SG SealGrid Athena Docs

Roles & Permissions

Athena ships four fixed roles — Admin, Operator, Helpdesk, and User — enforced by authorization policies across the console and API.

The Users page in Athena
The Users page — each account with its role, authentication provider, and status.

The four roles#

Each role grants a fixed set of capabilities. The table below summarizes what each role can do per feature area. An em dash () means the role has no access to that area.

CapabilityAdminOperatorHelpdeskUser
UsersCRUDViewViewSelf
AgentsCRUDCRUDView
DeploymentsExecuteExecuteView
CommandsExecuteExecuteView
SchedulerCRUDCRUDView
SettingsCRUDView
AuditViewViewViewOwn

Role detail#

Admin — full system access, including users and settings.

Operator — manage agents and execute deployments and commands, but cannot manage users or change settings (settings are view-only).

Helpdesk — read-only across most features, with no settings access.

User — their own profile and their own audit events only.

Access tiers#

Every endpoint and page is gated by the minimum role it requires:

Accounts & sign-in#

The first admin is seeded from the DefaultAdmin config section (default username admin). Sign-in is governed by the following policies, which an Admin can adjust in Settings → Security:

See Security Settings for the full list of options, defaults, and ranges, and how to change them from the console, the API, or PowerShell.

Clearing a lockout

Day to day, an Admin clears a lockout from the console. If every admin is locked out — or a password is lost — use the break-glass Emergency Recovery endpoints from the server host to unlock an account, reset its password, or ban an abusive IP.