User roles and User management authorization

Accessing a page does not grant permission to perform all actions on that page. Each operation requires specific roles and group restrictions. You cannot perform an operation unless you have the required roles.

User management authorization

This table shows the role required for each user management operation:
Operation Required roles
Add user User Mgmt - Add New User or Add User From Portal
Modify user User Mgmt - Modify User
View or Print user User Mgmt - View/Print User
Inactivate or Activate user User Mgmt - Inactivate User
Add group User Mgmt - Add Group
Modify group User Mgmt - Modify Group
View or Print group User Mgmt - View/Print Group
Clone user Add New User or Add From Portal OR Modify User

Protected groups: SA and ADMIN

This table shows the restrictions for the SA and ADMIN groups:
Restriction Who can perform
Modify the SA group or assign users to it SA group members only
Modify the ADMIN group SA or ADMIN group members only
Change role sets of SA or ADMIN groups No user
Assign SA-exclusive roles such as Properties Mgmt and Label Format to non-SA groups No user

Protected account: MSCMADMIN

This table shows the restrictions for the MSCMADMIN account:
Restriction Who can perform
Deactivate MSCMADMIN No user
Remove MSCMADMIN from the SA group No user
Modify or reset the password for MSCMADMIN SA group members only
Activate MSCMADMIN, if disabled Any user with the Inactivate User role

System management authorization

All System Management pages require the Properties Mgmt role. Only SA group members have this role.

If you are not an SA group member, you cannot access these pages. Attempts to access them directly prompts a "Server error occurred" message.

This table shows the pages that require the Properties Mgmt role:
Page or tab Required role Who has it
Properties (Tenant Settings) Properties Mgmt SA only
Date Tracker Settings Properties Mgmt SA only
Reports (BI Settings) Properties Mgmt SA only
Server Logs Properties Mgmt SA only
Scheduler Maintenance Properties Mgmt SA only
Audit Logs (System Mgmt tab) Properties Mgmt SA only

Audit logs and view logins authorization

The audit log pages on the User Management toolbar require the View Audit Logs role. Members of the SA and ADMIN groups have this role by default.

This table shows the pages that require the View Audit Logs role:
Page Required role
View Audit Logs (User Management toolbar) View Audit Logs
View Logins (User Management toolbar) View Audit Logs

Label Format authorization

The Label Format screen requires the Label Format role and SA group membership. All operations on this screen require both conditions.

If you are not an SA group member, you cannot access the Label Format screen and redirected to the standard error page.

This table shows the operations that require the Label Format role and SA group membership:
Operation Required role Group restriction
Open or view the Label Format screen Label Format SA group only
Update a custom label format Label Format SA group only
Confirm a label-format update Label Format SA group only

Server-side authorization

Authorization is validated at the server for these areas:

  • User Management (per-operation role checks)
  • System Management pages (Properties Mgmt role)
  • Audit Logs and View Logins pages (View Audit Logs role)
  • Label Format screen (Label Format role and SA group membership)

Privileged write role assignment

Only ADMIN or SA group members can assign these privileged write roles to a group:
  • User Mgmt - Add New User
  • User Mgmt - Add User From Portal
  • User Mgmt - Modify User
  • User Mgmt - Inactivate User
  • User Mgmt - Add Group
  • User Mgmt - Modify Group
Note:  Each user belongs to a single group. A user cannot accumulate all six privileged write roles across multiple groups.
This table shows the restrictions for privileged write role assignment:
Condition Result
A non-ADMIN or non-SA member attempts to assign a privileged write role Not permitted
A group is assigned all six privileged write roles Not permitted, including for ADMIN or SA members
A non-SA group is assigned an SA-exclusive role Not permitted
A user attempts to change the role set of the SA or ADMIN group Not permitted

Error messages for unauthorized access

If you attempt an action without the required role, an error message is displayed. The message does not include specific authorization details. All unauthorized access attempts are logged in the server log.

This table shows the error behavior by area:
Area Message displayed
User Management Error page
System Management "Server error occurred"
Audit Logs or View Logins "Server error occurred"