights and permissions for administration, management and/or monitoring of individual components of Axxon One.

Creating a role

To create a new role, do the following:

  1. At the end of the list of system roles, click the Create link. The new role is added to the system, with its properties displayed on the right side.
  2. Configure the access permissions:

    ParametersAccess levelDescription
    Basic
    NameoperatorSpecify a name of the role
    Map control
    Map controlNo accessSelect the access level to the maps for users with this role

    Other

    Archive depth viewing restriction (hours)0If you need to limit the access of users of this role to all system archives, you can specify the archive depth limit in hours. If no limit is set, users can view all videos
    Access to Functions 
    Configure access permissions to the Axxon One fucntions
    Access to confidential bookmarksYesAdd and view confidential bookmarks
    No

    Access to Search in archive mode 

    Yes

    Archive search (see Video surveillance in the Archive Search mode)

    No
    Adding camera to layout in monitoring modeYes 

    Add a camera to a layout in the Live mode (see Adding cameras to cells)

    No
    Adding/editing presetsYes

    Add and edit presets for PTZ cameras (see Selecting a preset)

    No
    Alarms processing

    Alarms management (see Video surveillance in the Alarm management mode)

    No accessUsers have no access to alarm events
    View onlyUsers can view alarm events, but they can't assess them
    Full accessUsers can view alarm events and assess them
    Allow deleting records
    Yes

    Remove videos from the archive (see Deleting a part of archive)

     

    No
    Allow unprotected exportYes

    Export frames and videos without password protection (see Frame export, Standard video recordings export). If No, it is necessary to set a password when exporting (see Exporting frames and video recordings)

    No
    Bookmarks processing


    No access

    Users can view and export bookmarks

    Create

    Users can create a bookmark without protection and export it. When editing, you can view and add cameras to the bookmark

    Create/Protect

    Users can create a bookmark with or without protection and export it. When editing, you can view and add cameras to the bookmark. You cannot add or remove protection while editing a bookmark

    Create/Protect/Edit and delete

    Users have all options, including bookmark deletion

    Display user login watermark
    User login

    The option of protection a video by overlaying watermarks with a unique identifier on top of it

     

    Full access
    ExportYes

    Export frames and videos (see Exporting frames and video recordings)

    No
    Layouts editingYes

    Edit layouts (see Editing layouts)

    No
    Minimize to taskbarYes

    Minimize the client of Axxon One (see Interface of Axxon One)

    No
    Operating domainYes

    Managing a domain (see Operations with domains)

    No
    Permission to access via WebUIYes

    Access to the Web-Server (see Working with Axxon One through the Web client)

    No
    Show facesYes

    Showing faces (see Masking faces)

    No
    Show titles
    Yes

    Showing titles (see Viewing titles from POS terminals)

     

    No
    System logYes

    Viewing the system log (see System log)

    No
    Unlock camera menu buttonYes

    Context menu of a camera (see Context Menu of the Surveillance window)

    No
    View masked videoYes

    Showing masked video (see Configuring privacy masking in archive, People masking)

    No
    Access to Settings
    Archive settingsYes
    • Configure the access permissions to the Settings tabs

    Attention!

      • If you select the Device access rights only value in the User Permission settings parameter, all users of the given role will have the permissions to change only the access permissions to the connected devices.
      • If the Programming setup isn't available for the user role, the user cannot use the created macros on the Programming tab until the appropriate permissions are granted.
    • Configure the access permissions to the system error messages

    Attention!

      • System error messages are displayed in real-time in the Layouts interface.

      • Critical error messages in the system are displayed regardless of the Show error messages parameter.
      • Critical errors include:
        • geomap connection error;
        • export error;
        • domain disconnection error;
        • insufficient network bandwidth error that is disabled by default. If necessary, you can enable it by adding the SHOW_INSUFFICIENT_BANDWIDTH_WARNING system variable with the TRUE value (see Appendix 9. Creating system variable).
    No
    Client special options settings
    Yes
    No
    Detection settingsYes
    No
    Device settingsYes
    No
    Domain options settingsYes
    No
    Programming setupYes
    No
    Show error messagesYes
    No
    User Permission settingsYes
    Device access rights
    No
    Access to Tabs
    Configure access permissions to interfaces
    Group panels
     
    Yes
    Configure access permissions to camera groups in the Hardware tab and to camera groups in the Layouts interface
     
    No
    Layouts tab
     
    Yes
    Configure access permissions to the Axxon One Layouts interface. This parameter refers to the Axxon One client and to the Web-Client (see Web-Client configuration)
     
    No
    Objects panel and Camera search panel
    Yes
    Configure access permissions to the object panel (see Object panel) and camera search panel (see Camera Search Panel).
     
    No
    Additional
    Comment

    Specify additional information about the user, if necessary

    Personal data settings

    Face recognition

     

    Full access

    The value is set by default. The user has full access to the face recognition functionality

    No access

    If the No access value is set, the user has no access to the:

    • face search in the archive (see Search in archive);
    • alert panel (see Alert panel) that won't display videos of alarm events that are associated with faces;
    • events search (see Events search) that won't display event notifications when faces are detected;
    • macros that won't display face settings (see Programming)

    License plate recognition

     

    Full access

    The value is set by default. The user has full access to the license plate recognition functionality

    No access

    If the No access value is set, the user has no access to the:

    • license plates search in the archive (see Search in archive);
    • alert panel (see Alert panel) that won't display videos of alarm events that are associated with license plates;
    • events search (see Events search) that won't display event notifications when license plates are detected;
    • macros that won't display license plates settings (see Programming)

    Similitude search

     

    Full access

    The value is set by default. The user has full access to the similitude search functionality

    No access

    If the No access value is set, the user has no access to the:

    • similitude search in the archive (see Search in archive);
    • alert panel (see Alert panel) that won't display videos of alarm events that are associated with similitude search;
    • events search (see Events search) that won't display event notifications when a similitude search is detected;
    • macros that won't display similitude search settings (see Programming)

    Vehicle recognition


     

    Full access

    The value is set by default. The user has full access to the vehicle recognition functionality

    No access

    If the No access value is set, the user has no access to the:

    • vehicle search in the archive (see Search in archive);
    • alert panel (see Alert panel) that won't display videos of alarm events that are associated with vehicles;
    • events search (see Events search) that won't display event notifications when vehicles are detected;
    • macros that won't display vehicle settings (see Programming)
    Supervisor confirmation
    Supervisor for acccess to export
    • If the administrator has to confirm the launch of export for users of this role (see Exporting frames and video recordings), select the corresponding role in the list
    • If the administrator has to confirm the login of users of this role (see Starting the client), select the corresponding role in the list

    Attention!

    • If a user belongs to several roles and each of these roles has its own supervisor, the user can receive confirmation to access export or authorization from a single administrator.

      Note

      For example, a user can belong to several roles at the same time: Operator 1, Operator 2, Operator 3.
      Each of these roles has its own supervisor:

      • For Operator 1, the supervisor is Admin 1.
      • For Operator 2, the supervisor is Admin 2.
      • For Operator 3, the supervisor is Admin 3.

      The user needs to receive confirmation from only one of the three administrators.

    • If a user belongs to a regular role (such as Operator) and an administrator role at the same time, supervisor confirmation isn't required, provided that the administrator role can be used as supervisor.

      Note

      For example, a user belongs to the Operator 1 and Admin 1 roles at the same time. If Admin 1 is selected as supervisor in the Supervisor confirmation settings, the user doesn't need to receive confirmation to access export or authorization.

    Supervisor for authorization in Client
    Time schedule management
    Time schedule

    If you need to grant the users in this role permissions only for a certain period of time, select a time schedule from the list. These users willn't be able to use their permissions outside of the selected time schedule

    Video walls management
    TESTInherited(No)

    Configure the permissions to manage the connected clients' monitors by setting permissions for each server on domain. A user who has management permissions for the monitors of a particular server can manage monitors of any client connected to that server

  3. On the Groups tab, configure the Default permissions (see Types of permissions to access hardware, archives and macros).

    Note

    When you create a new role, you cannot go to another tab until the role is saved. If you change any access permissions on any tab, you cannot go to another tab until the settings are saved.

    Device

    Access level

    Description

    Default permissionsConfigure the default permissions to devices

    Camera access

    No access

    No access to the device

    Archive only

    User can view only the archive

    Live in Armed mode

    User can view video from the camera only when the camera is armed

    Live

    User can view live video from the camera. Other functions and device configuration aren't available

    Live/Archive

    User can view live and recorded video from the camera. User cannot arm/disarm/configure the camera

    Live/Archive/Control

    All functions available. User cannot configure the device

    Live/Archive/Control/Configure

    All functions and device configuration available

    Microphone access

    No access

    User cannot listen to live audio:

    • from the camera;
    • in the archive.

    Audio recording to an exported file isn't available

    Live Audio

    User can listen to live audio from the camera (the microphone must be turned on). User cannot listen to audio in the archive

    Live Audio and Archive

    All functions are available

    PTZ priority

    No access

    User cannot control the PTZ device

    Maximum level

    User can control the PTZ device with the corresponding priority (see Controlling a PTZ сamera)

    High level
    Medium level
    Low level
    Minimum level
  4. If necessary, configure the access permissions to a specific device on the Devices tab.
    To do this, select the access level for a specific device (see Types of permissions to access hardware, archives and macros). 

    Access levelDeviceAccess level to device
    Inherited

    CameraAccess levels are inherited from the Default permissions tab Groups or from the group permissions
    MicrophoneAccess levels are inherited from the Default permissions tab Groups
    PTZ
    No access

    CameraNo access to device

    Microphone
    PTZ
    Archive only

    CameraArchive only
    MicrophoneLive audio and archive
    PTZMedium level
    Live in Armed mode

    CameraView in armed mode
    MicrophoneLive audio
    PTZMedium level
    Live

    CameraView live video
    MicrophoneLive audio
    PTZMedium level
    Live/Archive

    CameraView live video and archive
    MicrophoneLive audio and archive
    PTZMedium level
    Live/Archive/Control

    CameraAll functions, configuration isn't available
    MicrophoneLive audio and archive
    PTZMedium level
    Live/Archive/Control/ConfigureCameraAll functions, configuration is available
    MicrophoneLive audio and archive
    PTZMaximum level

    You can specify the access level to a specific camera and extend it to other cameras. To do this, do the following:

    1. Select the access level to a camera from a drop-down list on the Devices tab.
    2. Click the button and select the cameras, to which you want to specify the same access level.

    3. Click the Apply button.

    As a result, the specified access level is extended to the selected cameras.
    To quickly select multiple cameras, press down the Shift key, select the first and last camera, to which you want to specify the same access level. The checkbox is set for all selected cameras when you select any of them.

    Note

    Similarly, you can extend the access levels to microphones, PTZ devices and archives.

  5. Configure the Default permissions to domain archives or Archive permissions to a specific archive in the Archives section.

    DeviceAccess levelDescription
    Default permissionsConfigure the default access permissions to the archive (see Types of permissions to access hardware, archives and macros)
    Archive accessNo accessNo access to this archive
    Full accessFull access to the archive
    Archive permissionsConfigure the permissions to a specific archive (see Types of permissions to access hardware, archives and macros)
    Archive 

    Inherited (full access)Access level is inherited from the Default permissions tab
    No accessNo access to this archive
    Full accessFull access to the archive
     
  6. Configure the Default permissions to macros or Macro permissions to a specific macro in the Macros section.

    Attention!

    Users outside the admin role can create macros, if they have the permissions to create them. They cannot use them until they have the permissions to use them.

    Macro typeAccess levelDescription
    Default permissionsConfigure the default permissions to macros (see Types of permissions to access hardware, archives and macros)
    Macro accessNo accessNo access to macros
    Full accessFull access to macros
    Macro permissionsConfigure the access permissions to a specific macro (see Types of permissions to access hardware, archives and macros)

    Automatic rules

    InheritedAccess level is inherited from the Default permissions tab
    No accessNo access to macros
    Full accessFull access to macros
    Event rulesInheritedAccess level is inherited from the Default permissions tab
    No accessNo access to macros
    Full accessFull access to macros
  7. Click the Apply button to save the changes.

A new role is created.

Copying a role

You can copy a role. To do this, do the following:

  1. Click the name of the role that you want to copy.
  2. Click the Create button.

A new role is created with the same parameters as the selected role.

Note

To create an empty role with no parameters specified, select the Roles common group, and click the Create button.

Removing a role

To remove a role, do the following:

  1. Select the role that you want to remove.

  2. Click the Remove  button.


    Note

    You cannot delete a role if the user who is logged in belongs to that role.

  3. Click the Apply button.

The role is removed. All users who belong to this role are also removed.

  • No labels