Reference
Roles and capabilities
Built-in roles and all granular capability keys.
Built-in roles
| Role | Scope | Description | Action policy |
|---|---|---|---|
| Administrator | Global | Full platform, inventory and network access everywhere. | All capabilities and all actions |
| Power User | Global | Full switch operations and raw CLI access across the fleet, without platform administration. | All operational actions, terminal and custom CLI |
| Site Administrator | Scoped | Full governed operational access, restricted to assigned Sites and Groups. | All operational actions inside scope |
| Operator | Scoped | Operational troubleshooting, governed changes and approved Runbooks inside assigned scope. | Read actions, alias, interface/PoE cycle, PoE enable/disable, Fix UNP, VLAN maintenance, save configuration, approved Runbooks |
| Helpdesk | Scoped | Scoped visibility and basic port support. | Read actions, alias, interface restart and PoE restart |
| Read Only | Scoped | Scoped inventory and activity visibility only. | No live CLI execution or console access |
Capability catalog
| Capability | Category | Label | Description |
|---|---|---|---|
dashboard.view | Core access | Dashboard | View fleet health and scoped summary metrics. |
devices.view | Core access | Switches | View switch inventory within the assigned Site/Group scope. |
power.view | Core access | Power | View UPS health, power incidents and switch power-source correlation within scope. |
finder.use | Core access | Find Device | Run live endpoint discovery against scoped switches. |
devices.live_ports | Operations | Live port data | Read live interface, VLAN and PoE data from scoped switches. |
operations.view | Operations | Operations workspace | Open Operations and select switches inside the assigned scope. |
operations.read | Operations | Read-only CLI actions | Execute catalog actions classified as read-only. |
operations.runbook | Operations | Approved Runbooks | Execute approved Custom Runbooks within scope. |
audits.view | Operations | Fleet Audit history | View Fleet Audit results that are entirely within scope. |
audits.run | Operations | Run Fleet Audits | Launch read-only Fleet Audits against scoped switches. |
notifications.view | Observability | Notifications | View switch, stack and power notification state inside the assigned scope. |
activity.jobs | Observability | Jobs | View Jobs whose targets are within the assigned scope. |
activity.audit | Observability | Audit Log | View authorization and activity evidence permitted for the role. |
command_library.view | Tools | Command Library | View only the command templates that the role may execute. |
drivers.view | Tools | Drivers | View the built-in switch, UPS and future infrastructure driver reference. |
inventory.manage | Administration | Manage switches | Add, edit, import and remove switch records inside scope. |
power.create | Administration | Add UPS | Create new UPS assets inside the assigned scope. |
power.edit | Administration | Edit UPS | Edit UPS identity, monitoring profile and driver settings inside scope. |
power.delete | Administration | Delete UPS | Delete UPS assets inside scope and unassign their protected switches. |
power.verify | Administration | Verify UPS telemetry | Run read-only SNMPv3 UPS telemetry verification. |
power.assign | Administration | Assign power sources | Assign or remove scoped switches from a monitored UPS power source. |
terminal.use | Advanced access | Interactive terminal | Use the unrestricted interactive SSH terminal on scoped switches. |
custom_cli.use | Advanced access | Custom CLI | Submit manually authored CLI commands to scoped switches. |