:00Thu 24 Sep
Access control
About access control
Roles are sets of actions. People and Teams hold them through grants on a scope: the site, an area or a rack.
A saved role changes what the server allows from the next request.
5 roles · 63 actions
Only one active administrator
If Eszter Szabó is locked out, only the recovery code helps.
How access works here
- Step-up on every security action: roles, grants, badges, passcodes, Recovery mode. The passcode is asked again, every time.
- 1 active administrator: Eszter Szabó. The last one can’t be deactivated or demoted.
- Approvals are off by default. A preset switches them per action and scope: Policies.
- Recovery code: held sealed by the site; vendor staff never hold it. Recovery.
- Technician account · Dávid Horváth · DanutekPasscode · named account set up at install
Commissioning on the siteAlways-on · trialSigned in 14:04 · laptop at SR-02 - Superadmin · Perpixel · vendor L3RSA key · only the public key is installed · SHA256:9f3c…a17e
Every action; never a role a site assignsAlways-on · trialNever on this site
Technical details
- What they are
- Named and audited principals: not site users and not a shared login
- While R1 is trialled
- Always on, every action logged; suspending or revoking support comes after the trial
- Sources
- Neo 0040 §3 · 0044 §2 · REQ-222