CreaRack-SL

User management, roles and permissions

What it is

CreaRack uses three roles plus per-module fine-tuning. Every user gets a role — Read Only (Viewer), Operator or Admin — and an Admin can then adjust what each user can do in every module (Racks, Blueprints, Observatory, Terminal, Network, CNS, ITSM, Fleet, Signage, Users) with four levels: None, View, Edit, Admin.

All of this lives in the User Settings dialog: open Configuration in the top bar, then Users → User Settings. Every user can open it for their own language, security devices and email alerts; the user management part described here only shows to Admins.

How to add a user

  1. Open Configuration → Users → User Settings.
  2. In the add form, fill Username and Password, pick a Role (“Read Only (Viewer)”, “Operator” or “Admin”) and click Add. The password has to pass the same checks as a password change (at least 8 characters, not one of the common passwords, not only digits, not too close to the username); otherwise the user is not created and the reasons are shown.
  3. The user appears in the table with columns “Username”, “Role”, “MFA” and “Actions”. Share the credentials with them and encourage them to set up MFA on first login — see [[crearack—settings—mfa-and-login-security]].

How to fine-tune permissions

  1. Click Edit next to the user.
  2. In the “Module Permissions” table, pick a level per module: None (no access), View (read-only), Edit (can change things) or Admin (full control of that module).
  3. Reset to Defaults returns the user to their role’s standard permissions. You can only reset someone whose role does not give them more than you have yourself.

The grid shows the user’s permanent permissions, without any temporary access on top, and Save Changes only stores the modules you actually changed. A temporary grant therefore never becomes permanent by saving the user. To take access away, set the module to None.

Changing the role starts from the new role. When you pick another Role, the grid switches to that role’s standard permissions, so what you see is what will be saved. On saving, any custom per-module adjustments made under the old role are removed, and the changes you make in the grid are applied on top of the new role. Temporary grants are kept until they expire.

A common pattern: an “Operator” who manages monitoring but should not touch rack layouts gets Racks = View, Observatory = Edit.

Temporary access grants

When someone needs extra permissions for a maintenance window — not forever — use a grant instead of changing their role:

  1. In Edit User, go to the “Temporary Access” section.
  2. Choose the Scope (a single module or “All Modules”), the Level (View / Edit / Admin), the duration in Hours (1–72, default 4) and write a Reason.
  3. Click Grant. The user shows an “Elevated” badge with the scope, level and time remaining; the grant expires by itself, or you can end it early with Revoke.

Other actions

  • Change password — in Edit User. When you change your own password you must type your current one first; an Admin resetting another user’s password does not need it. You stay signed in after the change. The new password has to follow the usual rules — at least 8 characters, not one of the common passwords CreaRack blocks, not made only of digits, and not too close to the username — whether you are changing your own or an Admin is resetting someone else’s.
  • Password lockout — if you get your current password wrong 5 times within 5 minutes while trying to change it, CreaRack locks your own password change for a few minutes before you can try again. This does not affect signing in or an Admin resetting your password from User Settings.
  • Impersonate — an Admin can temporarily act as another user (a reason is required and recorded) to reproduce what they see. Not available against superusers. The view ends by itself if the target is deactivated or moved to another organization, or if the Admin loses that role.
  • Delete — removes the user after a confirmation prompt. Their work (racks, maps, devices) stays.
  • MFA — opens the user’s MFA devices so an Admin can remove a lost authenticator. See [[crearack—settings—mfa-and-login-security]].

Every one of these actions is recorded in the System Logs audit trail — see [[crearack—settings—system-logs]].

  • [[crearack—conceptos—usuarios-y-permisos]] — the roles model explained conceptually
  • [[crearack—settings—mfa-and-login-security]] — MFA, login history, session timeout
  • [[crearack—settings—system-logs]] — the audit trail

Véase también

  • [[crearack—conceptos—usuarios-y-permisos]]
  • [[crearack—settings—mfa-and-login-security]]