Accounts
Accounts Overview
An Account is a user with designated privileges that manages filtered clients in their group. Usually this person has some authority over the other users such as a teacher over a class of students, a manager over a group of workers, or a parent over a family. There are a variety of accounts available for delegating filtering administration.
Delegated Administration Overview
This document looks at how to prepare your system to be administered by a hierarchical management team.
The Master Admin is often an IT team member who may be closely involved in managing hardware and software issues, but not involved in managing filtering policies. In many cases, particularly those governing more than a dozen or so users, this technical person will delegate policy management to others, using one of the three account classes
These are:
· General Admins, who have permission-based access to manage the system.
· SysOps (System Operators), who have specific permissions to manage filtering for assigned groups
· Users who are members of a filtered group or accounts and may be assigned permission to manage some aspects of filtering for their group or accounts. This could be a teacher of a group of students. A user account can be assigned to a customer that belongs to a single group (large or small) with a single Deny List Policy. Users can add URLs to the local Allow and Deny Lists and can access activated Quick Reports through the WebAdmin.
Account Types
Master Admin Account
The Master Admin account (there can only be one master Admin) is a special permanent account designed for the head Netsweeper Server administrator. Typically, this is the person in charge of maintaining the server and managing the accounts of other administrators. This account has access to all administrative functions.
The Master Admin can delegate management of Groups, Policies, Clients, Accounts, Categories, Administration Settings, Tools, Directory Synchronization Reports, Lists, and some settings and logs to General Administrators and SysOps. General administrators and/or SysOps can also assign a user account to a customer that belongs to a single group (large or small) with a single Deny List Policy.
When creating an Account, there are three possible Classifications: Admin, SysOp, and User. A Master Admin and a General Admin can create all three.
A SysOp can create another SysOp or User if granted Account Management permissions. A User cannot create another Account.
General Admin Accounts
Admin Accounts are for regular administrators who manage one or more groups of users. These Accounts can be permissioned to manage all the WebAdmin features and configuration settings.
SysOp Accounts
The level of access that SysOps Accounts possess depends on the individual SysOps permission settings. SysOps can only report on Groups and Clients assigned to their account.
Hierarchy of SysOp Permissions
SysOps can create other SysOp Accounts and those SysOp Account can also create SysOp Accounts. SysOp permissions can only be modified up to the level of its parent’s permissions.
With the required permissions, SysOps can grant permissions to SysOps they have created. Permissions, not granted to a SysOp, are hidden from their view.
Applying an Account Template to an Account
Account Templates can be assigned to SysOp and Admin Accounts when creating or editing the Account. You can add one or more Templates and they can be assigned in priority order. The top Template in the list will take precedent over the ones further down the list.
User Accounts
User accounts are not intended for administration and reporting in the WebAdmin. They must be linked to a specific group to access quick reports for that group only. User accounts cannot access any other groups or clients other than themselves and cannot create Custom Reports.
In most Netsweeper deployments, user accounts are not used to access the WebAdmin or the Reporter directly.
For more information, please see the document User Guide – Managing Filtering with a WebAdmin User Account.
There are two types of user accounts:
· One uses a special WebAdmin interface to manage the local URL Allow and Deny lists of one group with one Deny List policy.
· The other type uses the Profile Manager interface to manage local filtering for a small group of filtering profiles.
· Each profile may be used either by an individual or a group of similar individuals.
Whether you are using the WebAdmin interface, or the Profile Manager interface, will depend on your deployment and filtering architecture.
The Client Filter is deployed differently, depending on whether filtering will be managed solely by the WebAdmin or by the Profile Manager. See the Client Filter documentation for more information.
User Restrictions
Permissions: User who uses the WebAdmin
A user is typically assigned to only one group with only one Deny List policy.
|
Permission Set |
A user that manages one group with oneDeny Listpolicy with the WebAdmin |
|
Policies |
Cannot access the Policy tools. |
|
Accounts |
Cannot access the Accounts tools. |
|
Categories |
Can manage the local CategoryDeny Listand URL/Keyword Allow and Deny lists for his or her own group |
|
Administration |
Cannot access any Administration Tools. |
|
Monitoring |
Cannot access any Monitoring tools. |
|
Reports |
Can only access activated Quick Reports if the User has been assigned to Manage a Group. |
|
Logs |
Cannot access any logs. |
|
Category Alerts |
Can only access the Category Alert tool, which is on a menu called Filtering Options on the user’s WebAdmin interface |
|
Your Account |
Can only change the account password and interface language |
Permissions: User who uses the Profile Manager
|
Permission Set |
A user who manages one small group of profiles |
|
Policies |
Sets local policy by creating filtering profiles for members of the small group |
|
Accounts |
Not applicable |
|
Categories |
Manages the Category list and URL/Keyword Allow and Deny lists for his or her profiles |
|
Administration |
Not applicable |
|
Monitoring |
Not applicable |
|
Reports |
Can access activated Quick Reports |
|
Logs |
Cannot access any logs |
|
Category Alerts |
Can access the Category Alert tool |
|
Your Account |
Can change all profile passwords and the account password |
|
Dashboard |
Not applicable |
Create Account Group Policy
User Accounts must be linked to a specific group to access Quick Reports for that Group only. When creating a User or SysOp Account, you should always choose ‘Create account group policy’ if you want these options.
If this is not selected only the Filtering Options and Your Account Options will display when the User logs in.
If this option is selected, Category Settings and Reports menu options will also be available.
Change Password on Login
If the 'Change password on login' is checked, regardless of password enforcement settings, the user must change their password before accessing the WebAdmin.
When the user logs in, the menu is not displayed until the password has been changed.










