Delegated administrator profiles¶
The Delegated administrator profiles module lets the administrator define, profile by profile, which delegated administrator accounts can access which console modules, with which permission level (read-only or read-write), and on which authentication domains. It is the central tool for setting up targeted administration delegation.
Profile cumulation
A delegated administrator can be associated with several profiles. In that case the higher rights of each profile are cumulated. As many profiles as needed can therefore be created, anticipating foreseeable changes, to ease administration.
Profile list¶
The main grid displays the existing profiles in a paginated view (15, 25 or 50 rows per page):
| Column | Description |
|---|---|
| Name | Profile name. |
| Delegated administrators | Counter of accounts associated with the profile. |
| Allowed modules | Counter of allowed modules. |
| Allowed domains | Counter of allowed domains. |
Expanding a row displays the profile detail: the list of delegated administrators, the modules granted Access only (regular text), those granted Modification (bold text) and the list of allowed domains.
A search field in the toolbar filters the list on the fly (triggered 700 ms after the last keystroke or immediately with the Enter key).
Add a delegated administrator profile¶
Clicking the + button opens a three-tab form preceded by two common fields:
| Field | Description |
|---|---|
| Name | Mandatory. A string made only of spaces is rejected. |
| Description | Free text. |
Two-column list (available on the left, selected on the right). Each column shows the Name and Domain fields. Selection is performed by drag and drop from one column to the other. A Select all button below each column allows bulk operations.
The form can be saved even when this list stays empty: only the Name field is mandatory.
This tab holds the access permissions to the console modules. It is displayed as a tree — one row per module — where each row exposes two checkboxes:
| Column | Description |
|---|---|
| Name | Module name as displayed in the console. Only one row can be expanded: Control Center, which exposes its two sections Live streaming and Archives. |
| Access | Opens the module to the profile and allows viewing its content. |
| Modify | Additionally allows creating, modifying and deleting items. The checkbox stays greyed out until Access is checked. |
The three Control Center rows are checked independently: checking the module does not check its sections. A permission on the module covers both sections; a permission on a single section opens the module but grants access to that section only.
The module list depends on the platform
The tree only offers the modules the platform actually exposes. Missing from it are the five ACM modules when the ACM function is not enabled, the Agents for password monitoring and Managed accounts usages modules outside the Systancia Access password vault mode, and the Workplace-related modules (VDI desktops, virtual machines, hypervisors, resource access, firewall and SSO modes) when the platform is not merged with a Workplace. The available choice therefore differs from one platform to another.
Two modules require a prior permission
These modules can only be used together with a permission on another module. Both their checkboxes are then greyed out and stay inert on click; hovering the row displays Requires one of the following permissions: followed by the list of candidates — one of them is enough to unlock the row.
| Module | Permission expected on |
|---|---|
| Comments | Control Center, or one of its Live streaming and Archives sections. |
| Cleanup platform log data | Logs. |
Implicit permission
A profile holding Modify on Logs additionally gets the Cleanup platform log data module in modify mode, without its row having to be checked.
A profile can be saved without a single checkbox checked: its delegated administrators then open the console without reaching any module.
Two-column list (available on the left, selected on the right). Selection is performed by drag and drop. A Select all button is available below each column.
The domains listed here scope the Authentication domains, User groups, Users and Blocked users modules: the profile's delegated administrators can only act on the domains present in the right-hand list.
Modules not affected by domain filtering
For the other modules (for example Access contracts), the list of allowed domains does not apply: a delegated administrator holding Modify on these modules can pick any domain when creating or editing a contract.
The tabs feature Previous and Next buttons in the footer for navigation.
Edit a delegated administrator profile¶
Select the profile in the list and click the Properties icon (or double-click the row). The form is identical to the add form and pre-filled with the profile values. Make the changes and click Validate.
Delete a delegated administrator profile¶
Select one or more profiles and click the × button. A confirmation is requested (label adapted to the singular or plural case).