User Roles and Permissions
Overview
AppsAnywhere provides the ability to assign differing user roles to grant different levels of access to both the Portal, Admin pages and Analytics.
Roles are assigned when Importing directory entities and/or Creating SAML Attribute Mappings.
AppsAnywhere Roles
The following roles are available to provide users or groups with the appropriate level of access to AppsAnywhere.
It is recommended to create a directory security group for each of the available roles, and to add the relevant users to those AD groups.
Role | Permissions |
---|---|
User | Access to log in to AppsAnywhere and launch apps (subject to any provision or app restrictions) |
Reporter | Same privileges as the User role, with the addition of access to Reporter. |
App Admin | Same privileges as the Reporter role, with the addition of access to Admin. |
System Admin | Same privileges as the App Admin role, with the added ability to configure system settings. |
Global Admin | This role is reserved for AppsAnywhere Support as global system changes need to be approved to ensure service continuity. |
Recommended directory groups:
Group | Role |
---|---|
AA_SysAdmins | System Admin |
AA_AppAdmins | App Admin |
AA_All_Users | User |
Other groups can be imported for Provisioning applications to users.
Analytics Roles
The following roles are only available for AppsAnywhere Analytics.
Only users can be granted the role of Analytics User or Explorer. These roles cannot be assigned to groups.
If AppsAnywhere admin rights have been granted to a user, rather than a group, assigning an Analytics Role will remove admin rights.
Ensure admin rights are granted via a directory security group prior to assigning an Analytics role.
Role | Permissions |
---|---|
Analytics User | Access to log in to AppsAnywhere Analytics and to view dashboards. |
Analytics Explorer | Same privileges as the Analytics User role, with the addition of access to Explorer. |
A default license for AppsAnywhere Analytics includes access for up to 5 users, of which 2 users can be set as Explorer users.