Admin Management Tools Accessed from the System Configuration menu, this is where you create/edit roles and permission as well as Admin User Accounts. Manage Roles and Permissions The Roles and Permissions feature provides granular control over what administrative users can access and do within the system. Its primary purpose is to allow administrators to define specific responsibilities, enhance security, and streamline operations by ensuring users only have appropriate access levels. This article is intended for OPS-COM administrators responsible for managing backend system security and administrative access. Setup and Configuration This feature dictates backend access and requires a high-level administrator to set it up initially. Admin Side: Administrators must have the pre-defined System Administrator (Primary) role, or equivalent high-level permissions, to create new roles and assign them to other staff members. Using this Feature Administrators can use the following instructions to create new role templates, edit existing ones, assign granular permissions, and apply these roles to administrative staff. Creating a New Role Click System Configuration , then Admin Management , and click Manage Roles . Click the Add New Role button at the bottom of the page. Enter a descriptive name in the Role Name field and provide a detailed summary in the Description field. Click the Save Role button to save the new role template. Editing an Existing Role Click the Edit Role button next to the specific role you wish to update on the Manage Administrator Roles screen. Make the desired changes to the Role Name and Description fields. Click the Save Role button to save your edits. Assigning Permissions to a Role Click the Permissions button next to the role you want to configure to open the Editing Permissions screen. Click a specific module icon (e.g., Permit, Violations) from the top bar to display the permissions available within that category. Enable the checkbox next to a permission's name to grant that specific access level to the role. Click the Save Permissions button once you have navigated through each icon and selected all necessary permissions. Assigning Roles to Admin Users Click System Configuration , then Admin Management , and click Edit Admin Users to open the Manage Active Administrators page. Select an existing user you wish to modify, or choose to create a new user. Add or confirm the details in the User Information section on the left side of the screen. Select the specific role or roles you wish to apply to the user from the available options on the right side. Enter any relevant notes about the user's role or status in the Comment field. Click the Update User button to finalize the changes. On the Editing Permissions screen, the top bar displays various icons mirroring the system menu structure. The number next to each icon indicates exactly how many permissions within that category have been selected for the current role. Additionally, the role description will appear as a helpful rollover tooltip when you mouse over the Edit Role button. Available Actions and Buttons Add New Role: Click this button at the bottom of the management page to create a new, blank role template. Edit Role: Click this button next to an existing role to modify its name or description. Note that the primary System Administrator role cannot be edited. Permissions: Click this button next to a role to open the granular matrix where individual system actions are enabled or disabled. Save Permissions: Click this button to finalize the selected access levels for a given role. Update User: Click this button to save any changes made to a specific administrator's profile, including their newly assigned roles. Best Practices and Considerations Adhere to the principle of least privilege: Always grant users only the permissions absolutely necessary for them to perform their job functions. This minimizes security risks and reduces the potential for accidental system errors. Utilize role-based access control: Instead of assigning individual permissions to each user manually, create template roles (e.g., "Enforcement Officer," "Finance Admin") and assign users to those templates. This significantly simplifies onboarding, offboarding, and security auditing. Maintain clear role descriptions: Use the role description field to clearly state the purpose of the role and the types of permissions it encompasses. This helps other administrators quickly understand what each role is intended for without having to open the complex permissions matrix. Conduct regular access reviews: Periodically review your defined roles and user assignments to ensure they remain appropriate. Adjust roles as job responsibilities change or as staff members join or leave your organization. Test new roles before deployment: Always test a new role with a dummy administrator account before deploying it to active users. This confirms that the assigned permissions function exactly as expected and do not inadvertently grant too much or too little backend access. Manage Administrator Groups The Administrator Groups feature allows organizations to organize backend users into logical teams or departments. Its primary purpose is to simplify system management by enabling you to apply specific settings, distribute communications, or assign tasks to a collective group rather than managing each user individually. This article is intended for OPS-COM administrators responsible for managing system access and administrative organization. Setup and Configuration This feature requires high-level administrative access to configure groups and assign users to them. Admin Side: Administrators must have the appropriate system role permissions to access the admin management tools, create groups, and edit administrator profiles. Using this Feature Administrators can use the following instructions to create new groups, edit existing ones, and assign administrative staff to specific teams. Creating a New Administrator Group Hover over System Configuration and click Admin Management then Manage Groups . Choose the specific tab for the type of group you want to add. Click the Add New button to open the group definition form. Enter the required information into the provided fields, such as the Group Name . Click the Save Group button to finalize the creation. Initially, the Manage Administrator Groups page may be empty if your organization has not configured any teams. Once saved, your newly created group will immediately appear in the list on the left-hand side of the page. Assigning Administrators to Groups Administrators are assigned to groups directly through their individual user profiles. Hover over System Configuration and click Admin Management then Edit Admin Users . Select the specific administrator profile you wish to modify. Select the appropriate team from the Admin Groups field within their profile settings to assign them to one or more groups. Save the profile changes. Available Actions and Buttons Add New: Click this button to open the form for creating a brand new administrator group. Edit: Click this button next to an existing group in the list to modify its name or associated settings. Save Group: Click this button to commit a newly created or modified group to the system database. Delete: Click this button to permanently remove a group that is no longer needed. Best Practices and Considerations Maintain logical organization: Create groups that reflect your actual organizational structure (e.g., "Enforcement Team," "Permit Office Staff," "IT Support"). Aligning system groups with real-world departments makes it significantly easier to manage permissions, communicate, and assign responsibilities across the platform. Use clear and concise naming conventions: Always use descriptive names for your groups to avoid confusion among administrators. Clear naming ensures that when assigning a user or sending a system-wide message, the target audience is immediately obvious. Conduct regular group reviews: Periodically review your Administrator Groups to ensure they remain relevant. Remove any outdated or unused groups to maintain a clean system and prevent users from being accidentally assigned to defunct operational teams. Understand deletion impacts: Be aware that deleting a group might impact any administrators or system settings currently associated with it. Always verify group membership and reassign active staff before confirming a deletion. Manage Admin User Accounts The Manage Admin User Accounts feature provides the tools necessary to create, modify, and disable administrator profiles within the system. Its primary purpose is to grant secure backend access to staff, define their specific responsibilities through assigned roles, and maintain accurate historical records of administrative actions. This article is intended for OPS-COM administrators responsible for managing system security and personnel access. Setup and Configuration This feature requires high-level administrative access to properly configure and manage other user accounts. Admin Side: Administrators must have the appropriate system role permissions enabled to access the admin management tools. Multi-factor Authentication (MFA) is strictly required for all administrative accounts to ensure system security. Using this Feature Administrators can use the following instructions to create new admin accounts, edit existing profiles, reset passwords, view activity logs, and disable departing staff. Creating a New Admin Account Hover over System Configuration , click Admin Management , then Edit Admin Users to access the Manage Active Administrators screen. Click the + Create New Admin button. Enter the required user information (e.g., username, first name, last name, email, and initial password) into the fields on the left side of the screen. Select the specific admin role or roles this person will be granted from the Active Roles form on the right side of the screen. Further details can be found on the Manage Roles and Permissions page. Click the Insert New User button to add the admin account to the system. Multi-factor Authentication (MFA) is now required when creating an Admin account. After the account is created, the user must first access it through the Admin portal before attempting to sign in on a handheld device. During their initial login, a One-Time Password (OTP) will be sent to their email, and they will be prompted to set up their credentials. For more details, refer to the MFA wiki article. Editing an Existing Admin Account Hover over System Configuration , click Admin Management , then Edit Admin Users . Select the specific user you wish to modify from the active list. Modify the available options for that selected user, including their personal information, roles, and account status. Click the Update User button to save your changes. Resetting an Admin's Password Select the specific administrator's account from the Manage Active Administrators screen. Enter a new, temporary password directly into the Password field. The password is hidden (displayed as asterisks), but you can simply type over the existing symbols. Click the Update User button. Inform the admin of this temporary password so they can log in and be prompted to update it to a personal, secure password. Disabling an Admin Account Hover over System Configuration , click Admin Management , then Edit Admin Users . Select the specific user's account you wish to disable. Disable the Activate this account and allow system login checkbox located in their profile. Click the Update User button to apply the change and move the account to the disabled list. Admin users cannot be permanently deleted from the system because their accounts are permanently linked to historical data (e.g., ticket issuance, system changes). When disabling an account, you must leave the admin user's permissions in place . These permissions affect historical reporting, verifying which access levels were active at the time certain actions were performed. Viewing Login Activity Select a specific administrator's account. Click the Login Activity button to view a detailed history log. Key Information Displayed: The activity log tracks when the administrator last logged into the OPS-COM backend or a handheld device. It also records critical actions, including log outs, new incident creations, and when an incident was marked as opened or closed. Available Actions and Buttons + Create New Admin: Click this button to open a blank profile form for onboarding a new staff member. Insert New User: Click this button to finalize the creation of a new administrator profile. Update User: Click this button to save any modifications made to an existing account. Login Activity: Click this button on a user's profile to open a historical log of their system access and major actions. View Disabled: Click this link on the main management screen to view the list of deactivated accounts. You can reverse a deactivation at any time by editing a disabled user and re-enabling their login checkbox. Best Practices and Considerations Use secure initial passwords: When creating new accounts or resetting passwords, use strong, temporary passwords and instruct users to change them immediately upon their first login. Enforce role-based access: Always assign granular, appropriate roles to admin users. Avoid giving out Primary Administrator access unless absolutely necessary. Granular roles ensure users only have access to the functions they strictly need for their daily duties. Disable accounts promptly: Disable accounts immediately when an employee's role changes or they leave the organization. Prompt deactivation is a critical security measure to prevent unauthorized access. Audit login activity: Regularly review the Login Activity for your admin accounts to monitor for unusual patterns or unauthorized access attempts. Proactive monitoring helps secure your organization's backend data. Maintain clear internal documentation: Maintain internal records of your admin accounts, their assigned roles, and any specific notes. This is especially important for disabled accounts to provide context for future administrators or security audits. Related Videos IP Filtering for Admin Users The IP Filtering feature provides a robust security layer by restricting backend access based on a user's specific Internet Protocol (IP) address. Its primary purpose is to enhance system security by ensuring that only authorized users from specified networks or devices can log into the system. This article is intended for OPS-COM administrators responsible for managing backend security and staff access controls. Setup and Configuration IP filtering configurations are managed directly within each administrator's user profile. Admin Side: Administrators must navigate to the active administrators list to modify the allowed IPs for specific staff members. Using this Feature Administrators can use the following instructions to apply specific IP filtering rules to an admin user's profile. Configuring IP Filters Hover over System Configuration , then Admin Management , and click Edit Admin Users . Select the specific user you wish to edit from the Manage Active Administrators page. Locate the Allowed IPs field within the user's profile configuration. Enter the appropriate IP filtering rule into the field based on the desired access level. Save the user profile to apply the security changes. An IP address typically consists of four groups of numbers (octets) separated by dots. The first two octets generally identify the network, while the last two identify the specific machine. To find your current public IP address, use a search engine to search for "What is My IP". Configuration Options for Allowed IP Addresses You can precisely tailor the level of access by entering specific formats into the Allowed IPs field: Allow Access from Any Network: Enter a single dot (.) to allow the user to log in from literally any network location. This is the least restrictive option and is typically used for managers who travel or work remotely. Restrict Access to a Specific Network: Enter the first two octets of the network's IP address (e.g., 10.32). The user can log in from any computer connected to that specific network, but will be restricted from accessing the system from any other network. Restrict Access to a Specific Computer: Enter the full IP address of the specific computer (e.g., 10.32.1.144). The user can only log in from that single, specified machine. This is the most restrictive option. Allow Access from Multiple Specific Computers: Enter the full IP address of each allowed computer, placing each address on a separate line within the field. Allow Access from Multiple Specific Networks: Enter the first two octets of each allowed network, placing each network segment on a separate line within the field. Do not use wildcards (e.g., 10.*) or domain names (e.g., OPSCOM.com) in the filtering field. Only numerical IP addresses and the single dot operator are supported for configuring access. Best Practices and Considerations Balance security with flexibility: Carefully balance the need for strict security with the practical access requirements of your administrators. More restrictive settings offer higher security but may prevent staff from working remotely or from different workstations. Account for dynamic IPs: Be aware that many internet service providers assign dynamic IP addresses that change over time. If administrators access the system from external locations with dynamic IPs, using a full IP filter will frequently require manual updates, making the single dot (.) setting more practical for remote users. Update filters after network changes: If your organization's internal network IP scheme changes, you must immediately update the allowed IPs for all affected administrators. Failing to do so will unexpectedly lock your staff out of the backend system. Consider IPv6 addresses: It is generally recommended to use IPv6 addresses if your network primarily utilizes them. IPv4 addresses are becoming less common for external-facing services. Collaborate with your IT department: For complex network setups involving firewalls or VPNs, collaborate with your IT department. Ensure proper network configuration aligns with your IP filtering rules to allow necessary external access.