EN
Español
English
Português
    Segment device visibility by groups

    What is segmenting device visibility by groups?

    Segmenting device visibility by groups is a data access control mechanism in ADM that complements the Roles and permissions of the application. The role defines the actions and modules that a user can use, the segmentation defines the devices and the information associated with them, which they will be able to consult within those modules.


    What is it used for?

    In organizations with large or distributed structures, segmentation allows you to delegate device management by area, site, or customer without exposing data from outside computers to each user, even when they share the same role or application permissions.


    How does it work?

    Segmentation is activated at the role level: the Manage all devices is enabled by default on all Roles, and while the user is in the same position, the user views all devices in the system without segmentation. When you disable this permission on a role and assign that role to the appropriate user group, the visibility of devices in that group is subject to segmentation.

    With targeting active for a group, it is configured in the Groups, associating devices to a group, and assigning each user group the display permissions corresponding to the segmented capabilities.

    A user will only be able to view information for a segmented feature when they have access to the related device by their group. If they are not assigned the permission, the system restricts viewing that data, even when the user’s role or application permissions will generally enable it.

    Currently, group targeting applies to the following permissions:

    Permission Description
    Remote control Actions -> Remote control.
    ADM Actions Actions -> Get Inventory
    Actions -> Update CI
    Actions -> Remove Device
    Actions -> Resolve conflicts
    More Actions -> Remove Device
    More actions -> Assign responsible user
    More actions -> Resolve conflicts
    More actions -> Update agent
    More shares -> Camb / act. Agent profile.
    Remote Administration Actions More actions -> Execute command
    More Actions -> Restart Device
    More Actions -> Turn Off Device
    More Actions -> Turn On Device
    More Actions -> Sync Clock
    More actions -> Erase file by extension
    More actions -> Send message
    Use of software Software -> Use of Software.
    Software licensing Software -> Licenses.

    Each segmented functionality applies filtering according to its own nature:

    • Use of software applies both in the Software Usage Management as in the Device Detail.
    • Software licensing applies in the Software Management and Licensing- Overall quantities (active, available, and purchased licenses) are kept consistent for all users, while assigned licenses, installations, and the list of licensed devices are filtered based on user access.


    Note: For details of permission settings by group, see Add permissions to user groups.