---
title: "Manage User Group Configuration"
slug: "profile-sub-tab"
updated: 2026-05-20T14:05:47Z
published: 2026-05-20T14:05:47Z
canonical: "docs.zpesystems.com/profile-sub-tab"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zpesystems.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring Group Profiles Permissions

This section explains how to assign system permissions to group profiles. You can manage user access using permission sets without changing the user profiles. The following table lists:

- Available permissions for users.
- Description of the permission.
- Web UIs and commands demonstrating the functions enabled for the user when each corresponding permission is enabled.

| Permission | Description | Commands Enabled |
| --- | --- | --- |
| Track System Information | Allows access to track information about the Nodegrid devices and the devices connected to them. The information includes the Event List, System Usage, Discovery Logs, and so on as indicated in the following figure. ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/tracking(1).png) | ```plaintext event_list routing_table system_usage discovery_logs serial_statistics serial_ports_summary lldp ipsec_table mac_table wireguard hotspot qos dhcp dhcp_ranges flow_exporter network_statistics network_failover_status network_failover_history switch_statistics mstp_statistics usb_devices usb_serial_stats wireless_modem gps geo_fence bluetooth scheduler_logs hw_monitor zpe_cloud about firewall_table nat_table ``` |
| Terminate Sessions | Allows to terminate any open Nodegrid sessions. ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/terminate.png) | ```plaintext cluster_peers cluster_clusters open_sessions device_sessions about ``` |
| Software Upgrade and Reboot System | Allows to upgrade and reboot the Nodegrid software. ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/upgrade_reboot.png) | ```plaintext toolkit about ``` |
| Configure System | Allows to configure the system. ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/Configure-system.png) | ```plaintext system/about/ system/fips/ settings/zpe_cloud settings/fips_140 settings/license settings/flow_exporter settings/qos settings/system_preferences settings/slots settings/custom_fields settings/remote_file_system settings/system_logging settings/date_and_time settings/ntp_authentication settings/ntp_server settings/dial_up settings/sms_settings settings/sms_whitelist settings/scheduler settings/devices settings/types settings/auto_discovery settings/power_menu settings/devices_session_preferences settings/devices_views_preferences settings/cluster settings/network_settings settings/network_connections settings/network_failover settings/switch_interfaces settings/switch_backplane settings/switch_vlan settings/switch_global settings/switch_acl settings/switch_lag settings/switch_mstp settings/switch_port_mirroring settings/switch_dhcp_snooping settings/802.1x settings/static_routes settings/hosts settings/snmp settings/dhcp_server settings/dhcp_relay settings/authentication settings/ipv4_firewall settings/ipv6_firewall settings/ipv4_nat settings/ipv6_nat settings/ssl_vpn settings/central_management settings/ipsec settings/wireguard settings/frr settings/routing settings/wireless_modem settings/services settings/certificates settings/geo_fence settings/auditing ``` Note: If you select the option **Restrict Configure System Permission to Read Only**, all commands from the above list are disabled except for: ```plaintext acknowledge_alarm_state edit event_system_audit ``` |
| Configure User Accounts | Allows to configure users and groups such as admin users, root users, and so on. To enable Configure User Accounts, Configure System Settings must also be enabled. ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/Configure-user-accounts.png) | ```plaintext system/about/ system/fips/ settings/zpe_cloud settings/fips_140 settings/license settings/flow_exporter settings/qos settings/system_preferences settings/slots settings/custom_fields settings/remote_file_system settings/system_logging settings/date_and_time settings/ntp_authentication settings/ntp_server settings/dial_up settings/sms_settings settings/sms_whitelist settings/scheduler settings/devices settings/types settings/auto_discovery settings/power_menu settings/devices_session_preferences settings/devices_views_preferences settings/cluster settings/network_settings settings/network_connections settings/network_failover settings/switch_interfaces settings/switch_backplane settings/switch_vlan settings/switch_global settings/switch_acl settings/switch_lag settings/switch_mstp settings/switch_port_mirroring settings/switch_dhcp_snooping settings/802.1x settings/static_routes settings/hosts settings/snmp settings/dhcp_server settings/dhcp_relay settings/local_accounts settings/password_rules settings/authorization settings/authentication settings/ipv4_firewall settings/ipv6_firewall settings/ipv4_nat settings/ipv6_nat settings/ssl_vpn settings/central_management settings/ipsec settings/wireguard settings/frr settings/routing settings/wireless_modem settings/services settings/certificates settings/geo_fence settings/auditing ``` |
| Apply & Save Settings | Executes Nodegrid device configurations Apply settings and Save Settings. ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/apply-save.png) | ```plaintext toolkit about ``` |
| Shell Access | Enables shell access to the Nodegrid device. ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/shell-access.png) | ```plaintext about ``` |
| Manage Devices | Enables access to devices connected to the Nodegrid device. Enabling manage devices will require enabling at least one of the following permissions at the device level. Device permissions include: - General Settings ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/Manage-devices-general1.png) - Connection Settings ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/Manage-devices-connection-settings.png) - Inbound Settings ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/Manage-devices-inboundsettings.png) - Management ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/Manage-devices-management.png) - Logging ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/Manage-devices-logging.png) - Custom Fields ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/Manage-devices-custom.png) - Commands ![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/Manage-devices-commands.png) - Outlets - Sensor Channels You can enable either Manage Devices or Configure System permission. Both these permissions cannot be selected together for a device. | ```plaintext access/ management/ logging/ custom_fields/ commands/ ``` |

## Procedure

To configure a user profile:

1. Go to *Security :: Authorization*.
2. Click on the **Group Name**.
3. Click on the **Profile** sub-tab.

![](https://cdn.document360.io/763c5fb1-b9af-4ccd-9ad6-cf28ae4cd5a3/Images/Documentation/profiles.png)
4. In the *System Permissions*menu:
  1. To add, select from the left-side panel, and click **Add**► to move to the right-side panel. To remove from the right-side panel, select, and click ◄**Remove**.
  2. Select **Restrict Configure System Permission to Read Only** checkbox (granted system settings are visible but cannot be changed)
5. In the *Profile Settings*menu:
  1. Select the **Menu-driven access to devices** checkbox (group members presented a target menu when SSH connection to the Nodegrid device is established).
  2. Select the **Sudo permission** checkbox (users can execute sudo commands).
  3. Select the **Custom Session Timeout** checkbox (enables a custom session time).
  4. Set **Timeout [seconds]**.
  5. On the *Startup application* menu, select one (**Cli**, **Shell**).
6. In the *Devices Related Events* menu, enter **Email Events to**(comma-separated)

**NOTE**

*Email Event Categories* and *Email Destinations* are configured in the *Auditing* section.
7. Click **Save**.
