Roles

Roles

Roles define permissions that technicians require to access AssetExplorer Cloud. Roles are determined based on the various modules in the application.
 
SDAdmin can create multiple roles and assign them to technicians. Multiple roles can be assigned to a technician, but only one admin role can be assigned to a technician.
 
Role Required: Organization Admin, SDAdmin
 
AssetExplorer Cloud comes with predefined roles that can be assigned to technicians. Learn more about the default roles.

You can also create custom roles and assign them to technicians.
 

Create Roles   

To create a role,
  1. Go to Setup > Users & Permissions > Roles.
  2. Click New Role.
  3. Provide a name for the role.
  4. Describe the role, purpose, and usage in the Description field.
  5. Enable Access Permissions by selecting the access level check boxes defined for the Inventory, Purchase, Contract, CMDB, and Reports modules.
 
Access Permissions
Explanation
Full Control
Grants the technician full access to the module by enabling View, Add, Edit, and Delete permissions. If the module has Advanced Permissions, those options will be automatically enabled.
If any action is disabled in Advanced Permissions, the corresponding Full Control permission will also be disabled.
View
Enables the technician to view only the selected module without being able to perform any operations.
 
Add
Allows the technician to perform add operations in the selected module.
Edit
Enables the technician to perform edit operations in the selected module. The technician cannot perform add/delete operations.  
Delete
Allows the technician to perform delete operations in the selected module. The technician cannot perform add/edit operations.
 
Info
If Add, Edit, or Delete access is enabled for a module, the View access is automatically enabled by default. 
  1. The access permissions for Purchases and Contracts modules are further categorized under Advanced Permissions. Enable the check boxes as required.
  2. Allow the technician to export request data from the list view by enabling Allow technician to export data from list view.
  3. Enable the following radio buttons to allow the technician to view data in the modules.
    1. All Module: The technician can access data in all sites.
    2. Module Level Granular Permissions: The technician can access data only in associated sites.
  4. Finally, click Save.
 

Edit/Delete Role   

You can edit or delete created roles from the roles list view.
  1. Click against a role to edit it.
  2. Click against a role to delete it. If technicians are assigned to the role, you will be prompted to send an email notification to the user.
 

  

View Technicians Assigned to Roles 

In the roles list view, click against a role to view the technicians assigned to that role.
 

Default Roles    

Role
Modules Associated
Permissions
AnnouncementConfig
Announcements
Create, edit, delete, and share announcements to users. By default, this role is assigned to all technicians.
AssetConfig
Assets
This role has complete control over the following features.
Asset Management: Product Type, Product, Vendor, Software Type, Software Category, Software License Type, Resource State
Additional Fields: Workstation, Asset License Agreement
Notification Rules: Asset
Probe and Discovery (site-specific): Probe, Credential Library, Windows Domain Network Scan Settings
ContractConfig
Contract and Assets
This role has complete control over the following features.
 
Asset Management: Vendor
Additional Fields: Contract
Notification Rules: Asset
PurchaseConfig
Assets and Purchase
This role has complete control over the following features.
 
Organization Settings: Currency
Asset Management: Product, Vendor
Purchase Management: Default Values, Cost Center, GL Code
Additional Fields: Purchase
Automation: Notification Rules
Closure Rules: Purchase Order Closure Rules
SDAdmin
All modules
Manage all modules in the application with administrative privileges across the organization sites
SDAssetManager
Assets, Purchase, and Contracts
Manage Assets, Purchase, and Contracts modules.
 
View Asset and Software dashboards.
SDCMDBAdmin
CMDB
A mandatory role that allows the technician to access CMDB, Relationships, and CI Types.
SDCMDBManager
CMDB
A mandatory role that allows the technician to access CMDB and Relationships.
SDGuest
Reminders and Announcements
Technicians with this role can access the dashboard, reminders, and announcements in the Home tab.
SDRemoteControl
Assets
Access workstations remotely to perform various tasks, especially troubleshooting.
SDReport
Reports
Generate and schedule all types of reports available in the application.
SDSiteAdmin
All modules
Administrative privileges for site-specific associations in the application. Technicians with this role can access only data related to their associated sites.
Info
The default roles cannot be edited or deleted. You can only edit the SDSiteAdmin role among the default roles.  
 
Operations of SDAdmin and Organization Admin 
SDAdmin has full control over the instance while Organization Admin has full control over the ESM Directory. You can enable organization admin privileges for a user from ESM Directory > Manage UsersLearn more

SDAdmin and Organization Admin can do the following:
Organization Admin
SDAdmin
  1. Convert user into Organization Admin.
  2. Delete other Organization Admin
  3. Extend license subscriptions
  4. Add a new organization user
  5. Enable/disable login for the organization user.
  6. Add a secondary email to user accounts via CSV import or provisioning tools.
  7. Manage users via Zoho Directory and perform several operations like creating users, editing users, monitoring user activity, password reset, etc. Learn more.
 
  1. Import users from the organization account to the instance.
  2. Edit/delete users.
  3. Change a user into a requester or a technician.
  4. Enable or disable login for the user/technician in the instance.
  5. Change roles for a technician.
  6. Modify the roles of Organization Admin to be that of a user or technician, but cannot remove Organization Admin privileges.
  7. Add a secondary email to user accounts via CSV import or provisioning tools.
  8. Edit the primary email of existing users, provided the Organization Admin has enabled the option under ESM Directory > Organization Details.
 
    • Related Articles

    • Organization Roles

      Organization roles are prominent in an organization to approve various requests. In AssetExplorer Cloud, SDAdmins can create and assign roles to users. You can configure organization roles in requests' Service Level Agreements (SLAs) as well. ...
    • Regions

      Organizations may have multiple branches across different regions to manage various activities. It is essential to centralize the data from all these branches in one location. In AssetExplorer Cloud, you can configure the regions of your branches. ...
    • Departments

      There can be various departments in an organization that can be situated in different sites, and each of these departments has a group of employees in them. In AssetExplorer Cloud, you can add, edit, or delete various departments of your ...
    • Users

      In AssetExplorer Cloud, users are categorized into two groups: Users: These are the employees within the organization. Technicians: These users have specialized permissions that allow them to perform activities in the application. Each technician is ...
    • Sites

      Organizations may have several branches across the globe to handle various specialized activities. These branches can be located in the same or different regions, and the data from each of these branches needs to be maintained in the same place. In ...