WiFi certification systems are often discussed most frequently in multi-branch settings such as chains, group parks."Can we get the headquarters to do it?"But the first problem to come up with when you're really online is usually another: permission. The headquarters manager, regional head of department, doorkeeper, outsourced maintenance staff, fee-payer, so many people are going to touch this system. If everyone can see full users, modify all configurations, and move all data, it's not a management tool, but rather the source of an accident."Who should see what, who can change what?"This thing.
NATSHELL_BRAD V7 Authentication & Billing supports multi-level authority management in terms of competency management, pre-positions administrators, billers, maintenance staff, collaborators, etc., and supports unlimited levels of regional management, which can also be cross-flexible in project management. The logic behind this design is that the role in the system is not one."Everyone's the same."and divided by duty, one section.
Let us first distinguish a few roles.The administrator has the highest authority to handle station-wide configuration, user-accounts; the charger can only operate the financial actions of fees, refunds and renewals, without seeing system configuration and bottom data; maintenance personnel perform troubleshooting, equipment status viewing, log queries but cannot move on account; cooperating or proxy is a separate operator who should see only the area and user operating data. The claims for these four types of players are completely different. If not separated, the charger will see the backoffice configuration of the system, the maintenance staff will be able to change accounts, and the partner will look at the details of Headquarters users, any one of which is an accident.
The blogger says that the situation is not a good one.Regional powers are harder to do than role rights.A chain hotel group runs all the doors at headquarters, but the owner of Gate A should not see B shop users. V7 supports unlimited level area management, which is to place users, equipment, and accounts by region, so managers can only use their own resources when logging in. The key here is that the regional division is designed well before going online: by large areas, by city, by door, by hierarchy, by reporting from across regions, by location of headquarters and by region.
In many chains, the door shop network is outsourced to local service providers, who have their own independent interfaces for opening accounts, charging fees and viewing their clients' data, but do not see other service providers and headquarters internal data. The agent ' s independent rights design of V7 is to allow agents to operate in separate interfaces without interference with administrators. This is particularly important for multi-agency operating models.——If all agents share a back-office and see each other's users, the customer resources are exposed.
Three things have to be decided in advance before the power system gets online.First, the list of roles.List all the roles that actually exist in the system, including temporary roles, identifying on a case-by-case basis which menus and functions it should see.Secondly, regional affiliation.Each user, each device and account belong to an area where the data model is designed before import.Thirdly, audit trails.The administrator records are kept, and the authority is checked when you change your configuration or fill it with any user."Who can do what?"♪ And the audit is..."Who did what?"And if they do, they can be closed.
And to note a common error: the tighter access is not safe. If you want to save your time, you can't even see the menu set for the bill collectors, the maintenance staff can't check the logs, and the real people who work are stuck, so we share the administrator accounts, and the permission system is empty."Every role is useful and not cross-border."Not"The less the better."。
Finally, multilevel privileges are often not the decisive factor in the WiFi certification system selection, but they are a hidden determinant of smooth operation. A chain of hundreds of shops with well-designed competencies, where headquarters, regions, doors and agents are all involved, is running water lines; if access is confused, people are present every day."Why can't I see it?"and"Why would he see it?"Up. The program phase takes one more day to set the rights model, which is much more cost-effective than a month of patching up after you're on line.
The permission model is online and also takes an evolutionary aspect: the structure changes."It's a human-preference death.", the person changes to wipe his ass with a line of weight and the area is bound by role plus two layers. Headquarters adjusts the area to the area, and all the entries below automatically change. So when designing the permission,The role and the region are best maintained separately. Don't tie two things to a person.In such organizational changes, the alignment of competencies is a one-time configuration and not a check.
A more negligible point: the fee-payer's rights and the security of accounts. In a chain situation, the charge-backer is responsible for the doorman's fees, refunds, and renewals."Can the biller run the accounts?"The accounting audit is to settle the"Is the charger working?"Both are not necessary.