Skip to main content
Endpoint permissions define what a user can do with specific Endpoints — narrower scope than administrative permissions, which apply system-wide. They’re granted on the Endpoint Access tab when adding or editing a user or user group.
Without the administrative Endpoint Installation and Management permission, users only see the Endpoints they have at least one Endpoint permission for. Otherwise, they see every Endpoint in the deployment.
Endpoint permissions are granted per Endpoint or Endpoint group individually — there’s no system-wide grant for these. To grant the same permissions across many Endpoints, use a Endpoint group.

The six permissions

Endpoint Uninstallation

Windows and macOS Endpoints only. Allows the user to uninstall the Endpoints (or all Endpoints in a Endpoint group).
If a user attempts to uninstall a Endpoint they don’t have this permission for, the user is forcibly logged out and the Endpoint is not uninstalled.

Endpoint Configuration Management

Allows the user to define the Endpoint configuration — every option except the license assignment, which is gated by License Management.

Viewing Monitoring Results

Allows the user to:
To actually open and play back the monitored sessions — viewing the screen captures and metadata — the user also needs the administrative Viewing Monitoring Results permission.

Viewing Text Data

Windows and macOS Endpoints only. Allows the user to view clipboard text data recorded during Endpoints monitoring. Without this permission, the user sees clipboard records exist but not their contents — useful for restricting investigators from seeing sensitive clipboard content while still letting them audit clipboard activity patterns.

Access to Endpoint via Secondary Auth

Windows and Linux Endpoints only. Allows the user to log in to a Endpoint computer where secondary user authentication is enabled — using their Management Tool credentials as the secondary credential layer.

Example of permission inheritance

The clearest way to understand how Syteca combines user-level and group-level permissions is a worked example.

Setup

  • Mark1 is a user who belongs to Group1 and Group2.
  • Endpoint1 and Endpoint2 are Endpoints, both in the default All Endpoints group.
The administrator grants the following:

Result: Mark1’s effective permissions

Administrative:
  • Management Tool Access — Mark1 belongs to Group1 and Group2, but also has it directly. Persists even if Mark1 leaves both groups.
  • Endpoint Installation and Management — granted directly to Mark1. Independent of group membership.
  • Database Management — Mark1 has it directly and inherits it from Group2. Persists even if Group2 is deleted or edited.
  • User Management — Inherited from Group1. Removed if Mark1 leaves Group1.
Endpoint permissions for Endpoint1:
  • Endpoint Uninstallation — Inherited from Group1.
  • Viewing Monitoring Results — Granted directly to Mark1. Persists regardless of group membership.
  • Endpoint Configuration Management — Mark1’s “All Endpoints” grant covers Endpoint1.
Endpoint permissions for Endpoint2:
  • Viewing Monitoring Results — Inherited from Group2.
  • Endpoint Configuration Management — Mark1’s “All Endpoints” grant covers Endpoint2.

Takeaways

  • Direct grants persist — they’re independent of group membership.
  • Group-inherited grants disappear if the user leaves the group.
  • Both layers stack — a permission granted in multiple places isn’t compounded; it’s just present.
  • All Endpoints grants cascade to every Endpoint (current and future) in the deployment.
For most deployments, the operational pattern is:
  1. Define typical roles as user groups (Investigators, Operators, Admins, PAM Users) with the appropriate inheritable permissions.
  2. Assign users to one or more groups to give them their baseline access.
  3. Use direct grants sparingly for one-off exceptions (“Mark1 also needs Database Management”) that shouldn’t be tied to a group.

Administrative permissions reference

The seven system-wide permissions, granted alongside these per-Endpoint ones.

Users and user groups

The day-to-day workflow for granting and revoking permissions.

Endpoints

The Endpoint objects these permissions apply to.

Sessions list

What “Viewing Monitoring Results” actually unlocks.