Planning for administrator roles

Define the authority levels that you want to assign to administrators who have access to the IBM Storage Protect solution.

You can assign one of the following levels of authority to administrators:
System
Administrators with system authority have the highest level of authority. Administrators with this level of authority can complete any task. They can manage all policy domains and storage pools, and grant authority to other administrators.
Policy
Administrators who have policy authority can manage all of the tasks that are related to policy management. This privilege can be unrestricted, or can be restricted to specific policy domains.
Storage
Administrators who have storage authority can allocate and control storage resources for the server.
Operator
Administrators who have operator authority can control the immediate operation of the server and the availability of storage media such as tape libraries and drives.
The scenarios in Table 1 provide examples about why you might want to assign varying levels of authority so that administrators can perform tasks:
Table 1. Scenarios for administrator roles
Scenario Type of administrator ID to set up
An administrator at a small company manages the server and is responsible for all server activities.
  • System authority: 1 administrator ID
An administrator for multiple servers also manages the overall system. Several other administrators manage their own storage pools.
  • System authority on all servers: 1 administrator ID for the overall system administrator
  • Storage authority for designated storage pools: 1 administrator ID for each of the other administrators
An administrator manages 2 servers. Another person helps with the administration tasks. Two assistants are responsible for helping to ensure that important systems are backed up. Each assistant is responsible for monitoring the scheduled backups on one of the IBM Storage Protect servers.
  • System authority on both servers: 2 administrator IDs
  • Operator authority: 2 administrator IDs for the assistants with access to the server that each person is responsible for