Reference Guide
...
Password Vault User Rights
Account & Group Creator User
the user who created it can create their own static and dynamic accounts a device realm is required when creating all accounts, except for a static strategy the kron pam admin user is the one who created the device realm each user created account and group is private to the user other user groups need permission to view and manage these accounts and groups to create a private account, the following parameters must be entered on the system config manager screen parameter name parameter value description sapm private option default value yes (default value is no) the parameter that creates the private account sapm private option hide true (default value is false) parameter that removes the private field from the sapm accounts tab creator user groups must have the following function groups function group description sapm management the main password vault function group sapm account module visibility function group that grants the authority to see the vault account tab sapm group module visibility function group that grants the authority to see the vault group tab sapm group admin can authorize the user to create an account sapm group manager can authorize the user to create a group sapm historical password viewer can authorize the user to see old password values