PXG 900 User's Guide - Firmware Version 4.3 - 1/9/201733Command View usersUpdate View users, Install. Troubleshoot, Configuration file save/restoreRoles and Permissions CookbookThe following are examples of how to combine permissions to create roles that make sense in your organization.The examples explain four of the default roles in the PXG. These default roles may not be a good fit for your securitypolicies; however, discussing what they allow and how the permissions work can help you in picking the rightpermissions when you create your own roles.Security AuditThis role must be able to view the various audit logs for the system as well as verify the set of users and their roles.In addition, this role must allow the user to verify the settings in the PXG. However, unlike a true administrator, userswith this role only view this information and can't change any settings. You can grant these capabilities through theView users permission. View users allows the user to view the Security tab under settings. It also lets them see all ofthe logs listed under the Audit Logs command on the Choose an Action list in the Network tab. This command isavailable when the gear icon for Power Xpert Gateway is clicked.Security AdminThis role must be able to create/delete users and roles, as well as change user passwords or other settings. Itspermissions (and capabilities) are similar to the Security audit, but with the added capabilities for useradministration. So, in addition, the following permission has been added:Manage : This lets the user not only view the current users and roles (View users is selected automaticallyuserswhen this is selected), but create, edit, and delete them as well.EngineerAn engineer must be able to control everything related to the various devices that are connected to the PXG.However, an engineer doesn't need to access any of the security or maintenance features of the PXG. Therefore,that role has the following permissions that are related to working with devices.Change settings: This setting permits the user to view Settings (which is automatically selected when Changesettings is selected). It also unlocks the various fields in the sidebar within the Network tab.Install: This lets the user add and edit devices.Configure : As the name implies, this permission allows the user to edit the list of device channels.device channelsIt also allows the user to remove a device and configure the Modbus and INCOM ports.Acknowledge alarms: The user can click the Acknowledge button and enter notes about the alarm.Minimal and Operational control: The user can issue all available device commands through the Choose anaction menu.