<a id="managing-command-center-roles"></a>

# Roles

Command Center provides role-based user management functionality.
Granular per-activity user roles can be defined and assigned to Command
Center user accounts.

To create and configure Command Center users, see
[Users](ccvm-users.md#managing-command-center-users).

## Managing Roles

The system includes the preconfigured, non-modifiable **Read Only** role.
**Read Only** role holders have viewing access of all managed resources:

Additional roles can be created as needed.

### Viewing roles

1. At the top right of the Command Center window, click the cog wheel icon.
2. In the dropdown menu that displays, select **Roles**.

   The **Roles** view displays the **Roles** grid:

   | Column      | Description                                                                                  |
   |-------------|----------------------------------------------------------------------------------------------|
   | Name        | The role’s name.                                                                             |
   | Permissions | A list of the managed resources, each resource followed by access permissions for this role. |

   Some managed resources only have permission to allow view access.
   The others have configurable resource-specific permissions, in addition
   to the viewing permission:

   | Managed Resource       | Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
   |------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
   | Access Logs            | - View                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | Protection Zones       | - View<br/>- Rename                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | App Engine types       | - View                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | Central logs           | - View<br/>- Manage RSYSLOG                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
   | Cloud users            | - View<br/>- Manage Vlan ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
   | Clouds                 | - View<br/>- Zsnap<br/>- Upgrade<br/>- Shutdown                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
   | Comments               | - View<br/>- Manage                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | Composite Engine types | - View                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | Virtual Networks       | - View<br/>- Manage                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | Data services          | - View<br/>- Manage                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | Drive types            | - View                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | Drives                 | - View<br/>- Replace<br/>- Manage led<br/>- Enable<br/>- Disable<br/>- Designate as Cache/AFA-Meta<br/>- Undesignate a Cache/AFA-Meta<br/>- SMART test<br/>- License<br/>- Unlicense<br/>- Purge                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
   | IO Engine types        | - View                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | Images                 | - View<br/>- Set default<br/>- Register<br/>- Delete                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
   | Licensing              | - View<br/>- Manage                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | Remote Authentications | - View                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | Storage nodes          | - View<br/>- Evacuate VCs<br/>- Evacuate drives<br/>- Reboot<br/>- Shutdown<br/>- Install<br/>- Upgrade<br/>- Zsnap<br/>- Failover<br/>- Check configuration<br/>- Import drives<br/>- License<br/>- Refresh license<br/>- Set block device performance thresholds                                                                                                                                                                                                                                                                                                                                                                                                                                             |
   | Public IPs             | - View<br/>- Manage                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | VLANs                  | - View<br/>- Add<br/>- Remove<br/>- Allocate<br/>- Deallocate<br/>- Reserve<br/>- Unreserve<br/>- Set default<br/>- Manage VRIDs                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
   | Vpsas                  | - View<br/>- Clear lockdown<br/>- Failover<br/>- Zsnap<br/>- Upgrade<br/>- Launch GUI<br/>- Read Only Launch GUI<br/>- Modify public IP<br/>- Hibernate<br/>- Restore<br/>- Manage File Lifecycle<br/>- Add drives<br/>- Manage Virtual Network Interfaces<br/>- Manage Networks<br/>- Change engine type<br/>- Change object storage engine type<br/>- Change cache<br/>- Move setup to ssd<br/>- Move Virtual Controller<br/>- Purge<br/>- Set Pool Migration<br/>- Set data reduction bundle<br/>- Add storage policies<br/>- Add proxy virtual controllers<br/>- Manage Object Storage Zones<br/>- Manage settings<br/>- Manage file lifecycle management<br/>- Translation missing: en.manage_shared_vpsa |

<a id="ccvm-role-create"></a>

### Defining a new custom role

To define a new custom role:

1. At the top right of the Command Center window, click the cog wheel icon.
2. In the dropdown menu that displays, select **Roles**.
3. In the Roles screen, click **Create new role**.
4. In the **Create Role** dialog, configure the new role:
   * **Name**: Enter a name for the role.
   * **Permissions**:
     * **Global Permission Controls**

       This set of controls apply permission configurations across all
       managed resources.
       * **Select All**:
         * Mark the checkbox to grant all permissions of all resources.
         * Unmarking this checkbox removes all permissions of all
           resources, including those that were applied individually
           or via a specific resource’s **Select All** control.
       * **Expand All**: Display the permissions for all managed resources.
       * **Hide All**: Display the list of managed resources only.
       * **Import Role**: To populate specific permissions based on an
         existing role’s configuration, select the role from the
         dropdown list.

         Multiple roles can be imported to build up a combined
         permissions set.
     * **Managed Resource Permission Controls**

       Each managed resource has its own set of controls:
       * **Expand/Contract** arrow toggle displays all of the selected
         resource’s permission settings, or hides them.
       * **Select All** checkbox appears only for resources that have
         other permissions in addition to the **View** permission
         setting.
         * Mark the checkbox to grant all permissions of the resource.
         * Unmarking this checkbox removes all permissions of the
           resource, including those that were applied individually.
       * One or more resource-specific permission checkboxes:

         Mark the checkbox of each permission that you want to grant to
         users who are assigned this role.
5. Click **Create** to confirm creation of the role with the configured
   settings.

<a id="ccvm-role-edit"></a>

### Editing a custom role

To edit a custom role:

1. At the top right of the Command Center window, click the cog wheel icon.
2. In the dropdown menu that displays, select **Roles**.
3. In the Roles screen, locate the role to edit and click its **Name**.
4. In the **Edit Role** dialog, all attributes are configurable, as
   described in the [Defining a new custom role](#ccvm-role-create) section.
5. Click **Update** to confirm applying the changed settings to the role.

### Deleting a custom role

To edit a custom role:

1. At the top right of the Command Center window, click the cog wheel icon.
2. In the dropdown menu that displays, select **Roles**.
3. In the Roles screen, locate the role and click the down-arrow on its
   right. In the dropdown menu, select **Destroy**.
4. In the **Destroy Role** dialog, click **Confirm** to delete the role.

   On completion, the role will disappear from the list in the Roles
   screen.
