Storage access roles for NetApp Console local deployment
You can assign the following roles to users to provide them access to the storage management features in NetApp Console local deployment. You can assign users an administrative role to manage storage or a viewer role for monitoring.
Administrators can assign storage roles to users for the following storage resources and features:
Storage resources:
-
On-premises ONTAP clusters
Console services and features:
-
Storage health functions
XYZ Corporation, a multinational company, has a large team of storage engineers and storage administrators. They allow this team to manage storage assets for their regions while limiting access to core Console local deployment tasks like user management and license management.
Within a team of 12, two users are given the Storage viewer role which allows them to monitor the storage resources associated with the Console local deployment fleets they are assigned to. The remaining nine are given the Storage admin role which includes the ability to manage software updates, access ONTAP System Manager through the Console local deployment, as well as discover storage resources (add systems). One person on the team is given the System health specialist role so they can manage the health of the storage resources in their region, but not modify or delete any systems. This person can also perform software updates on the storage resources for fleets they are assigned.
The organization has two additional users with the Organization admin role who can manage all aspects of the Console local deployment, including user management and license management, as well as several users with the Folder or fleet admin role who can perform Console local deployment administration tasks for the folders and fleets they are assigned to.
The following table shows the actions each storage role performs.
| Feature and action | Storage admin | System health specialist | Storage viewer |
|---|---|---|---|
Storage Management: |
|||
Discover new resources (add systems) |
Yes |
Yes |
No |
View added systems |
Yes |
Yes |
No |
Delete systems from the Console |
Yes |
No |
No |
Modify systems |
Yes |
No |
No |
System manager access |
|||
May enter credentials |
Yes |
Yes |
No |