Password Vault Account Permissions
kron pam administrators can assign different authorization levels to different user groups or users for password vault accounts for example, a user group or a user can get full control rights for a password vault account, while another user group or another user can have list only rights to set permissions to password vault accounts navigate to secrets > vault open the vault tab select the account to set permissions for, click the options button, and select permissions select the user or user group, and the permission types in the permission lines listed on the screen, it is possible to select which user or user group will have the corresponding permissions to list the users contained in an added user group, you can click the little ℹ️ button next to the group name permission types list only to only grant the authority to see the account on the password vault read only first part to only grant the authority to see the first half of the password vault password read only second part to only grant the authority to see the second half of the password vault password read only to only grant the authority to see the password vault password manage password to only grant the authority to manage the password vault password read write to grant full control permission, except for the permissions option full control to grant full control applies to admins of this password account these users have full authority for actions such as resetting/changing the password, and giving other users permissions for operations multiple permissions can be assigned to a user group or user according to the permission levels, users will access the accounts with the highest permission, with those rights one user can be a member of multiple user groups with different rights in this case, the following permission order will apply full control > read write > manage password > read only > read only first part > read only second part > list only if authorized users are assigned to password vault management, the kron pam administrator must define the following parameter in the system configuration manager to authorize their own accounts to access other user groups parameter name parameter value sapm all usergroup seen permission true