Built-in Users and Roles
Loftware Enterprise SP includes built-in administrator users, non-interactive users, and roles.
Administrator Users
The following administrator users are installed with Loftware Enterprise SP. These users cannot be deleted.
| User | Description |
|---|---|
|
SuperAdmin |
This is the default administrator user. This user can do anything within Loftware Enterprise SP. |
|
ClientAdmin |
This is the default administrator user for customers using Loftware Cloud Enterprise SP. This user is assigned the ROLE_ADMINISTRATOR role and can configure users and system settings for their instance of Loftware Enterprise SP. |
|
SystemAdmin |
This is the default administrator user for Loftware Cloud Operations using Loftware Cloud Enterprise SP. This user is assigned the LICENSE_ADMIN_ROLE and ROLE_ADMINISTRATOR roles. |
Non-Interactive Users
The following non-interactive users are installed with Loftware Enterprise SP. These users cannot be deleted or used to sign in to Loftware Enterprise SP.
| User | Description |
|---|---|
|
AutoProvisionUser |
This is the LDAP administration user. This user is assigned the ROLE_ADMINISTRATOR role and can create and modify users as well as add and remove users from groups. |
|
Integration User |
This user may be specified as the Run As for integrations. This user is assigned the INTEGRATOR role. |
|
jvmAdmin |
This is the JVM (server) administration user. This user is assigned the JVM_MANAGEMENT role. |
|
MultiSiteAdmin |
This is the multi-site administration user. This user is assigned the MULTISITE_MANAGEMENT role. |
Built-in Roles
The following roles are installed with Loftware Enterprise SP. These roles cannot be deleted. You can use the built-in roles to assign permissions to users, or you can create custom roles. Custom roles can be created using the Create Role or Copy Role functionality.
| Role | Description |
|---|---|
|
DEVICE_ADMIN |
This role is granted the permissions needed to create, modify, and delete devices. Permissions include Read for everything except Facility, Groups, Roles, and Tag Categories; Write for Device Groups, Devices, Folders, JVM Processes, Remote Sites, and Servers; Create for Device Groups, Devices, Folders, Jobs, and Remote Sites; Delete for Device Groups, Devices, Folders, and Remote Sites, Administration for Device Groups, Devices, Folders, and Remote Sites; and Print for Data Services, Device Groups, Devices, Documents, Jobs, JVM Processes, Processes, and Servers. |
|
DOCUMENT_APPROVER |
This role is granted the permissions needed to view and print label templates and layer objects, progress or fail a step in a workflow, and approve and publish label templates and layer objects. Permissions include Read for everything except User Profiles and Users; Write for Folders; Create for Jobs; Design Print and Print permissions for Data Services, Device Groups, Devices, Documents, Jobs, and Processes; Print permission for Integrations, JVM Processes, and Servers; and Publish for Documents. |
| DOCUMENT_DESIGNER |
This role is granted the permissions needed to create label templates and layouts and import images. Permissions include Read for everything except Facility, Groups, Roles, and Tag Categories; Create for Documents, Folders, and Jobs; Write and Delete for Documents and Folders; and Print and Design Print permissions for Documents, Data Services, Device Groups, Devices, Jobs, and Processes; and Print permission for JVM Processes. |
| DOCUMENT_PRINTER |
This role is granted the permissions needed to act as a Data Provider |
|
DOCUMENT_REVIEWER |
This role is granted the permissions needed to view and print label templates and layer objects and progress or fail a step in a workflow. Permissions include Read for everything except User Profiles and Users; Create for Jobs; Design Print and Print permissions for Data Services, Device Groups, Devices, Documents, Jobs, and Processes; and Print permission for Integrations and JVM Processes. |
| INTEGRATOR |
This role or equivalent permissions are required by any user account that is selected as the Run As user for an integration. Such accounts are typically not interactive. Permissions include Create for Catalogs and Jobs; Write for Catalogs, Read for everything except for Remote Sites; and Print permission for Data Services, Devices, Documents, Device Groups, Jobs, Processes, Integrations, and JVM Processes. This role is read-only. |
|
JVM_MANAGEMENT |
This role or its equivalent is required by the jvmAdmin user for internal product management. You do not need to assign it to any users. |
| LOCAL_ADMIN |
This role is granted most administrator permissions except for those needed for deleting servers and server processes in a distributed services environment. The LOCAL_ADMIN role includes the permissions for a DOCUMENT_DESIGNER and a DOCUMENT_PRINTER, as well as the permissions necessary to act as a Data Service Administrator |
|
MULTISITE_MANAGEMENT |
This role or its equivalent is required by the MultiSiteAdmin user for internal product management of multi-site deployments of Loftware Enterprise SP. You do not need to assign it to any users. |
|
OBJECT_PROMOTER |
This role is granted the permission needed to perform object promotion in System |
|
REPORTING_ADMIN |
This role is granted the permission needed to access administrator features in Business Intelligence Note: Functionality related to Business Intelligence is available only if your Loftware Enterprise SP license has the Business Intelligence component enabled. |
|
REPORTING_USER |
This role is granted the permission needed to access Business Intelligence Note: Functionality related to Business Intelligence is available only if your Loftware Enterprise SP license has the Business Intelligence component enabled. |
|
ROLE_ADMINISTRATOR |
This role is granted the permissions needed to create, modify, and delete other roles. It cannot be altered, and its permissions are not displayed. Note: Only the SuperAdmin and SystemAdmin users can assign or remove this role to or from a user. |

