Skip to content

Administrators

Administrators manage Tessera itself — users, targets, access and settings. This page covers how administrative authority is delegated and protected. For connect-level access to targets, see Access control.

Beyond full administrator, you can grant finer management permissions to a user under Users:

  • Manage targets — add and edit servers, databases, clusters, credentials.
  • Manage access — grant and revoke access, approve just-in-time requests.
  • Manage users — create users, reset passwords, enable/disable accounts.

A full administrator implicitly has all of these.

Exactly one account is the primary administrator — by default the built-in admin created on first start. It carries a primary badge in the Users list. The primary administrator:

  • cannot be demoted, disabled or deleted by anyone else — this is the account that can always recover control of the installation;
  • is the root of the management hierarchy (below).

To hand the role to another administrator, open Users, and choose Make primary on their row. Only the current primary administrator can do this, and there is always exactly one.

When an administrator grants another user an admin or management role, they become that user’s manager. Tessera then prevents a delegated administrator from turning on the people above them:

  • You cannot change the roles, disable, delete or reset the password of your manager, or of anyone further up the chain — all the way to the primary administrator.
  • You can manage peers (administrators created alongside you) and anyone you granted a role to.

So an administrator you create can never revoke or lock out the administrator who created them.

If you are ever locked out of single sign-on with password login disabled, use the break-glass recovery on the controller host.