Creating System Administrator Policies

A System Administrator Policy controls access to forms in the System Administration Tool. When you create a policy, you set permissions that grant Read or Read/Write access to forms. You can also Deny access to forms, which hides them from the user.

Policies are assigned to users (one per user only) in the User Authorization Profiles form and distributed to all cluster elements by SDS.

There are three default policies—ROOT, SYSTEM, and REMOTE—each with different levels of access as described in the following table:

Level

Form Access Allowed

Permissions Granted

ROOT Administrator

(equivalent to the SDS Administrator in 7.x and earlier releases)

All.

Read/Write

SYSTEM Administrator

All except:

  • Admin Policies

  • User Authorization Profile

  • SDS Form Sharing form

Admin Policies: Deny

User Authorization Profile: Read

All others: Read/Write

REMOTE System Management

Same as System Administrator except for the following IP networking forms:

  • System IP Properties form (for all nodes)

  • IP Routing form (for CXi, CXi II, and MXe)

  • All forms in the Internet Gateway branch (for CXi and MXe)

  • All forms in the Firewall branch (for CXi, CXI II, and MXe)

IP Networking: Deny
All others: Read/Write

To create a new System Administrator policy:

  1. Log in as a Root Administrator.

  2. In the Admin Policies form, click Add.

  3. Type a name up to 25 alphanumeric characters for the policy.

  4. Select a Default Access Type. This sets the permissions on all forms, which you can change for individual forms; see below for instructions.
    By default, all forms are
    Read/Write.

  5. Click Save.

To change the access type for individual forms:

  1. Select a form  from the Policy Members area.

  2. Click Change Member.
    Select an
    Access Type.

  3. Click OK.

Change Page Members and Change All Members allow you to change the access type for currently listed forms only, or for all forms. To assign a System Administrator policy to a user, see Assigning Administrators.