User's Manual

80
Restrict access to OsOne features only to authorized and authenticated users (created by users with
the Administrator role)
Control what users can do in OsOne
Trace users, modifications, alteration, addition of data /settings in the audit trail
Guarantee of data integrity
Why
To comply with Title CFR21 part 11 (US Regulation) that regulates Electronic Records and Electronic
Signatures
How
Users are created by Administrators
Users must provide valid credentials to access OsOne
By giving different rights to the users
By logging all authenticated users’ actions (failed login, deletion, modifications of data…,) to an audit
trail
By checking that the data are not corrupted, have not been modified outside the system, and if they
are, by informing the user
In order to give different rights to the users, the following concepts are used:
Roles: Rather than assigning individual permissions directly to each user, permissions are grouped
into roles. When users are created, they are assigned a role.
Built-in Roles
The “Administrator” role: is the only user that can access all functionalities and create other users
The “Operator” role: can operate the device but cannot access configuration items
The “Guest” role: cannot do anything, is the default user at startup
Built-in users
Users that exist by default in OsOne, they cannot be deleted and their passwords cannot be modified.
For each role (except for the “Guest” role), there is a built-in user:
User “admin” for the “Administrator role
User “guestthe default user with limited rights
User “operator” for the “Operator” role
User “engineer” for the “Maintenance” role. For Ovizio only.
The passwords of these accounts will be communicated when the software will be delivered.
First use
The first time OsOne is opened built-in users only exist. The first thing to do is to create new users.
To do so, the administrator of the system first creates his own Administrator user account using the built-in
user “admin” and its password (provided) by Ovizio.