Documentation PI Nexus+ Documentation

PI Nexus+ / Reference

Roles and Permissions

This reference lists what each PI Nexus+ role may do, how roles are assigned, and how to recover Admin access. The same checks apply in the web interface and in the API.

Overview

This reference lists what each PI Nexus+ role may do, how roles are assigned, and how to recover Admin access. The same checks apply in the web interface and in the API.

Roles

RoleIncludesMeant for
ViewerRead-only users
OperatorViewerEngineers who scan, export and work on issues
AdminOperator, ViewerAdministrators who configure PI Nexus+ and run destructive maintenance

A user's roles are the union of all enabled mappings whose Windows or AD group the user belongs to. The Access card on Admin > Security shows the result as View, Scan, Export and Admin. A signed-in user without any mapped role has no access to PI Nexus+ pages.

What each role may do

ActionViewerOperatorAdmin
Dashboard, Monitoring, Servers, Issues, inventory pages, detail dialogs, dependency graphs, change historyYesYesYes
View analysis recalculation runs, suggestions and scheduled plansYesYesYes
Scanning page: history, targets, queueYesYes
Start, cancel, promote or retry scans and health refreshes; Check health; Update nowYesYes
CSV exportsYesYes
Suppress and restore issues; acknowledge host issuesYesYes
Create, start and retry analysis recalculations, including Recalculate dependent analyses; dismiss suggestionsYesYes
Create, edit, pause, run and delete scheduled recalculation plansYesYes
Compression Tuning (runs, plans, applying and restoring)Yes
Declare or remove point source declarationsYes
Confirm a sent recalculation, confirm a native-outcome review, delete recalculation historyYes
Recover a stuck scanYes
Map PI Interface runtime signals (Monitoring setup)Yes
Every page of the Admin area, including Scan Automation, Notifications, Security, Support, SQL Server, License and Inventory MaintenanceYes
Background job dashboardYes

Recalculation additionally needs the database permission (see AF Server Settings), the license and native PI rights. A PI Nexus+ role never changes PI security.

Role mappings

FieldValues
RoleViewer, Operator, Admin
Windows / AD GroupDOMAIN\Group, up to 256 characters
EnabledTicked: applies at once. Cleared: the mapping is kept but ignored
RuleBehavior
Bootstrap AdminWhile no enabled Admin mapping exists, members of the local Administrators group on the web server are Admins. Bootstrap Admin shows Active
Last Admin mappingDisabling, changing or removing the last enabled Admin mapping is refused
Group namesLeading and trailing spaces and doubled backslashes are removed
Current User columnShows whether the signed-in user is in the mapped group

Recover Admin access

Use this when no Admin can open the Security page, for example after the Admin group was renamed or removed in AD.

ItemValue
ScriptC:\Program Files\Software Athlete\PI Nexus+\Admin\Recover-AdminAccess.bat (runs Recover-AdminAccess.ps1)
Run asA Windows account that can update the PI Nexus+ database
-AdminGroupRequired. The new Admin group as DOMAIN\GroupName
-SqlServer, -DatabaseOptional. Default: read from C:\ProgramData\Software Athlete\PI Nexus+\bootstrap.json
-DisableOtherAdminMappingsOptional. Disables all other Admin mappings
-WhatIfOptional. Shows the change without making it

Security page tabs

TabShows
Role MappingsRole, group, status, whether the current user is in the group, last update
Security HealthStatus, paths checked, broad write principals and missing paths of the folders and files PI Nexus+ protects
Security AuditTime, actor, action, result and target of admin, scan, export and support actions; warnings and failures of the last 7 days; filter by severity