NexLog Recorder User Manual v2.2.0
113
'Add Group' and 'Edit Group' both navigate to the same page where group
membership can be viewed and modified. However, 'Edit Group' provides access
to the options for an existing group, while 'Add Group' creates a new group and
provided access. In addition to a Group Name, this page allows you to modify
which users are a member of the group. To accomplish this task, choose a user
from the drop down list of all users. Once chosen the user will appear below the
dropdown list as being a member of this group. You can remove a user by
simply clicking the 'remove' link next to the user name. You can also control a
user's group memberships via the check boxes on the Security: Users page. No
changes will take effect on this page until the 'Save button' is clicked.
'Delete Group' will prompt for conformation and then delete the currently
selected user group from the system. Users that are members of that group will
not be deleted, but they will no longer possess any permissions they were
inheriting through their group membership.
The 'Permissions' button is a shortcut which navigates to the Security:
Permissions page with a preset filter to show only permissions for the currently
selected User Group
4.9.5. Permissions
In NexLog, “Permission” refers to an action or "Security Operation" that can be
taken on an Entity or "Security Object". For example "Alert Codes" is a Security
Object and "Update" is a Security Operation, so a user or user group could be
assigned permission to "Update" "Alert Codes", which would allow them access
to modify the Alert Code Settings under Alerts and Logs: Alert Codes. At install
time, your NexLog recorder is pre-assigned a default set of User Groups and
Permissions. Often, Recorder Administrators will simply assign users to the
preexisting groups, and possibly make minor modification to what permissions
each group has. However, if necessary, the NexLog permissions system is
flexible to allow for the creation of arbitrary user groups and the assignment of
arbitrary subsets of the available permission to that group, so the entire security
system behavior can be altered. Permissions can be assigned directly to a user,
or can be assigned to a user group, which causes all users who are enrolled in
that user group to inherit the permission.
The primary element on the Permissions Setup page is a table showing all the
currently assigned permissions. Each row in the table represents one
permission assignment on the system, for example "Group Maintainers can
Update Alert Codes", along with "Next Page" and "Previous Page" buttons for
navigating through the table.
The table contains the following fields:
Security Object
: The entity or object which the permission references.
Examples of Security Objects are "Alert Codes" or "Archive Drives".
Security Operation
: The action upon the security object that the permission
references. For example, READ, UPDATE, ADD, DELETE. Some Security Objects