ITAM Built In Accounts and Roles

Summary

List of the built-in Accounts, Roles, and Groups in the ITAM platform

Body

This is a list of the built in Accounts, Roles, and Groups in the ITAM platform as of 8.1.0.6.

Accounts (8)

Account

Notes

Administrator

 

Community

This Account has limited access rights to objects like Computers and Divisions. It is meant to be assigned to externally authenticated users based on membership in an external group.

External Report Account

This Account has the Report-only Role and is a member of the Viewers group. It can be used to do reporting on all objects through ODBC.

KeyReporter Guest

This Account is used when viewing KeyReporter as Guest. By default it has read-only reporting privileges. If you want to change what KeyReporter guest can do, you should change the Roles of this Account.

KeyReporter Schedule

This Account is used internally by KeyReporter in order to generate reports on Schedules that have been created by any Accounts.
Do NOT disable this account or certain core functions will cease to operate properly.

Manager

This Account has broad access rights to all objects and settings. It can serve as a shared account, or be assigned to externally authenticated users based on membership in an external group.

Staff

This Account has limited access rights to objects like Computers, Divisions, and Time Sets. It can serve as a shared account, or be assigned to externally authenticated users based on membership in an external group.

Support

This Account has limited access rights to objects like Computers and Divisions, and has rights to create Maps. It can serve as a shared account, or be assigned to externally authenticated users based on membership in an external group.

 

Roles (16)

Role

Notes

Administrators Role

 

Computer Manager Role

This Role has limited privileges on computers, products, and policies, but cannot see purchases. Its focus is primarily for managing computers (and not users). It is able to run reports and configure report settings.

Enterprise Manager Role

This Role has full privileges on all main objects (computer, products, policies, etc), but cannot change KeyServer-wide settings or Admin configurations. By default this Role has full rights in all ACLs.

Help Desk Role

This Role has limited privileges on computers, products, and policies, but cannot see purchases. Its focus is for assisting active users (not for managing computers). It is able to run reports, but has limited configuration privileges.

Loaner Checkout Role

This Role has the privileges needed to check out computers on behalf of users in the Loaner Checkout extra. Assign this Role to accounts that should be allowed to use the Loaner Checkout extra.

Map Creator Role

This Role has limited privileges on computers but cannot see products, policies, purchases, users, etc. Its focus is primarily for building Computer Availability Maps. It is not able to logon to KeyConfigure or to run reports.

Product Creator Role

This Role adds supplemental privileges to other Roles for manual creation of software Product definitions. It can be assigned to an Account in addition to another Role or it can be the only Role assigned.

Proxy Role

This Role allows the KeyReporter Schedule Account to run reports on behalf of other Accounts.

Public Role

This Role has read-only privileges on all main objects (computers, products, policies, etc). It does not appear by default in ACLs, so Access Rights must be gained by another Role or Group.

Purchasing Assistant Role

This Role has limited privileges on purchases. It can view products and policies but cannot see computers. Its focus is for entering software procurement details. It is able to run reports, but has limited configuration privileges.

Purchasing Manager Role

This Role has full privileges on purchases, limited privileges on products and policies, and cannot see computers. Its focus is for managing software procurement. It is able to run reports and configure report settings.

Remote Connection Role

This Role has rights to connect remotely to computers. It does not appear by default in ACLs, so Access Rights must be gained by another Role or Group.

Report-only Role

This Role has read-only privileges on all main objects (computers, products, policies, etc). It is useful for KeyReporter or ODBC reporting. It does not appear by default in ACLs, so Access Rights must be gained by another Role or Group.

Section Manager Role

This Role has a limited set of privileges that are typically needed by accounts that manage individual Sections.

Section Reporter Role

This Role has read-only privileges on all main objects and limited configuration privileges for Time Sets and reports. It is able to run reports and configure report settings.

Self Service Role

This Role has the rights needed to view computers, devices, and software that is associated with the account. Assign this Role to accounts that should be allowed to View Assets connected to them.

 

Groups (2)

Group

Notes

Editors

This Group has rights to change all objects, restricted to applicable privileges, as configured in the root Server ACL and inherited by all other ACLs.

Viewers

This Group has view rights for all objects, as configured in the root Server ACL and inherited by all other ACLs.

 

Accounts — Assigned Roles & Groups

Account

Roles & Groups

Administrator

Administrators Role

Community

Public Role, Remote Connection Role, Viewers

External Report Account

Report-only Role, Viewers

KeyReporter Guest

Public Role, Remote Connection Role, Viewers

KeyReporter Schedule

Report-only Role, Proxy Role, Viewers

Manager

Administrators Role, Editors

Staff

Computer Manager Role, Editors

Support

Help Desk Role, Computer Manager Role, Map Creator Role, Viewers

 

See also the complete list of all Privileges held by these default Roles.

Details

Details

Article ID: 172789
Created
Wed 9/2/26 9:28 AM
Modified
Wed 9/2/26 9:33 AM