HP Servicecontrol Manager 3.0 User's Guide

HP Servicecontrol Manager Introduction
Users and Roles
Chapter 1
14
deleted from SCM. All other roles can be enabled, disabled, or deleted. If you don’t want
a user to have access to all available tools for a specific node or node group, they should
not be authorized for the master role on that node or node group.
CAUTION A user assigned the master role on the CMS can execute commands as any user.
Therefore, this user could grant trusted user privilege to himself.
Trusted User
A trusted user is a user who has been given a special privilege to administer the SCM
software. Trusted users manage:
authorizations
nodes
node groups
•users
roles
tools
In addition, trusted users maintain and backup the repository and monitor the SCM
audit log.
By default, root on the CMS is assigned the trusted user privilege, but this privilege can
later be revoked. The trusted user privilege can be given to one or more users, and SCM
requires that at least one user is a trusted user. A trusted user is not automatically
authorized to execute tools. Trusted users must be authorized for roles on specific nodes
or node groups just like any other user.