Skip to main content
User guide

Users

Accounts for the gateway's own login and their four roles. Create, change roles, disable, reset passwords and delete; the auditor role and separation of duties. Community has 1 user, Professional is per seat, the auditor role needs Enterprise.

Users is a tab of the Settings page. It manages the accounts for the gateway's own password login; only administrators can change them. Deployments with an IdP use SSO instead: accounts and roles come from the IdP's group mapping, not from this page. SSO needs an Enterprise license; without one, the gateway falls back to the password login managed on this page.

Users

Accounts are stored in state/users.db on the gateway; include it in your backups, see Upgrade, rollback and backup. A standard deployment has password sign-in on. If it is off (for example with SSO), the page says no account can be added. To turn it on, set RST_LOGIN_ENABLED=1 or RST_ADMIN_PASSWORD_HASH in .env and restart the gateway; see the configuration reference.

Create a user

Prerequisites

  • The administrator role.
  • A free seat. Community has 1 user; on Professional and Enterprise, enabled accounts cannot exceed the licensed user count; a trial allows up to 10 enabled accounts. When the seats are full, Create or Enable opens an upgrade dialog.

Steps

  1. Select New user.
  2. Enter the Account and an Initial password (at least 8 characters), and pick a Role.
  3. Select Create.

The gateway sends no email. Give the user the initial password; they change it on the Account page after signing in.

Manage existing accounts

On the account's row:

  • Change the Role. It applies immediately, with no re-login.
  • Select Disable. Every session of that account ends. The account is kept and can be turned back on with Enable.
  • Select Reset password and enter a New password. Every session of that account ends, and the user signs in again with the new password.
  • Select Delete. The account can no longer sign in, every session ends, and this cannot be undone.

You cannot disable or delete the account you are signed in with. The last administrator cannot be disabled, demoted or deleted.

Roles

RolePermissions
AdministratorEverything, including settings, the Zabbix connection, inspection setup, notification channels, AI settings, knowledge base uploads, users, the license and the audit log
AnalystQueries, AI analysis, alert correlation and fault investigation. Can acknowledge or close Zabbix problems, create triggers and maintenance windows, run remote ping / traceroute, push findings, and run inspections and baselines by hand. Cannot change gateway configuration
ViewerQueries and every operations page, CSV export, AI analysis. Cannot write to Zabbix or push anything
AuditorCan only view and export the audit log; sees no operations pages or configuration

An administrator can switch off the analyst's Zabbix write actions and the viewer's AI analysis under Role permissions in Settings.

Auditors and separation of duties

The auditor role and separation of duties are Enterprise features. They meet the separation-of-duties requirement of China's MLPS 2.0, where the system administrator, security administrator and audit administrator are different people.

  • Without an Enterprise license, the auditor role cannot be picked.
  • Separation of duties is off by default, and administrators can read the audit log. When it is on, only auditors can read it; administrators cannot. The switch is under Permissions in Settings.
  • Create the auditor account before turning separation of duties on.

With SSO, the auditor role comes from an IdP group mapping; see SSO.

More enabled accounts than seats

When a license expires, or is replaced by one with fewer users, enabled accounts can exceed the seats. Only administrators can then sign in; other accounts are told that more accounts are enabled than the license allows (code seats_exceeded_admin_only). Accounts and data are kept. Renewing, or disabling the extra accounts, restores access.

On this page