PI Nexus+ / Reference
Roles and Permissions
This reference lists what each PI Nexus+ role may do, how roles are assigned, and how to recover Admin access. The same checks apply in the web interface and in the API.
Overview
This reference lists what each PI Nexus+ role may do, how roles are assigned, and how to recover Admin access. The same checks apply in the web interface and in the API.
Roles
| Role | Includes | Meant for |
|---|---|---|
| Viewer | Read-only users | |
| Operator | Viewer | Engineers who scan, export and work on issues |
| Admin | Operator, Viewer | Administrators who configure PI Nexus+ and run destructive maintenance |
A user's roles are the union of all enabled mappings whose Windows or AD group the user belongs to. The Access card on Admin > Security shows the result as View, Scan, Export and Admin. A signed-in user without any mapped role has no access to PI Nexus+ pages.
What each role may do
| Action | Viewer | Operator | Admin |
|---|---|---|---|
| Dashboard, Monitoring, Servers, Issues, inventory pages, detail dialogs, dependency graphs, change history | Yes | Yes | Yes |
| View analysis recalculation runs, suggestions and scheduled plans | Yes | Yes | Yes |
| Scanning page: history, targets, queue | Yes | Yes | |
| Start, cancel, promote or retry scans and health refreshes; Check health; Update now | Yes | Yes | |
| CSV exports | Yes | Yes | |
| Suppress and restore issues; acknowledge host issues | Yes | Yes | |
| Create, start and retry analysis recalculations, including Recalculate dependent analyses; dismiss suggestions | Yes | Yes | |
| Create, edit, pause, run and delete scheduled recalculation plans | Yes | Yes | |
| Compression Tuning (runs, plans, applying and restoring) | Yes | ||
| Declare or remove point source declarations | Yes | ||
| Confirm a sent recalculation, confirm a native-outcome review, delete recalculation history | Yes | ||
| Recover a stuck scan | Yes | ||
| Map PI Interface runtime signals (Monitoring setup) | Yes | ||
| Every page of the Admin area, including Scan Automation, Notifications, Security, Support, SQL Server, License and Inventory Maintenance | Yes | ||
| Background job dashboard | Yes |
Recalculation additionally needs the database permission (see AF Server Settings), the license and native PI rights. A PI Nexus+ role never changes PI security.
Role mappings
| Field | Values |
|---|---|
| Role | Viewer, Operator, Admin |
| Windows / AD Group | DOMAIN\Group, up to 256 characters |
| Enabled | Ticked: applies at once. Cleared: the mapping is kept but ignored |
| Rule | Behavior |
|---|---|
| Bootstrap Admin | While no enabled Admin mapping exists, members of the local Administrators group on the web server are Admins. Bootstrap Admin shows Active |
| Last Admin mapping | Disabling, changing or removing the last enabled Admin mapping is refused |
| Group names | Leading and trailing spaces and doubled backslashes are removed |
| Current User column | Shows whether the signed-in user is in the mapped group |
Recover Admin access
Use this when no Admin can open the Security page, for example after the Admin group was renamed or removed in AD.
| Item | Value |
|---|---|
| Script | C:\Program Files\Software Athlete\PI Nexus+\Admin\Recover-AdminAccess.bat (runs Recover-AdminAccess.ps1) |
| Run as | A Windows account that can update the PI Nexus+ database |
-AdminGroup | Required. The new Admin group as DOMAIN\GroupName |
-SqlServer, -Database | Optional. Default: read from C:\ProgramData\Software Athlete\PI Nexus+\bootstrap.json |
-DisableOtherAdminMappings | Optional. Disables all other Admin mappings |
-WhatIf | Optional. Shows the change without making it |
Security page tabs
| Tab | Shows |
|---|---|
| Role Mappings | Role, group, status, whether the current user is in the group, last update |
| Security Health | Status, paths checked, broad write principals and missing paths of the folders and files PI Nexus+ protects |
| Security Audit | Time, actor, action, result and target of admin, scan, export and support actions; warnings and failures of the last 7 days; filter by severity |
