PortivoDocs · v2.0.0Complete handbookportivo.orgGitHub
Reference

Roles and capabilities

Built-in roles and all granular capability keys.

v2.0.0Source-backed

Built-in roles

RoleScopeDescriptionAction policy
AdministratorGlobalFull platform, inventory and network access everywhere.All capabilities and all actions
Power UserGlobalFull switch operations and raw CLI access across the fleet, without platform administration.All operational actions, terminal and custom CLI
Site AdministratorScopedFull governed operational access, restricted to assigned Sites and Groups.All operational actions inside scope
OperatorScopedOperational troubleshooting, governed changes and approved Runbooks inside assigned scope.Read actions, alias, interface/PoE cycle, PoE enable/disable, Fix UNP, VLAN maintenance, save configuration, approved Runbooks
HelpdeskScopedScoped visibility and basic port support.Read actions, alias, interface restart and PoE restart
Read OnlyScopedScoped inventory and activity visibility only.No live CLI execution or console access

Capability catalog

CapabilityCategoryLabelDescription
dashboard.viewCore accessDashboardView fleet health and scoped summary metrics.
devices.viewCore accessSwitchesView switch inventory within the assigned Site/Group scope.
power.viewCore accessPowerView UPS health, power incidents and switch power-source correlation within scope.
finder.useCore accessFind DeviceRun live endpoint discovery against scoped switches.
devices.live_portsOperationsLive port dataRead live interface, VLAN and PoE data from scoped switches.
operations.viewOperationsOperations workspaceOpen Operations and select switches inside the assigned scope.
operations.readOperationsRead-only CLI actionsExecute catalog actions classified as read-only.
operations.runbookOperationsApproved RunbooksExecute approved Custom Runbooks within scope.
audits.viewOperationsFleet Audit historyView Fleet Audit results that are entirely within scope.
audits.runOperationsRun Fleet AuditsLaunch read-only Fleet Audits against scoped switches.
notifications.viewObservabilityNotificationsView switch, stack and power notification state inside the assigned scope.
activity.jobsObservabilityJobsView Jobs whose targets are within the assigned scope.
activity.auditObservabilityAudit LogView authorization and activity evidence permitted for the role.
command_library.viewToolsCommand LibraryView only the command templates that the role may execute.
drivers.viewToolsDriversView the built-in switch, UPS and future infrastructure driver reference.
inventory.manageAdministrationManage switchesAdd, edit, import and remove switch records inside scope.
power.createAdministrationAdd UPSCreate new UPS assets inside the assigned scope.
power.editAdministrationEdit UPSEdit UPS identity, monitoring profile and driver settings inside scope.
power.deleteAdministrationDelete UPSDelete UPS assets inside scope and unassign their protected switches.
power.verifyAdministrationVerify UPS telemetryRun read-only SNMPv3 UPS telemetry verification.
power.assignAdministrationAssign power sourcesAssign or remove scoped switches from a monitored UPS power source.
terminal.useAdvanced accessInteractive terminalUse the unrestricted interactive SSH terminal on scoped switches.
custom_cli.useAdvanced accessCustom CLISubmit manually authored CLI commands to scoped switches.