User Role Permissions

Each type of User account in Cove Data Protection (Cove)'s Management Console has different access to data and features.

Device Management

Action User roles who can Notes User roles who cannot
Adding Devices
  • SuperUser with Security Officer
  • SuperUser
  • Manager with Security Officer *
  • Manager *

Add new devices to the Cove Management Console Backup Dashboard.

* Managers and Managers with Security Officer permissions can only add devices using Self-Managed installation.

  • Administrator with Security Officer
  • Administrator
  • Operator with Security Officer
  • Operator
  • Supporter
Managing Devices
  • SuperUser with Security Officer
  • SuperUser
  • Manager with Security Officer
  • Manager
All features except adding devices and generating passphrases.

The following users cannot manage devices, but do have read-only access:

  • Administrator with Security Officer
  • Administrator
  • Operator with Security Officer
  • Operator
  • Supporter
Managing Microsoft 365 Domains
  • SuperUser with Security Officer
  • SuperUser *
  • Administrator with Security Officer *
  • Manager with Security Officer *
  • Operator with Security Officer *

Add, edit and delete Microsoft 365 domains to the Cove Management Console Backup Dashboard, and add new services to existing Microsoft 365 domains.

* SuperUsers, Administrators with Security Officer, Managers with Security Officer, and Operators with Security Officer permissions cannot delete Microsoft 365 services, or delete backup history.

The following users cannot manage Microsoft 365 domains, but do have read-only access:

  • Administrator
  • Manager
  • Operator
  • Supporter
Sending Remote Commands to Devices
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
Actions can be performed remotely using Remote Commands.
  • Supporter

Management Console

Action User roles who can Notes User roles who cannot
Managing Views
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter
Add or remove columns to view, move column order, and create custom views. -
Generate Passphrases
  • SuperUser with Security Officer
  • Administrator with Security Officer
  • Manager with Security Officer
  • Operator with Security Officer
Passphrases are used in place of the Encryption Key/Security Code for any device installed using the Managed installation method.
  • SuperUser
  • Administrator
  • Manager
  • Operator
  • Supporter
Export Monthly Device Statistics
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter

Export a spreadsheet (in .xlsx format) which details monthly statistics containing:

  • The selected columns in the view, or;
  • Maximum value usage.
-
Managing Profiles
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator

Add, edit and remove Backup Profiles.

Available to Resellers and End-Customers only.

The following users cannot manage API Users, but do have read-only access:

  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator

The following user do not have read-only access:

  • Supporter
Managing Retention Policies
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
Add, edit or remove custom Retention Policies.

The following users cannot manage API Users, but do have read-only access:

  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator

The following user do not have read-only access:

  • Supporter
Managing Notifications
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
Add, edit or remove email notifications for backups that have failed or completed with errors, or critical configuration changes.
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter

Data Recovery

Action User roles who can Notes User roles who cannot
Recover data in Backup Manager
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
Restore backup data directly from the Backup Manager on the device.
  • Supporter
Recover data in Recovery Console
  • SuperUser with Security Officer
  • SuperUser *
  • Administrator with Security Officer
  • Administrator *
  • Manager with Security Officer
  • Manager *
  • Operator with Security Officer
  • Operator *

Restore backup data using the Recovery Console.

* SuperUsers, Administrators, Managers, and Operators without Security Officer permissions cannot generate passphrases. If the device uses Passphrase-based encryption, these user roles will not be able to add the device to the Recovery Console. If the device uses an Encryption Key/Security Code, these user roles will be able to proceed with the recovery via Recovery Console.

  • Supporter

Continuity

Action User roles who can Notes User roles who cannot
Trigger One-Time Restore
  • SuperUser with Security Officer
  • SuperUser *
  • Manager with Security Officer
  • Manager *

Trigger an on-demand restore of data to Hyper-V, Azure, or ESXi.

* SuperUsers, and Managers without Security Officer permissions cannot generate passphrases. If the device uses Passphrase-based encryption, these user roles will not be able to trigger the One-time Restore. If the device uses an Encryption Key/Security Code, these user roles will be able to proceed with One-time Restore.

The following users cannot trigger a One-time Restore, but do have read-only access:

  • Administrator with Security Officer
  • Administrator
  • Operator with Security Officer
  • Operator
  • Supporter
Manage StandBy Image
  • SuperUser with Security Officer
  • SuperUser *
  • Manager with Security Officer
  • Manager *

Enable and edit continuous restore of data using a StandBy Image plan to Hyper-V, ESXi, or Azure.

* SuperUsers, and Managers without Security Officer permissions cannot generate passphrases. If the device uses Passphrase-based encryption, these user roles will not be able to add the device to the StandBy Image plan. If the device uses an Encryption Key/Security Code, these user roles will be able to proceed with StandBy Image.

The following users cannot enable StandBy Image, but do have read-only access:

  • Administrator with Security Officer
  • Administrator
  • Operator with Security Officer
  • Operator
  • Supporter
Manage Recovery Testing
  • SuperUser with Security Officer
  • SuperUser *
  • Manager with Security Officer
  • Manager *

Enable and edit the service to provide a screenshot as proof that data is recoverable on the device.

* SuperUsers, and Managers without Security Officer permissions cannot generate passphrases. If the device uses Passphrase-based encryption, these user roles will not be able to add the device to the Recovery Testing plan. If the device uses an Encryption Key/Security Code, these user roles will be able to proceed with Recovery Testing.

The following users cannot enable Recovery Testing, but do have read-only access:

  • Administrator with Security Officer
  • Administrator
  • Operator with Security Officer
  • Operator
  • Supporter
Manage Recovery Locations
  • SuperUser with Security Officer
  • SuperUser
Add, edit and remove the host running the recovery service used to process data restores.

The following users cannot manage API Users, but do have read-only access:

  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter

Customer Management

Action User roles who can Notes User roles who cannot
Managing Customers
  • SuperUser with Security Officer
  • SuperUser
Add, edit and remove Customer to the Cove Management Console.

The following users cannot manage API Users, but do have read-only access:

  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter
Managing Contacts
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
Add, edit and remove contact details, containing names of Customer representatives.

The following users cannot manage API Users, but do have read-only access:

  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter
Managing Contact Notes
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
Add, edit and remove information regarding past and upcoming communication activities, or relevant information regarding the Customer.

The following users cannot manage API Users, but do have read-only access:

  • Operator with Security Officer
  • Operator
  • Supporter

User Management

Action User roles who can Notes User roles who cannot
Managing Users
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
All features except for Managing Security Officers.

The following users cannot manage users, but do have read-only access:

  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter
Managing API Users
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
Add, edit and remove API users.

The following users cannot manage API Users, but do have read-only access:

  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter
Managing Security Officers
  • SuperUser with Security Officer
Enable and disable Security Officer permission for users.
  • SuperUser
  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter

Reporting

Action User roles who can Notes User roles who cannot
Manage Scheduled Reports
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter
Add, edit and remove scheduled reports on recent backup and recovery activities. -
Generate Executive Summary Reports
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator

Trigger the generation of an Executive Summary Report.

Available to Resellers only.

  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter
Download Executive Summary Reports
  • SuperUser with Security Officer
  • SuperUser
  • Administrator with Security Officer
  • Administrator

Download the generated Executive Summary Report.

Available to Resellers only.

  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter
Manage Executive Summary Reports
  • SuperUser with Security Officer
  • SuperUser

Add, edit and remove recipients for Executive Summary Reports once generation has completed.

Available to Resellers only.

  • Administrator with Security Officer
  • Administrator
  • Manager with Security Officer
  • Manager
  • Operator with Security Officer
  • Operator
  • Supporter