Skip to main content

User groups

Each user group can contain both users and other user groups. Users and groups can be members of multiple groups at the same time. User groups are mainly used for bulk management of user permissions, in which permissions are granted to the entire group at once (rather than to each user individually).

You can manage user groups in Administration - Groups.

When importing users from Microsoft Entra ID, user groups are also imported, so you can use Entra-defined groups to manage permissions in Alvao.

System groups

System groups are built-in groups in Alvao. Each system group represents a user role with certain permission in Alvao. By putting a user in a system group you assign the role to the user.

Core

GroupDescription

Administrators

Users in this group have access to the Alvao system administration.

Configuration administrators

Users in this group have access to the following agendas in Alvao system administration:

  • Users (except for changing membership in the Administrators group)
  • Groups (except for changing membership in the Administrators group)
  • Asset Management (all agendas)
  • Service Desk (all agendas)
  • Custom fields
  • Settings (WebApp home page, Advanced settings and Webhooks nad Settings Check only)
  • License (except changing activation key)

They can still manage all shared views in the app.

Contact administrators

Users in this group can manage people (except for changing group memberships) and organizations in Alvao WebApp - Manage.

Contact readers

Users in this group can search for all users and organizations.

They can also see the values of users' and organizations' custom fields.

Everyone

All users. This group contains all registered users and Guest users.

Insider Preview Testers

Users with access to the Insider Preview features.

Registered users

All registered users. This group contains all users except the Host user.

Team managers

Users in this group can manage their reports on the My Team page.

Asset Management

GroupDescription

Accountant

Users in this group can write inventory numbers to the IT device records.

Asset Management administrators

Users in this group have unrestricted access to all parts of the system, managing system dials and the system recycle bin.

Asset Management readers

Users in this group have read-level access to IT device records, software licenses, software auditing, and scans.

Asset managers

Users in this group have unrestricted access to IT device records. The asset manager can change the object type only for computers and only to a different type of computer.

Object property administrators

Users in this group can edit the values of object properties.

Object property readers

Users in this group can see object properties and their values.

Object relation managers

Users in this group can manage relations for all objects regardless of object permissions (but they cannot read values of their properties unless they have permissions to do that).

Object relation readers

Users in this group can see all object relations. (But cannot see values of objects they do not have permissions for.)

PC software managers

Users in this group may be notified of missing software licenses.

Software and hardware scan managers

Users in this group can manage software and hardware scans on computers and manage a library of software products. Only this group (with AM administrators) can see unrecognized registry entries.

Software licenses managers

Users in this group have unrestricted access to software license registry and software auditing by default. They manage software products. If licenses for multiple organizations are recorded separately, then permissions are not tied to membership in this group, but to the permissions set in software license security.

Software profiles managers

Users in this group can create and edit software profiles of computers for ALVAO Asset Management.

Service Desk

GroupDescription

Administrator of knowledge base root

Users in this group can manage articles in the knowledge base that are not included in any service. To do so, they do not need to be members of the management team of any service.

Creators of tickets on behalf of other users

Users in this group can create tickets for other users from the same organization. They can fill in the Requested for field on the ticket creation form.

People reporting time

Users in this group can report their time to tickets.

Service administrators

Users in this group can manage services, SLAs, processes, and uptime.