Users and roles

A user is a sign-in account for the Nexus Telemetry Fleet dashboard. A user belongs to one organisation and has one of 4 roles. The Users page is where users are added, edited and deleted. It is open to the Owner and Admin roles only.

The Users page, one row per account with its role and group access

Roles

Role Can
Owner Everything, including billing
Admin Everything except billing: users, tokens, organisations, collectors, certificates and settings
Operator Act on terminals: rename, update, rotate a certificate, schedule maintenance, decommission and revoke
Viewer Read everything and change nothing

Billing has no interface yet, so today Owner and Admin can do the same things. Operator and Viewer cannot open the Tokens, Users and Organisations pages. See Roles and permissions for the full matrix.

First user

A new fleet server has no users, and anyone who can reach the dashboard is let in without a sign-in. The dashboard shows the banner This dashboard is open with the command that creates the first user. The command is run on the fleet server. See Command line for the command. Once a user exists, the dashboard requires a sign-in.

Users page

Users in the rail lists every user in the organisation, with User, Role, Group access, Last login and Two-factor. Last login reads Never until the user’s first sign-in. Two-factor reads On or Off. The signed-in user’s own row is marked you, and a user limited to Microsoft sign-in is marked Microsoft only. Each row has an actions menu: Edit, Reset password, Reset two-factor when the user has it on, and Delete. Organisation audit log opens the organisation’s audit trail.

New user

  1. Press Add user.
  2. Type a Username, and an Email address (optional). The user verifies the address from their account page.
  3. Choose a Role. The default is Viewer.
  4. Leave Password blank to have one generated.
  5. Press Create user.

The generated password is shown once, with a Copy password button. Store it before leaving the page.

Group access

A user can be limited to particular groups, when created or later.

  1. Open the user’s actions menu and choose Edit.
  2. Tick the groups the user may see.
  3. Press Save changes.

A user with particular groups sees only the terminals in those groups. The change applies the next time the user loads a page. A user with no group ticked sees every group, including groups added later, and the Group access column reads All groups.

Role change

Change Role in the same Edit drawer and press Save changes. The drawer also holds Microsoft sign-in only, which refuses the user’s password. See Sign-in.

A user cannot change their own role. The field is disabled with the note You cannot change your own role. An organisation always keeps at least one owner: while other users exist, the last owner cannot be given another role.

Password reset

  1. Open the user’s actions menu and choose Reset password.
  2. Press Generate new password.

The new password is shown once, with a Copy password button. The user’s old password stops working immediately and their sessions end. At their next sign-in they are asked to set a password of their own.

Two-factor reset

  1. Open the user’s actions menu and choose Reset two-factor.
  2. Press Reset two-factor in the drawer.

The user’s second factor is removed and their sessions end. Their next sign-in is the password alone. If the organisation requires two-factor authentication for their role, they set it up again at that sign-in. When no administrator can sign in, the command line does the same. See Command line.

User deletion

  1. Open the user’s actions menu and choose Delete.
  2. Press Delete user, or Keep user to cancel.

The user’s sessions end. A user cannot delete their own account, and the last owner cannot be deleted while other users exist.

Passwords and sessions

A user who signs in with a generated password is taken to Set your password at their next sign-in. A password requires at least 12 characters. Any user can change their own password later from their account page. See Sign-in for the email address, two-factor authentication and Microsoft sign-in.

Rule Detail
One session per user Signing in ends the user’s previous session
Setting a password Ends the user’s other sessions
Session length A session ends after 1 day without activity, or 7 days after sign-in, whichever is first
Fleet server restart Sessions survive it
A failed sign-in Reads Invalid username or password. and does not say which was wrong

Creating a user, changing a role, changing group access, resetting a password and deleting a user are recorded in the Audit trail.