Roles
Roles allow you to control access to the HyWorks and define the privileges that the user is going to have on the HyWorks/HyLabs resources.
You can check the list of the pre-defined roles and add custom roles from the Users > Admin Users > Roles page.
Roles are critical for organizational access and are accessible to the Super Administrator only. Based on access, roles can also be classified into HyWorks roles and HyLabs roles.
Built-in Roles
The following pre-defined roles are available in HyWorks configurations. This section covers HyWorks management roles, whereas HyLabs roles are covered in the Reservation Management guide.
-
Super Administrator
-
Administrator
-
Helpdesk
-
Read-only
-
Session Recording Auditor
The following pre-defined roles apply to HyLabs users but are managed from HyWorks:
-
Reservation Administrator
-
In-charge
-
Assistant
-
Participant
Super Administrator
-
The Super Administrator can be defined only during installation.
-
The Super Administrator role can not be modified or deleted.
-
No user other than the local user or group defined as the Super Administrator during installation can be assigned a Super Administrator role.
-
A Super Administrator is, by default, propagated to the child organizations.
-
A Super Administrator has all the configurational access in HyWorks, including the system-level configurations.
Administrator
-
Users with this role do not have access to the system-level configurations.
-
The Administrator (predefined) role cannot be deleted, but the user with the Administrator role can be removed.
-
The Administrator user/group permissions can be overridden at the child organization level by assigning a different role to this user.
Helpdesk
-
The level-3 Administrator role requires writing access to the limited modules.
-
The Helpdesk (predefined) role cannot be deleted, but the user with the Administrator role can remove this user.
-
The Helpdesk user/group permissions can be overridden at the child organization level by not propagating to the child organizations or by assigning a different role to this user.
Read-Only
-
Users in this role have view-only permissions for the limited modules.
-
Predefined role in HyWorks which cannot be deleted.
-
Read-only user/group permissions can be overridden at the child organization level by assigning a different role to this user.
Session Recording Auditor
-
Only Session Recording Auditor role users have permission to play session recordings.
-
Users with this role do not have access to the system-level configurations.
-
The Session Recording Auditor (predefined) role cannot be deleted, but the user with the Session Recording Auditor role can be removed.
-
The Session Recording Auditor, user/group permissions, can be overridden at the child organization level by assigning a different role to this user.
Roles Management
The following actions can be performed from the Users > Admin Users > Roles page:
- View Role privileges
- Add Role
- Edit Role
- Delete Role - Select the custom-defined role you want to delete and click Delete.
View Privileges
To view the associated privileges of any role, follow the steps below:
-
Go to Users > Admin Users > Roles.
-
Click Role to view its privileges. You will be navigated to the Privileges page that displays HyWorks resources and associate permissions of that role.
Add Role
-
Log in as a Super Administrator.
-
Go to Users > Admin Users > Roles and click Add.
-
Enter the following details in the wizard:
-
Enter the Name for a new role.
-
Describe the role if required.
-
Select the Status to activate the role. If you do not activate the role, it will not appear on the Permissions page.
-
Select a Role Classification, i.e., Administrator, HyLabs-Incharge, HyLabs-Assistant or HyLabs-Participant.
Role classification determines the basic level of access in HyLabs For example, a role classified as In-charge will also have the permissions of that of an In-charge.
- Select appropriate resource privileges for the new role.
Note
Privileges for the system-level resources should not be given to the custom role and should be kept for the Super Administrator only. These resources or configurations are critical to the whole system.
-
-
Click Add to save the new role. The role will be displayed in the list of roles and can now be assigned to users from the Permissions page. <!--1. Privileges on the resources at the system level cannot be given to custom roles and will appear disabled; examples of such resources are:
- Role Management
-
Client Software Settings
-
Server Configurations
-
HyWorks Controller
-
Backup and Restore
-
License Management
-
RDP Proxy Settings
-
SMTP Configuration -->
Edit Custom Role
-
Log in as the Super-Administrator and go to Users > Admin Users > Roles.
-
Select the role to edit and click Edit.
-
In the wizard, modify the fields as required and click Update.
The new privileges will come into effect at the next login.
Delete Custom Role
Prerequisite
The role you want to delete should not be associated with any permissions.
-
Log in as the Super-Administrator and go to Users > Admin Users > Roles.
-
Select the role to delete and click Delete.
-
The Confirm Action dialog will be displayed; click Delete to continue deleting the role.