Documentation for Axxon One 3.0/3.1 version. Documentation for Axxon One 2.0 version is also available.


On the page:


General information

A role is intended for assigning a group of users individual rights and permissions for administration, management, and/or monitoring of individual components of Axxon One.

Create a role

To create a new role:

  1. At the end of the list of system roles, click the Create link. The new role is added to the system, with its properties displayed on the right.
  2. Configure the access permissions:

    ParametersAccess levelDescription
    Basic
    NameoperatorEnter the name of the role
    Map control
    Select the access level to the maps for users with this role
    Map control


    No accessUsers cannot view the map
    View onlyUsers can only view the map
    View/move/scaleUsers can view, move, and change the scale of the map
    Full accessAll operations with the map are available

    Other

    Archive depth viewing restriction (hours)0If you need to limit the access of users of this role to all system archives, you can specify the archive depth limit in hours. If no limit is set, users can view all videos in the archive
    Access to Functions 
    Configure access permissions to the Axxon One fucntions
    Access to confidential bookmarksYesAdd and view confidential bookmarks
    No

    Access to Search in archive mode 

    Yes

    Search in archive (see Search in archive)

    No
    Adding camera to layout in monitoring modeYes 

    Add a camera to a layout in the live mode (see Configuration of layouts)

    No
    Adding/editing presetsYes

    Add and edit presets for PTZ cameras (see Selecting a preset)

    No
    Alarms processing

    Alarm management (see Video surveillance in the Alarm management mode)

    No accessUsers have no access to alarm events
    View onlyUsers can view alarm events, but they can't assess them
    Full accessUsers can view alarm events and assess them
    Allow deleting records
    Yes

    Remove videos from the archive (see Deleting archive fragment)

     

    No
    Allow unprotected exportYes

    Export frames and videos without password protection. If No, it is necessary to set a password when exporting (see Export)

    No
    Bookmarks processing


    No access

    Users can view and export bookmarks

    Create

    Users can create a bookmark without protection and export it. When editing, you can view and add cameras to the bookmark

    Create/Protect

    Users can create a bookmark with or without protection and export it. When editing, you can view and add cameras to the bookmark. You cannot add or remove protection while editing a bookmark

    Create/Protect/Edit and delete

    Users have all options, including bookmark deletion

    Display user login watermark
    Username

    Protection of a video by overlaying watermarks with a unique identifier on top of it (username)

    Full access
    ExportYes

    Export frames and videos (see Export)

    No
    Layouts editingYes

    Edit layouts (see Configuration of layouts)

    No
    Minimize to taskbarYes

    Minimize the Axxon One client (see Interface of Axxon One)

    No
    Operating domainYes

    Management of a domain (see Operations with domains)

    No
    Permission to access via WebUIYes

    Access to the web server (see Working with Axxon One through the Web client)

    No
    Show titles
    Yes

    Title display (see Viewing titles from POS terminals)

     

    No
    System logYes

    View the system log (see System log)

    No
    Unlock camera menu buttonYes

    Context menu of a camera (see Context menu of the surveillance window)

    No
    View masked videoYes

    Display of the masked video (see Configuring privacy masking in archive, People masking)

    No
    Access to Operator panels
    Group tabYes
    Configure access permissions to camera groups in the Hardware tab and to camera groups in the Layouts interface
     
     No
    Layouts tabYes
    Configure access permissions to the Axxon One Layouts interface (see Configuration of layouts). This parameter refers to the Axxon One client and to the web client (see Web-Client GUI)
     No
    Access to Settings
    Allow password change by user (starting with Axxon One 3.2) 
    Yes

    Allow or prohibit the user with this role to change the password. The default value is Yes. To prevent the user from changing the password, select the No value 

     
    No
    Archive settingsYes
    • Configure the access permissions to the Settings tabs

    Attention!

      • If you select the Device access rights only value in the User Permission settings parameter, all users of the given role will have the permissions to change only the access permissions to the connected devices.
      • If the Programming setup isn't available for the user role, the user cannot use the created macros on the Programming tab until the appropriate permissions are granted.
    • Configure the access permissions to the system error messages

    Attention!

      • System error messages are displayed in real-time in the Layouts interface.

      • Critical error messages in the system are displayed regardless of the Show error messages parameter.
      • Critical errors include:
        • Geomap connection error.
        • Export error.
        • Domain disconnection error.
        • Insufficient network bandwidth error that is disabled by default. If necessary, you can enable it by adding the SHOW_INSUFFICIENT_BANDWIDTH_WARNING system variable with the TRUE value (see Creating system variable).
    No
    Client special options settings
    Yes
    No
    Detector settingsYes
    No
    Device settingsYes
    No
    Domain options settingsYes
    No
    Programming setupYes
    No
    Show error messagesYes
    No
    User Permission settingsYes
    Device access rights
    No
    Additional
    Comment

    Enter additional information about the user, if necessary

    Personal data settings

    Face recognition

     

    Full access

    The value is set by default. The user has full access to the face recognition functionality

    No access

    If the No access value is set, the user has no access to the:

    • Face search in the archive (see Search in archive).
    • Alert panel (see Alert panel) that won't display videos of alarm events that are associated with faces.
    • Events search (see Events search) that won't display event notifications when faces are detected.
    • Macros that won't display face settings (see Programming)

    License plate recognition

     

    Full access

    The value is set by default. The user has full access to the license plate recognition functionality

    No access

    If the No access value is set, the user has no access to the:

    • License plate search in the archive (see Search in archive).
    • Alert panel (see Alert panel) that won't display videos of alarm events that are associated with license plates.
    • Events search (see Events search) that won't display event notifications when license plates are detected.
    • Macros that won't display license plate settings (see Programming)

    Similarity search

     

    Full access

    The value is set by default. The user has full access to the similarity search functionality

    No access

    If the No access value is set, the user has no access to the:

    • Similarity search in the archive (see Search in archive).
    • Alert panel (see Alert panel) that won't display videos of alarm events that are associated with the similarity search.
    • Events search (see Events search) that won't display event notifications when a similarity is detected.
    • Macros that won't display similarity search settings (see Programming)

    Vehicle recognition


     

    Full access

    The value is set by default. The user has full access to the vehicle recognition functionality

    No access

    If the No access value is set, the user has no access to the:

    • Vehicle search in the archive (see Search in archive).
    • Alert panel (see Alert panel) that won't display videos of alarm events that are associated with vehicles.
    • Events search (see Events search) that won't display event notifications when vehicles are detected.
    • Macros that won't display vehicle settings (see Programming)
    Supervisor confirmation
    Supervisor for access to export
    admin
    • If the administrator has to confirm the launch of export for users of this role (see Export), select the corresponding role in the list
    • If the administrator has to confirm the login of users of this role (see Start the client), select the corresponding role in the list

    Attention!

    • If a user belongs to several roles and each of these roles has its own supervisor, the user can receive confirmation to access export or authorization from a single administrator.

      Note

      For example, a user can belong to several roles at the same time: Operator 1, Operator 2, Operator 3.
      Each of these roles has its own supervisor:

      • For Operator 1, the supervisor is Admin 1.
      • For Operator 2, the supervisor is Admin 2.
      • For Operator 3, the supervisor is Admin 3.

      The user needs to receive confirmation from only one of the three administrators.

    • If a user belongs to a regular role (such as Operator) and an administrator role at the same time, supervisor confirmation isn't required, provided that the administrator role can be used as supervisor.

      Note

      For example, a user belongs to the Operator 1 and Admin 1 roles at the same time. If Admin 1 is selected as supervisor in the Supervisor confirmation settings, the user doesn't need to receive confirmation to access export or authorization.

    operator
    Supervisor for authorization in client
    admin
    operator
     
    Time zone management
    Time zone

    If you need to grant the users in this role permissions only for a certain period of time, select a time zone from the list. These users won't be able to use their permissions outside of the selected time zone

    Videowall and monitors management
    TEST

    Inherited(No)

    Configure the permissions to manage the connected clients' monitors by setting permissions for each server on the domain. A user who has management permissions for the monitors of a particular server can manage monitors of any client connected to that server

    No
    Yes
  3. On the Groups tab, configure the Default permissions (see Types of permissions to access hardware, archives and macros).

    Note

    When you create a new role, you cannot go to another tab until the role is saved. If you change any access permissions on any tab, you cannot go to another tab until the settings are saved.

    Device

    Access level

    Description

    Default permissionsConfigure the default permissions to devices

    Camera access

    No access

    No access to the device

    Archive only

    User can view only the archive

    Live in Armed mode

    User can view video from the camera only when the camera is armed

    Live

    User can view live video from the camera. Other functions and device configuration aren't available

    Live/Archive

    User can view live and recorded video from the camera. User cannot arm/disarm/configure the camera

    Live/Archive/Control

    All functions are available. User cannot configure the device

    Live/Archive/Control/Configure

    All functions and device configuration are available

    Microphone access

    No access

    User cannot listen to live audio:

    • From the camera
    • In the archive.

    Audio recording to an exported file isn't available

    Live Audio

    User can listen to live audio from the camera (the microphone must be turned on). User cannot listen to audio in the archive

    Live Audio and Archive

    All functions are available

    PTZ priority

    No access

    User cannot control the PTZ device

    Maximum level

    User can control the PTZ device with the corresponding priority (see Controlling a PTZ сamera)

    High level
    Medium level
    Low level
    Minimum level
  4. If necessary, configure the access permissions to a specific device on the Devices tab.
    To do this, select the access level for a specific device (see Types of permissions to access hardware, archives and macros). 

    Access levelDeviceAccess level to device
    Inherited

    CameraAccess levels are inherited from the Default permissions tab Groups or from the group permissions
    MicrophoneAccess levels are inherited from the Default permissions tab Groups
    PTZ
    No access

    CameraNo access to device

    Microphone
    PTZ
    Archive only

    CameraArchive only
    MicrophoneLive audio and archive
    PTZMedium level
    Live in Armed mode

    CameraView in armed mode
    MicrophoneLive audio
    PTZMedium level
    Live

    CameraView live video
    MicrophoneLive audio
    PTZMedium level
    Live/Archive

    CameraView live video and archive
    MicrophoneLive audio and archive
    PTZMedium level
    Live/Archive/Control

    CameraAll functions, configuration isn't available
    MicrophoneLive audio and archive
    PTZMedium level
    Live/Archive/Control/ConfigureCameraAll functions, configuration is available
    MicrophoneLive audio and archive
    PTZMaximum level

    You can specify the access level to a specific camera and extend it to other cameras. To do this, do the following:

    1. Select the access level to a camera from a drop-down list on the Devices tab.
    2. Click the button and select the cameras for which you want to set the same access level.

    3. Click the Apply button.

    As a result, the specified access level is extended to the selected cameras.
    To quickly select multiple cameras, press the Shift key, select the first and last cameras for which you want to set the same access level. The checkbox is set for all selected cameras when you select any of them.

    Note

    Similarly, you can extend the access levels to microphones, PTZ devices, and archives.

  5. Configure the Default permissions to domain archives or Archive permissions to a specific archive in the Archives section.

    DeviceAccess levelDescription
    Default permissionsConfigure the default access permissions to the archive (see Types of permissions to access hardware, archives and macros)
    Archive accessNo accessNo access to this archive
    Full accessFull access to the archive
    Archive permissionsConfigure the permissions to a specific archive (see Types of permissions to access hardware, archives and macros)
    Archive 

    Inherited (full access)Access level is inherited from the Default permissions tab
    No accessNo access to this archive
    Full accessFull access to the archive
     
  6. Configure the Default permissions to macros or Macro permissions to a specific macro in the Macros section.

    Attention!

    Users outside the admin role can create macros if they have the permissions to create them. They cannot use them until they have the permissions to use them.

    Macro typeAccess levelDescription
    Default permissionsConfigure the default permissions to macros (see Types of permissions to access hardware, archives and macros)
    Macro accessNo accessNo access to macros
    Full accessFull access to macros
    Macro permissionsConfigure the access permissions to a specific macro (see Types of permissions to access hardware, archives and macros)

    Automatic rules

    InheritedAccess level is inherited from the Default permissions tab
    No accessNo access to macros
    Full accessFull access to macros
    Event rulesInheritedAccess level is inherited from the Default permissions tab
    No accessNo access to macros
    Full accessFull access to macros
  7. Click the Apply button to save the changes. Click the Cancel button to cancel the changes.

A new role is created.

Copy a role

You can copy a role. To do this, do the following:

  1. Select the name of the role that you want to copy.
  2. Click the Create button.

A new role is created with the same parameters as the selected role.

Note

To create an empty role with no parameters specified, select the Roles common group, and click the Create button.

Remove a role

To remove a role, do the following:

  1. Select the role that you want to remove.

  2. Click the Remove  button.


    Note

    You cannot delete a role if the user who is logged in belongs to that role.

  3. Click the Apply button.

The role is removed. All users who belong to this role are also removed.


  • No labels