Skip to content

Delegated Administration

Smart companies are paying increasing attention to secure internal management practices. With this in mind, Don wants to ensure that users with access to Gateway Administrator have access to only those features and servers they need to do their Job. For this, he will add delegated administrators and configure their access rights.

Set Up Delegated Administration

Lee is a financial analyst in Don's company. Don wants her to be able to add and edit Jobs and Transfer Sites, but does not want her to have access to Gateway Administrator system settings.

Add a File Transfer Administrator to Gateway Administrator

  1. Log into Gateway Administrator as Don.

  2. On the Users tab, click New.

  3. For UserID enter Lee.

  4. For Email address, use an arbitrary address (like Lee@demo.com). The tests that follow don't use emails.

  5. Click Specify password, then enter and confirm a password.

  6. From the Reflection Gateway group membership list, select File Transfer Administrators.

    This group provides access to Transfer Sites, Jobs, and users, but not groups or system management.

  7. Click Save.

  8. Click Logout and log in as Lee. Notice that only four tabs are available to this user: Transfer Sites, Jobs, Users, and About.

  9. Click Transfer Sites. Note that Lee does not yet have access to the site Don created. Transfer Sites can only be viewed and edited by individuals who are members of the Transfer Site and have management rights .

  10. Click Jobs. Lee can see the Jobs Don created. Transfer Site Administrators have the Manage Jobs role enabled, and every user with this role can see all configured Jobs.

  11. Click Logout.

You can use the next procedure to give Lee access to Don's Transfer Site.

Enable an additional user to Manage your Transfer Site

  1. Log into Gateway Administrator as Don.

  2. On Transfer Sites tab, select the Reports site and click Edit.

  3. Under Existing User, search for Lee and click Add.

  4. In the user list for Lee, under Permissions, click the gear icon to change it from gray (disabled) to green (enabled). This gives Lee management rights to this site.

  5. Click Save, then Logout.

  6. Log in as Lee.

  7. Click Transfer Sites. This user can now view and edit the Reports site.

  8. Click Logout.

File server groups are a feature of the Gateway Administrator that enables you to specify which file servers Gateway Administrator users have access to. Use the next procedure to see how this feature works.

Use File Sever Groups to limit access to added file servers

  1. Log into Gateway Administrator as Don.

  2. Go to System > File Server Groups > New.

  3. For File server group name enter Demo Servers.

  4. Use the File servers drop-down to add both of your file servers to this group.

  5. Add Lee as a member of this group.

  6. Click Save.

  7. Click Users and add a new user, Paul. Use an arbitrary email and specify a password.

  8. Add this user to the File Transfer Administrators group and click Save.

  9. Log out, then log in as Paul.

  10. On the Jobs tab, Paul cannot see the existing Jobs. This is because their actions require access to servers in the Demo Servers file server group, and he is not a member. If he tries to create a new Job, he sees a message telling him that he cannot create a Job because he doesn't have access to any servers.

  11. Log in as Lee to confirm that--as a member of the Demo Servers group--she can view the existing Jobs and create new Jobs using the servers in this group. Click Logout.

  12. Log in as Don. Although he is not a member of the Demo Serves group, he can view the existing Jobs and create new ones. This is because all users in the Administrators groups have access to all file servers regardless of how the file server groups are set up.

  13. While you're still logged in as Don, delete the Demo Servers group. (Go to System > File Server Groups and select the Demo Servers group and click Delete.)

    When there are no file server groups configured, all users with Manage Jobs role can create and edit Jobs using all added servers.

  14. Log out and log in again as Paul. Confirm that he can now view the existing Jobs and add new ones.