Users & Access Control

Default Roles

Role Access Level
Super AdminFull unrestricted access — bypasses all permission checks. Includes system settings, role management, system health, and all other features.
AdminAll features including system health, documentation, user management, channels, and settings view — except role management and settings editing.
OperatorView devices, monitors, alerts, traps, MIBs, discovery, channels, notification log, and documentation. Can acknowledge/resolve alerts and traps, run network tools, and manage own dashboards. No access to settings, system health, users, or roles.
ViewerRead-only access to devices, monitors, alerts, traps, MIBs, discovery, channels, notification log, and documentation. No access to settings, system health, users, or roles.

Permissions

Granular permission slugs control access to every resource. Custom roles can be created with any combination of these permissions.

Category Permission Slugs
SNMP Devicesdevices.view devices.create devices.edit devices.delete
Device Groupsdevice-groups.view device-groups.create device-groups.edit device-groups.delete
Service Monitorsmonitors.view monitors.create monitors.edit monitors.delete monitors.run_tools
Monitor Groupsmonitor-groups.view monitor-groups.create monitor-groups.edit monitor-groups.delete
Alert Rulesalert-rules.view alert-rules.create alert-rules.edit alert-rules.delete
Alert Eventsalerts.view alerts.create alerts.edit alerts.delete alerts.acknowledge
Notification Lognotifications.view
MIBsmibs.view mibs.upload mibs.delete
Discoverydiscovery.view discovery.create discovery.run
SNMP Trapstraps.view traps.acknowledge traps.delete
Dashboardsdashboards.view dashboards.create dashboards.edit dashboards.delete dashboards.share
Webhookswebhooks.view webhooks.create webhooks.edit webhooks.delete
Usersusers.view users.create users.edit users.delete roles.manage
Channelschannels.view channels.create channels.edit channels.delete
Settingssettings.view settings.edit
Systemsystem-health.view documentation.view
System Maintenancesystem.restart-services system.restart-host (host reboot is super-admin-only by default)

Two-Factor Authentication (2FA)

TOTP-based 2FA via Google Authenticator or similar apps. Enable from your profile page — scan the QR code, enter the verification code, and store your recovery codes securely. Recovery codes provide backup access if you lose your authenticator.

Profile & API Tokens

Users can update their profile (name, email, avatar), change password, and manage API tokens from the profile page. API tokens are used for REST API authentication via Bearer tokens.

We use essential cookies only to keep you logged in and remember your preferences. Cookie Policy