VRS Authorization & Permissions
This document details the roles a user can assume in VRS and the permissions associated with each role.
Roles & Permissions
A user in VRS can assume any role from the following list of supported roles.
admin
agent
The following table outlines the features available for admins and agents and their expected behavior.
Feature | Description | Expected Behavior |
|---|---|---|
Media Recordings | To be able to view media recordings | Agent: An agent role user can access and view only their recording data. Admin: An admin role user can access and view the recording data for all users. |
Recording Rules | To configure the selective recording mechanism | Agent: Not authorized Admin: Only a user with an admin role can access and configure. |
Audit Logs | To view and track user activity | Agent: Not authorized Admin: Only a user with an admin role can access and view the audit logs. |
Archival Service Configuration | To configure archival settings | Agent: Not authorized Admin: Only a user with an admin role can access and configure. |
If a user has multiple roles assigned, the role with the highest level of permissions takes precedence.
Auth Token Expiry
When a user logs into VRS, they are assigned an auth token that is valid up to a certain configured time, which is set on the EF IAM platform. When that token expires, and the user tries to perform any action on the VRS interface, they are automatically logged out of the application and prompted to log in again for accessibility.