Administrators
Administrators manage Tessera itself — users, targets, access and settings. This page covers how administrative authority is delegated and protected. For connect-level access to targets, see Access control.
Beyond full administrator, you can grant finer management permissions to a user under Users:
- Manage targets — add and edit servers, databases, clusters, credentials.
- Manage access — grant and revoke access, approve just-in-time requests.
- Manage users — create users, reset passwords, enable/disable accounts.
A full administrator implicitly has all of these.
The primary administrator
Section titled “The primary administrator”Exactly one account is the primary administrator — by default the built-in admin created on
first start. It carries a primary badge in the Users list. The primary administrator:
- cannot be demoted, disabled or deleted by anyone else — this is the account that can always recover control of the installation;
- is the root of the management hierarchy (below).
To hand the role to another administrator, open Users, and choose Make primary on their row. Only the current primary administrator can do this, and there is always exactly one.
Who can manage whom
Section titled “Who can manage whom”When an administrator grants another user an admin or management role, they become that user’s manager. Tessera then prevents a delegated administrator from turning on the people above them:
- You cannot change the roles, disable, delete or reset the password of your manager, or of anyone further up the chain — all the way to the primary administrator.
- You can manage peers (administrators created alongside you) and anyone you granted a role to.
So an administrator you create can never revoke or lock out the administrator who created them.
Losing access
Section titled “Losing access”If you are ever locked out of single sign-on with password login disabled, use the break-glass recovery on the controller host.
We would like to count visits with Google Analytics, which needs a cookie. Nothing is loaded and nothing is stored unless you accept. What this sets.