OperationsCommander - https://opscom.wiki

Admin Management Tools

Accessed from the System Configuration menu, this is where you create/edit roles and permission as well as Admin User Accounts.

Manage Roles and Permissions

The Roles and Permissions feature provides granular control over what administrative users can access and do within the system. Its primary purpose is to allow administrators to define specific responsibilities, enhance security, and streamline operations by ensuring users only have appropriate access levels. This article is intended for OPS-COM administrators responsible for managing backend system security and administrative access.

Setup and Configuration

This feature dictates backend access and requires a high-level administrator to set it up initially.

Admin Side: Administrators must have the pre-defined System Administrator (Primary) role, or equivalent high-level permissions, to create new roles and assign them to other staff members.

Using this Feature

Administrators can use the following instructions to create new role templates, edit existing ones, assign granular permissions, and apply these roles to administrative staff.

Creating a New Role

  1. Click System Configuration, then Admin Management, and click Manage Roles.

  2. Click the Add New Role button at the bottom of the page.

  3. Enter a descriptive name in the Role Name field and provide a detailed summary in the Description field.

  4. Click the Save Role button to save the new role template.

Editing an Existing Role

  1. Click the Edit Role button next to the specific role you wish to update on the Manage Administrator Roles screen.

  2. Make the desired changes to the Role Name and Description fields.

  3. Click the Save Role button to save your edits.

Assigning Permissions to a Role

  1. Click the Permissions button next to the role you want to configure to open the Editing Permissions screen.

  2. Click a specific module icon (e.g., Permit, Violations) from the top bar to display the permissions available within that category.

  3. Enable the checkbox next to a permission's name to grant that specific access level to the role.

  4. Click the Save Permissions button once you have navigated through each icon and selected all necessary permissions.

Assigning Roles to Admin Users

  1. Click System Configuration, then Admin Management, and click Edit Admin Users to open the Manage Active Administrators page.

  2. Select an existing user you wish to modify, or choose to create a new user.

  3. Add or confirm the details in the User Information section on the left side of the screen.

  4. Select the specific role or roles you wish to apply to the user from the available options on the right side.

  5. Enter any relevant notes about the user's role or status in the Comment field.

  6. Click the Update User button to finalize the changes.

On the Editing Permissions screen, the top bar displays various icons mirroring the system menu structure. The number next to each icon indicates exactly how many permissions within that category have been selected for the current role. Additionally, the role description will appear as a helpful rollover tooltip when you mouse over the Edit Role button.

Available Actions and Buttons


Best Practices and Considerations

Manage Administrator Groups

    The Administrator Groups feature allows organizations to organize backend users into logical teams or departments. Its primary purpose is to simplify system management by enabling you to apply specific settings, distribute communications, or assign tasks to a collective group rather than managing each user individually. This article is intended for OPS-COM administrators responsible for managing system access and administrative organization.

    Setup and Configuration

    This feature requires high-level administrative access to configure groups and assign users to them.

    Admin Side: Administrators must have the appropriate system role permissions to access the admin management tools, create groups, and edit administrator profiles.

    Using this Feature

    Administrators can use the following instructions to create new groups, edit existing ones, and assign administrative staff to specific teams.

    Creating a New Administrator Group

    1. Hover over System Configuration and click Admin Management then Manage Groups.

    2. Choose the specific tab for the type of group you want to add.

    3. Click the Add New button to open the group definition form.

    4. Enter the required information into the provided fields, such as the Group Name.

    5. Click the Save Group button to finalize the creation.

    Initially, the Manage Administrator Groups page may be empty if your organization has not configured any teams. Once saved, your newly created group will immediately appear in the list on the left-hand side of the page.

    Assigning Administrators to Groups

    Administrators are assigned to groups directly through their individual user profiles.

    1. Hover over System Configuration and click Admin Management then Edit Admin Users.

    2. Select the specific administrator profile you wish to modify.

    3. Select the appropriate team from the Admin Groups field within their profile settings to assign them to one or more groups.

    4. Save the profile changes.

    Available Actions and Buttons


    Best Practices and Considerations

    Manage Admin User Accounts

    The Manage Admin User Accounts feature provides the tools necessary to create, modify, and disable administrator profiles within the system. Its primary purpose is to grant secure backend access to staff, define their specific responsibilities through assigned roles, and maintain accurate historical records of administrative actions. This article is intended for OPS-COM administrators responsible for managing system security and personnel access.

    Setup and Configuration

    This feature requires high-level administrative access to properly configure and manage other user accounts.

    Admin Side: Administrators must have the appropriate system role permissions enabled to access the admin management tools. Multi-factor Authentication (MFA) is strictly required for all administrative accounts to ensure system security.

    Using this Feature

    Administrators can use the following instructions to create new admin accounts, edit existing profiles, reset passwords, view activity logs, and disable departing staff.

    Creating a New Admin Account

    1. Hover over System Configuration, click Admin Management, then Edit Admin Users to access the Manage Active Administrators screen.

    2. Click the + Create New Admin button.

    3. Enter the required user information (e.g., username, first name, last name, email, and initial password) into the fields on the left side of the screen.

    4. Select the specific admin role or roles this person will be granted from the Active Roles form on the right side of the screen. Further details can be found on the Manage Roles and Permissions page.

    5. Click the Insert New User button to add the admin account to the system.

    Multi-factor Authentication (MFA) is now required when creating an Admin account. After the account is created, the user must first access it through the Admin portal before attempting to sign in on a handheld device. During their initial login, a One-Time Password (OTP) will be sent to their email, and they will be prompted to set up their credentials. For more details, refer to the MFA wiki article.

    Editing an Existing Admin Account

    1. Hover over System Configuration, click Admin Management, then Edit Admin Users.

    2. Select the specific user you wish to modify from the active list.

    3. Modify the available options for that selected user, including their personal information, roles, and account status.

    4. Click the Update User button to save your changes.

    Resetting an Admin's Password

    1. Select the specific administrator's account from the Manage Active Administrators screen.

    2. Enter a new, temporary password directly into the Password field. The password is hidden (displayed as asterisks), but you can simply type over the existing symbols.

    3. Click the Update User button.

    4. Inform the admin of this temporary password so they can log in and be prompted to update it to a personal, secure password.

    Disabling an Admin Account

    1. Hover over System Configuration, click Admin Management, then Edit Admin Users.

    2. Select the specific user's account you wish to disable.

    3. Disable the Activate this account and allow system login checkbox located in their profile.

    4. Click the Update User button to apply the change and move the account to the disabled list.

    Admin users cannot be permanently deleted from the system because their accounts are permanently linked to historical data (e.g., ticket issuance, system changes). When disabling an account, you must leave the admin user's permissions in place. These permissions affect historical reporting, verifying which access levels were active at the time certain actions were performed.

    Viewing Login Activity

    1. Select a specific administrator's account.

    2. Click the Login Activity button to view a detailed history log.

    Key Information Displayed: The activity log tracks when the administrator last logged into the OPS-COM backend or a handheld device. It also records critical actions, including log outs, new incident creations, and when an incident was marked as opened or closed.

    Available Actions and Buttons


    Best Practices and Considerations


    IP Filtering for Admin Users

    The IP Filtering feature provides a robust security layer by restricting backend access based on a user's specific Internet Protocol (IP) address. Its primary purpose is to enhance system security by ensuring that only authorized users from specified networks or devices can log into the system. This article is intended for OPS-COM administrators responsible for managing backend security and staff access controls.

    Setup and Configuration

    IP filtering configurations are managed directly within each administrator's user profile.

    Admin Side: Administrators must navigate to the active administrators list to modify the allowed IPs for specific staff members.

    Using this Feature

    Administrators can use the following instructions to apply specific IP filtering rules to an admin user's profile.

    Configuring IP Filters

    1. Hover over System Configuration, then Admin Management, and click Edit Admin Users.

    2. Select the specific user you wish to edit from the Manage Active Administrators page.

    3. Locate the Allowed IPs field within the user's profile configuration.

    4. Enter the appropriate IP filtering rule into the field based on the desired access level.

    5. Save the user profile to apply the security changes.

    An IP address typically consists of four groups of numbers (octets) separated by dots. The first two octets generally identify the network, while the last two identify the specific machine. To find your current public IP address, use a search engine to search for "What is My IP".

    Configuration Options for Allowed IP Addresses

    You can precisely tailor the level of access by entering specific formats into the Allowed IPs field:

    Do not use wildcards (e.g., 10.*) or domain names (e.g., OPSCOM.com) in the filtering field. Only numerical IP addresses and the single dot operator are supported for configuring access.


    Best Practices and Considerations