Skip to content

Delegated administrator profiles

The Delegated administrator profiles module lets the administrator define, profile by profile, which delegated administrator accounts can access which console modules, with which permission level (read-only or read-write), and on which authentication domains. It is the central tool for setting up targeted administration delegation.

Profile cumulation

A delegated administrator can be associated with several profiles. In that case the higher rights of each profile are cumulated. As many profiles as needed can therefore be created, anticipating foreseeable changes, to ease administration.


Profile list

The main grid displays the existing profiles in a paginated view (15, 25 or 50 rows per page):

Column Description
Name Profile name.
Delegated administrators Counter of accounts associated with the profile.
Allowed modules Counter of allowed modules.
Allowed domains Counter of allowed domains.

Expanding a row displays the profile detail: the list of delegated administrators, the modules granted Access only (regular text), those granted Modification (bold text) and the list of allowed domains.

A search field in the toolbar filters the list on the fly (triggered 700 ms after the last keystroke or immediately with the Enter key).


Add a delegated administrator profile

Clicking the + button opens a three-tab form preceded by two common fields:

Field Description
Name Mandatory. A string made only of spaces is rejected.
Description Free text.

Two-column list (available on the left, selected on the right). Each column shows the Name and Domain fields. Selection is performed by drag and drop from one column to the other. A Select all button below each column allows bulk operations.

The form can be saved even when this list stays empty: only the Name field is mandatory.

This tab holds the access permissions to the console modules. It is displayed as a tree — one row per module — where each row exposes two checkboxes:

Column Description
Name Module name as displayed in the console. Only one row can be expanded: Control Center, which exposes its two sections Live streaming and Archives.
Access Opens the module to the profile and allows viewing its content.
Modify Additionally allows creating, modifying and deleting items. The checkbox stays greyed out until Access is checked.

The three Control Center rows are checked independently: checking the module does not check its sections. A permission on the module covers both sections; a permission on a single section opens the module but grants access to that section only.

The module list depends on the platform

The tree only offers the modules the platform actually exposes. Missing from it are the five ACM modules when the ACM function is not enabled, the Agents for password monitoring and Managed accounts usages modules outside the Systancia Access password vault mode, and the Workplace-related modules (VDI desktops, virtual machines, hypervisors, resource access, firewall and SSO modes) when the platform is not merged with a Workplace. The available choice therefore differs from one platform to another.

Two modules require a prior permission

These modules can only be used together with a permission on another module. Both their checkboxes are then greyed out and stay inert on click; hovering the row displays Requires one of the following permissions: followed by the list of candidates — one of them is enough to unlock the row.

Module Permission expected on
Comments Control Center, or one of its Live streaming and Archives sections.
Cleanup platform log data Logs.

Implicit permission

A profile holding Modify on Logs additionally gets the Cleanup platform log data module in modify mode, without its row having to be checked.

A profile can be saved without a single checkbox checked: its delegated administrators then open the console without reaching any module.

Two-column list (available on the left, selected on the right). Selection is performed by drag and drop. A Select all button is available below each column.

The domains listed here scope the Identity Providers, User groups, Users and Blocked users modules: the profile's delegated administrators can only act on the domains present in the right-hand list.

Modules not affected by domain filtering

For the other modules (for example Access Policies), the list of allowed domains does not apply: a delegated administrator holding Modify on these modules can pick any domain when creating or editing a contract.

The tabs feature Previous and Next buttons in the footer for navigation.


Edit a delegated administrator profile

Select the profile in the list and click the Properties icon (or double-click the row). The form is identical to the add form and pre-filled with the profile values. Make the changes and click Validate.


Delete a delegated administrator profile

Select one or more profiles and click the × button. A confirmation is requested (label adapted to the singular or plural case).