Skip to main content

User roles

Each user can perform actions based on the roles that are assigned to them in the organization. Each user is assigned one or more of the following roles.

When using XClarity One on premises, you can enable the View only toggle to give users read-only privileges, meaning that they can only view information. If this toggle is disabled, users can view information and perform actions on those resources.

Note
If a user belongs to one or more user groups, that user inherits roles that are assigned to each user group of which they are a member in addition to the roles that are assigned directly to that user. For more information about, see User groups.
Important
If you change roles for a user that is currently signed in, that user must sign out and then sign in again to see the correct privileges.
  • User administrator

    An organization must have at least one active user administrator; however, at least two user administrators is highly recommended for redundancy and security.

    User administrators can perform the following actions.
    • View user information, including user profiles, user groups, events, alerts, todos, and jobs

    • Manage users, including adding, deleting, modifying, enabling, and disabling users, and modifying roles for users

    • Manage authentication, including resetting passwords and multifactor authentication for local users

    • Manage user groups, including adding, deleting, modifying, enabling, and disabling groups, importing externally defined LDAP groups, modifying group membership and roles

    • Manage user-related todos, including dismissing and restoring todos

    • Manage user-related alerts and events, including dismissing and restoring alerts, and adding, editing, and removing exclusion rules

    • View external identity provider configurations

  • Hub administrator

    Hub administrators can perform the following actions.
    • View hub information, including hub details, discovered and managed devices, events, alerts, todos, jobs, vulnerabilities, and service tickets

    • Manage hubs, including adding (connecting), removing (disconnecting), and enabling or disabling hubs

    • Migrate devices and artifacts from Lenovo XClarity Administrator

    • Manage hub-related todos, including dismissing and restoring todos

    • Manage hub-related alerts and events, including dismissing and restoring alerts, and adding, editing, and removing exclusion rules

  • Device administrator

    Device administrators can perform the following actions.
    • View device information, including device details (inventory, health, usage metrics, warranties), collections, event forwarders, events, alerts, todos, jobs, vulnerabilities, and service tickets

    • Discover and manage devices, including discovering and managing devices in your data center, and migrating devices and artifacts from XClarity Administrator

    • Power on, off and restart devices

    • Manage collections of devices, including adding, deleting, modifying collections and monitoring health and usage metrics for the entire collection

    • (Cloud only) Remotely access the management controller and server console

    • Manage the repositories of firmware, device settings, and operating systems

    • Manage device-configuration templates, including adding, removing, modifying templates, and deploying templates to devices

    • Manage device-related todos, including dismissing and restoring todos

    • Manage device-related alerts and events, including dismissing and restoring alerts, and adding, editing, and removing exclusion rules

    • Manage scheduled jobs

    • Manage external certificates for device

    • Export data as a report

    • Assign support contacts to specific devices and collections

    • Collect and upload device service data to Lenovo Support

    • (On premises only) View and manage device service data

Organization owners

You can enable the View only toggle to give organization owners read-only privileges, meaning that they can only view information. If this toggle is disabled, organization owners can view information and perform actions on those resources.

Organization owners can perform the following actions.

  • View organization information, including organization details, domains, licenses, alerts, events, things to do and jobs

  • Manage users in the organization, including inviting new users, assigning roles, reset passwords and multifactor authentication, and enabling or disabling users.

    Note
    Only organization owners can create local user accounts when your organization uses a corporate identity provider for authentication.
  • Add or remove the owner property from other users. Owners cannot remove the owner property from their own user account.

    If you add or remove the owner property from a user that is currently signed in, that user must sign out and then sign in again to see the correct privileges.

  • Manage todos, including dismissing and restoring todos

  • Manage alerts and events, including dismissing and restoring alerts, and adding, editing, and removing exclusion rules

  • Manage Call Home configurations and contacts

  • Manage data forwarders, including adding, removing and modifying forwarders

  • Managing management-hub functions that can be performed through the portal, including disabling function on the portal and hub, and enabling functions on the portal

  • Manage federated authentication, including adding, deleting an modifying external identity providers

  • Manage API keys used to for authentication when running scripts, including adding, removing, modifying, enabling, disabling keys and regenerating secrets

  • Configure memory and processor thresholds

  • Manage custom alerts, including adding, removing and modifying custom alerts

  • (On premises only) Import licenses

  • (On premises only) Configure the portal settings, including network, web proxy, date and time, SMTP email server, usage thresholds, and security certificates

  • (On premises only) Collect and upload XClarity One service data to Lenovo Support

  • (On premises only) Mange portal update packages and update the portal software