Administrative authority levels
To complete some IBM® Storage Protect tasks, you must have a specific administrative authority level. Administrators who have system authority can assign authority levels to other administrators.
On the menu bar of the Operations Center, an icon indicates the authority level of the administrator who is logged in. You can hover over the icon for a text description of the authority level.
If you have more than one authority level, the icon indicates the highest authority level that you have.
Authority levels are also called privilege classes.
System authority- Administrators who have system authority can complete any task in the Operations Center and can issue the GRANT AUTHORITY command to assign authority levels to other administrators.
Policy authority or storage authority- Administrators who have policy authority can manage backup and archive services.
- Administrators who have storage authority can manage server storage.
Operator authority- Administrators who have operator authority can manage alerts and client sessions.
Client owner authority- Administrators with this authority can manage the clients for which they were granted authority. They can remotely access a client by using the web client interface, view client logs, and decommission clients.
- Viewing information in the Operations Center
- Any administrator who is registered on the hub server can view information in the Operations Center.
Tips:
- If an administrator who has system authority changes your authority level while you are logged in to the Operations Center, you must log out and log back in to use the new authority level.
- To complete a task on a spoke server, you must have the required authority level on both the hub and spoke servers.
Table 1 lists the actions that administrators with different authority levels can take in the Operations Center.
| Page or window in the Operations Center | Action | System authority | Policy authority | Storage authority | Operator authority | Client owner authority |
|---|---|---|---|---|---|---|
| Alerts | Close alerts | Yes | Yes | Yes | Yes | No |
| Assign alerts | Yes | Yes | Yes | Yes | No | |
| Change the alert state | Yes | Yes | Yes | Yes | No | |
| Add alert | Yes | No | No | No | No | |
| Delete alerts | Yes | No | No | No | No | |
| Configure notification | Yes | No | No | No | No | |
| Change category | Yes | No | No | No | No | |
| Clients | Add client | Yes | Yes | No | No | No |
| Back up clients | Yes | Yes | No | No | No | |
| Configure at-risk settings | Yes | Yes | No | No | No | |
| Assign clients to schedules | Yes | Yes | No | No | No | |
| Decommission clients | Yes | Yes | No | No | Yes | |
| Change the value of certain properties | Yes | Yes | No | No | No | |
| Connect to a client for remote file-restore operations | Yes | No | No | No | Yes | |
| View client logs | Yes | Yes | No | No | Yes | |
| Add schedule | Yes | Yes | No | No | No | |
| Update schedules (edit the times and repeat frequencies) | Yes | Yes | No | No | No | |
| Reports | Configure report settings | Yes | No | No | No | No |
| Servers | Connect spoke | Yes | No | No | No | No |
| Back up server database | Yes | No | Yes | No | No | |
| Monitor spoke | Yes | No | No | No | No | |
| Change the value of certain properties | Yes | No | No | No | No | |
| Cancel sessions | Yes | No | No | Yes | No | |
| Cancel processes | Yes | No | No | No | No | |
| Storage Pools | Back up storage pool | Yes | No | Yes | No | No |
| Migrate storage pool | Yes | No | Yes | No | No | |
| Reclaim storage pool | Yes | No | Yes | No | No | |
| Change the value of certain properties | Yes | No | Yes | No | No | |
| Command Line | Issue commands | See the information about privilege classes for commands in the documentation. | ||||
| Change retention and at-risk settings | Yes | No | No | No | No | |
| Edit the list of shared links | Yes | No | No | No | No | |