> For the complete documentation index, see [llms.txt](https://docs.gxc.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gxc.io/docs/network-configuration-and-operations-guides/5g-onyx-portal-4.x-operations/administration.md).

# Administration

This section describes how to create and manage partner, customer, and user accounts, and cloud resources.

## Manage Onyx Portal Accounts

The Onyx Portal supports the following account types:

* **GXC Root Account** – The root account comprising of all GXC partner (and associated customer accounts) and GXC-direct customer accounts. You can switch to and manage the GXC Root account only if you are a GXC Administrator.
* **GXC Partner Accounts** – System Integrator (SI) or Value-added Reseller (VAR) accounts comprising associated customer accounts. If you are a Partner Administrator, you can switch to and manage your own GXC partner account. If you are a GXC Administrator, you can switch to and manage any GXC partner account.
* **Customer Accounts** – Individual customer accounts. If you are a Partner Administrator, you can switch to and manage your own customer accounts. If you are a GXC Administrator, you can switch to and manage any customer account.

### Support Plans

Support plans are assigned to each GXC partner and customer account outline the level of assistance and services available, including technical support hours, response times, resolution times, and access to resources such as support documentation and training materials.

* **Basic** – GXC provides business hours support for Tier 3 issues.
* **Basic Plus** – (Additional subscription) GXC provides NOC monitoring, and Tier 1 / 2 / 3 Support 24 x 7 x 365 with standard response times for a cost-effective solution.
* **Platinum** – (Additional subscription) Includes "Basic Plus" features with accelerated SLA response and resolution times.
* **Partner Managed** – GXC Partner / Customer integrates GXC Onyx to their own NOC to directly manage Tier 1 / 2 issues.

For more information regarding the entitlements associated with each of these support plans, please contact your GXC Account representative or GXC Technical Support.

### Manage GXC Partner Accounts

{% hint style="info" %}
**NOTE:** You can create and manage GXC partner accounts only if you are a GXC Administrator.
{% endhint %}

#### View GXC Partner Accounts

This section describes how to:

* View Summary Details of All GXC Partner Accounts
* View a GXC Partner Account's Details

**View Summary Details of All GXC Partner Accounts**

{% hint style="info" %}
**NOTE:** You can view GXC partner account details only if you are a GXC Administrator.
{% endhint %}

**To view the summary details of all GXC partner accounts:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Partners** tab.

The **Administration** page > **Partners** tab displays the summary details of all GXC partner accounts.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FsZJvk8WpMExwJPZ40kJ0%2Fimage.png?alt=media&amp;token=a84f73a9-3899-424a-a095-20f15a77e07b" alt=""><figcaption></figcaption></figure></div>

* **Name** – The GXC partner account's name.
* **Email** – The GXC partner account's email address.
* **Support Plan** – The support plan assigned to the GXC partner account—Basic, Basic Plus, Platinum, and Partner Managed. For more information, see [Support Plans](#support-plans).
* **Actions** – (Super Administrator only) Options to view, edit, and delete the GXC partner account.
  {% endstep %}

{% step %}
To download a CSV file listing the partner accounts' details including partner name, GXC support plan, contact email ID, and address, click **Download**. The CSV file is downloaded to your computer.
{% endstep %}

{% step %}
To search for a particular GXC partner account, in the **Search** box, enter your search term.
{% endstep %}
{% endstepper %}

**View a GXC Partner Account's Details**

{% hint style="info" %}
**NOTE:** You can view GXC partner account details only if you are a GXC Administrator.
{% endhint %}

**To view a GXC partner account's details:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Partners** tab.

The **Administration** page > **Partners** tab displays the summary details of all GXC partner accounts.
{% endstep %}

{% step %}
To view the details of a particular GXC partner account, click the account's name.

The ***\<partner name>*** page displays the GXC partner account's details:

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F4DVrJjMOrNeamGRipmnF%2Fimage.png?alt=media&amp;token=d102f440-28da-46dd-98a9-9f0e9b659589" alt=""><figcaption></figcaption></figure></div>

* **Partner Details**:
  * **E-mail** – The Account Manager's email address.
  * **Type** – The account's type—GXC Partner.
  * **Parent** – The GXC partner account's parent—GXC Root.
  * **Name** – The GXC partner account's name.
  * **Address** – The GXC partner account's registered address.
  * **Session Timeout** – The Onyx Portal user session timeout duration for users in this GXC partner account. If a user's session is idle for this duration, the user is automatically logged out.
  * **Support Plan** – The support plan assigned to the GXC partner account—Basic, Basic Plus, Platinum, and Partner Managed. For more information, see [Support Plans](#support-plans).
* **Customers** – List of customer accounts under this GXC partner account.
  * **Name** – The customer account's name.
  * **E-mail** – The customer's email address.
  * **Type** – The customer account type—Customer.
  * **Customer ID** – The customer account's ID.
  * **Actions** – Options to view and delete the customer account.
* **Own Users** – List of the GXC partner account's own users.
  * **Name** – The user's name.
  * **E-mail** – The user's email address.
  * **Role** – The user's role.
  * **User ID** – The user's ID.
  * **Actions** – Options to edit and delete the user account.
* **Account Managers** – List of the GXC partner account's Account Managers.
  * **Name** – The user's name.
  * **E-mail** – The user's email address.
  * **Role** – The user's role.
  * **User ID** – The user's ID.
    {% endstep %}
    {% endstepper %}

#### Add Super Admin User Account under a GXC Partner Account

**To add a Super Admin user account under a GXC partner account:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Partners** tab.

The **Administration** page > **Partners** tab displays the summary details of all GXC partner accounts.
{% endstep %}

{% step %}
For the GXC partner account that you want to edit, in the **Actions** column, click the corresponding ⋮ (options) icon, then click **View**.

The ***\<partner name>*** page displays the GXC partner account's details.
{% endstep %}

{% step %}
To add a Super Admin user account to the GXC partner account, in the **Own Users** section, click **Add User**.

The **Create User** page is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F6Asd2wX6YZ38lVmCMtCe%2Fimage.png?alt=media&amp;token=85cb9a39-8ff7-4b4e-b28d-ea698d57fc4d" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details:

* **Upstream IdP User** – If a customer's IdP cannot release user attributes such as "onyxPortalTenantId", "onyxPortalRole", etc. required for SSO user authentication to the Onyx IdP, user accounts for Onyx Portal users in the customer's organization are created in the Onyx Portal. To enable SSO authentication for such users, this toggle button must be enabled to fetch the required attributes from the user's Onyx Portal account settings. Default setting: disabled.
* **User Email** – (Required) The user's email address.
* **User Name** – (Required) The user account's user name.
* **Role** – (View-only field) The user's role—Super Admin.
  {% endstep %}

{% step %}
To save the user account, in the upper-right corner of the page, click **Save User**.
{% endstep %}
{% endstepper %}

### Manage Customer Accounts

{% hint style="info" %}
**NOTE:** You can create and manage customer accounts only if you are a GXC Administrator.
{% endhint %}

#### View Customer Accounts

{% hint style="info" %}
**NOTE:** You can view customer accounts only if you are a GXC Administrator.
{% endhint %}

This section describes how to:

* View Summary Details of All Customer Accounts
* View a Customer Account's Details

**View Summary Details of All Customer Accounts**

{% hint style="info" %}
**NOTE:** You can view customer account details only if you are a GXC Administrator.
{% endhint %}

**To view the summary details of all customer accounts:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Customers** tab.

The **Administration** page > **Customers** tab displays the summary details of all Onyx Portal customer accounts. All customer accounts irrespective of their partner hierarchy are listed in the **Customers** tab.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FF7Vn0vUmfv2eJK4hv6dx%2Fimage.png?alt=media&amp;token=1722f546-4055-4dcf-990d-df4c9c940d74" alt=""><figcaption></figcaption></figure></div>

* **Customer Name** – The customer account's name.
* **GXC Partner** – If the customer account is associated with a GXC partner, the GXC partner's name.
* **Email** – The Account Manager's email address.
* **Support Plan** – The support plan assigned to the customer account—Basic, Basic Plus, Platinum, or Partner Managed. For more information, see [Support Plans](#support-plans).
* **Actions** – Options to view details, edit and delete a GXC partner account.
  {% endstep %}

{% step %}
To download a CSV file listing the associated customer accounts with details including customer name, partner, GXC support plan, contact email ID, and address, click **Download**. The CSV file is downloaded to your computer.
{% endstep %}

{% step %}
To search for a customer account, in the **Search** box, enter your search term.
{% endstep %}
{% endstepper %}

**View a Customer Account's Details**

**To view a customer account's details:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Customers** tab.

The **Administration** page > **Customers** tab displays the summary details of all Onyx Portal customer accounts. All customer accounts irrespective of their partner hierarchy are listed in the **Customers** tab.
{% endstep %}

{% step %}
To view the details of a particular customer account, click the customer account's name.

The ***\<customer name>*** page displays the following details:

* **Customer Details**:
  * **E-mail** – The Account Manager's email address. The email address of the customer account's first Super Administrator user. This Super Administrator user will have the privilege to create other user accounts within the customer account.
  * **Type** – The account type—Customer.
  * **GXC Partner** – If the customer account is associated with a GXC partner, the GXC partner's name.
  * **Name** – The customer account's name.
  * **Address** – The customer's registered address.
  * **Session Timeout** – The Onyx Portal user session timeout duration for users in this customer account. If a user's session is idle for this duration, the user is automatically logged out.
  * **Support Plan** – The support plan assigned to the customer account—Basic, Basic Plus, Platinum, and Partner Managed. For more information, see *Support Plans*.
  * **Add SSO Config** – (Displayed only if SSO is not configured.) Click to add SSO configuration for the customer account. For more information, see *Add SSO with IdP Configuration*.
  * **Edit SSO Config** – (Displayed only if SSO is already configured.) Click to edit SSO configuration for the customer account. For more information, see *Edit SSO with IdP Configuration*.
* **Account ID** – The Onyx Portal cloud account ID.
  * **Resource Group ID** – The resource group's ID.
  * **Resource Group Name** – The resource group's name.
  * **Region** – The region associated with the resource group.
  * **Availability Zone** – The availability zone associated with the resource group.
  * **Status** – The resource group's status—Create Complete, etc.
  * **Host Key** – Options to view and download the host key.
  * Click the expand icon to view EC2 instances, if provisioned.
    * **Instance ID** – The instance's ID.
    * **Instance Name** – The instance's name.
    * **Connected Onyx Edge** – The connected Onyx Edge's name.
    * **Network Name** – The network's name.
    * **Private IP** – The instance's private IP address.
    * **Public IP** – The instance's public IP address.
    * **Status** – The instance's provisioning status.
      * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F8UHMDykRo2ZdGMLKmYHJ%2Fimage.png?alt=media&amp;token=de28e1df-0e33-4196-a8c3-5cab4fa0744d" alt="" data-size="line"> Green – Create Complete
      * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FRPGrPdIfFb8rFKV5rqhD%2Fimage.png?alt=media&amp;token=4303d444-d2f0-42ff-a262-5b039d3f49e4" alt="" data-size="line"> Red – Rollback Complete
    * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FP9nviL2QrZrqmafa53Zk%2Fimage.png?alt=media&amp;token=d74708f7-c8a4-4668-a11a-1815375dc1cc" alt="" data-size="line"> – Click to delete the instance.
* **Add Resource Group** – Click to create a cloud resource group. For more information, see *Create Cloud Resource Groups*.
* **Own Users**:
  * **Name** – The user's name.
  * **E-mail** – The user's email address.
  * **Role** – The user's role.
  * **User ID** – The user's user ID.
  * **Actions** – Options to edit and delete the user account.
* **Account Managers**: This section is not applicable in this release.
  * **Add User** – Click to add a user account under the customer account. For more information, see *Create User Accounts under a Customer Account*.
    {% endstep %}
    {% endstepper %}

#### Create User Accounts under a Customer Account

{% hint style="info" %}
**NOTE:** You can add users to customer accounts only if you are a GXC Administrator.
{% endhint %}

**To add a user to a customer account:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Customers** tab.

The **Administration** page > **Customers** tab displays the summary details of all Onyx Portal customer accounts.
{% endstep %}

{% step %}
For the customer account that you want to add the user to, in the **Actions** column, click the corresponding ⋮ (options) icon, then click **View**.

The ***\<customer name>*** page displays the customer account's details.
{% endstep %}

{% step %}
In the **Account Managers** section, click **Add User**.

The **Create User** page is displayed.
{% endstep %}

{% step %}
Enter the following details:

* **User Email** – (Required) The user's email address.
* **User Type** – (View-only field) The user's account type—Own User.
* **User Name** – (Required) The user's account name.
* **Role** – (Required) The user's role. Select from **Super Admin**, **Admin**, **Viewer**.
* **Upstream IdP User** – (Optional) If a customer's IdP cannot release user attributes such as "onyxPortalTenantId", "onyxPortalRole", etc. required for SSO user authentication to the Onyx IdP, user accounts for Onyx Portal users in the customer's organization are created in the Onyx Portal. To enable SSO authentication for such users, this toggle button must be enabled to fetch the required attributes from the user's Onyx Portal account settings. Default setting: disabled.
  {% endstep %}

{% step %}
To save the user account, in the upper-right corner of the page, click **Save User**.
{% endstep %}
{% endstepper %}

#### Configure SSO Authentication with IdP Configuration

The Onyx Portal can integrate with a customer organization's existing IdP for SSO user authentication. The customer must provide their IdP details to GXC for integration with the Onyx Portal.

All IdP-related configurations such as entity ID, IdP metadata, Single Sign-On/Single Logout URLs and certificates are configured in the Onyx IdP. The Single Sign-On and Single Logout requests are redirected from the Onyx Portal to the Onyx IdP. The Onyx IdP does the target IdP discovery based on the RequestedAuthnContext in the SAML Authentication Request and redirects the Single Sign-On/Logout request to the customer IdP.

{% hint style="info" %}
**NOTE:** Before enabling SSO for an Onyx Portal customer account, the SAML or OIDC application must be configured with the customer's IdP.
{% endhint %}

**Add SSO with IdP Configuration**

**To add SSO configuration for an existing Onyx Portal customer account:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Customers** tab.

The **Administration** page > **Customers** tab displays the summary details of all Onyx Portal customer accounts.
{% endstep %}

{% step %}
In the upper-right corner of the **Customer Details** panel, click **Add SSO Config**.

The **Add SSO Config** dialog box is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FM7o7tJY6GHRhxybUOBkK%2Fimage.png?alt=media&amp;token=3b85ac83-c964-42a3-850b-fed76d04c4d5" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details:

* **Enable SSO** – Toggle to enable or disable SSO for the customer account.
* **Organization Name** – (Required) The organization's name.
* **IdP Entity ID** – (Required) The IdP's entity ID, a unique ID for the IdP within the SSO ecosystem. It is used by service providers to recognize and trust the IdP.
* **IdP Destination URL** – (Required) The endpoint where the IdP receives authentication requests from the service provider. This URL is used during the SSO process to authenticate users.
* **SSO Vendor** – (Required) Select the SSO solution vendor's name—**Google**, **Shibboleth**, **Okta**.
* **IDP SLO URL** – (Optional) The IDP's single logout (SLO) URL. The endpoint where the IdP handles logout requests. This URL ensures that when a user logs out from one service, the session is terminated across all connected services in the SSO environment.
* **IdP Metadata URL** – (Required) The metadata file location for the IdP. This file contains configuration information, such as entity ID, SSO URLs, SLO URLs, and certificates, which the service provider uses to establish trust and integrate with the IdP.
* **+ Upload Metadata** – Click to add a metadata file. In XML format, this metadata contains the necessary configurations and certificates required to establish trust between the IdP and service providers within the SSO environment.
* **Additional Config**:
  * **IDP Certificate** – A digital certificate issued to the IdP that is used to sign authentication assertions and encrypt communications. This certificate ensures the integrity and security of the data exchanged between the IdP and the service provider. It typically contains the public key used in the cryptographic processes.
  * **InCommon Metadata Filter** – A configuration tool or setting used within the "InCommon Federation", a trusted framework for U.S. education and research institutions. This filter allows administrators to selectively include or exclude metadata from the federation's metadata aggregate based on specific criteria. This helps manage which entities are trusted and ensures that only relevant and up-to-date metadata is processed for authentication and authorization purposes.
    {% endstep %}

{% step %}
To save the SSO config, click **Save**.
{% endstep %}
{% endstepper %}

**Edit SSO with IdP Configuration**

**To edit the SSO configuration for an Onyx Portal customer account:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Customers** tab.

The **Administration** page > **Customers** tab displays the summary details of all Onyx Portal customer accounts.
{% endstep %}

{% step %}
In the upper-right corner of the **Customer Details** panel, click **Edit SSO Config**.

The **Edit SSO Config** dialog box is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FCEUnRSvsWsQQ1PfsCQkx%2Fimage.png?alt=media&amp;token=0946595a-7f89-4c6c-852c-b99a076ae5ea" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Update the following details as required:

* **Enable SSO** – Toggle to enable or disable SSO for the customer account.
* **Organization Name** – (Required) The organization's name.
* **IdP Entity ID** – (Required) The IdP's entity ID, a unique ID for the IdP within the SSO ecosystem. It is used by service providers to recognize and trust the IdP.
* **IdP Destination URL** – (Required) The endpoint where the IdP receives authentication requests from the service provider. This URL is used during the SSO process to authenticate users.
* **SSO Vendor** – (Required) Select the SSO solution vendor's name—**Google**, **Shibboleth**, **Okta**.
* **IDP SLO URL** – (Optional) The IDP's single logout (SLO) URL. The endpoint where the IdP handles logout requests. This URL ensures that when a user logs out from one service, the session is terminated across all connected services in the SSO environment.
* **IdP Metadata URL** – (Required) The metadata file location for the IdP. This file contains configuration information, such as entity ID, SSO URLs, SLO URLs, and certificates, which the service provider uses to establish trust and integrate with the IdP.
* **+ Upload Metadata** – Click to add a metadata file. In XML format, this metadata contains the necessary configurations and certificates required to establish trust between the IdP and service providers within the SSO environment.
* **Additional Config**:
  * **IDP Certificate** – A digital certificate issued to the IdP that is used to sign authentication assertions and encrypt communications. This certificate ensures the integrity and security of the data exchanged between the IdP and the service provider. It typically contains the public key used in the cryptographic processes.
  * **InCommon Metadata Filter** – A configuration tool or setting used within the "InCommon Federation", a trusted framework for U.S. education and research institutions. This filter allows administrators to selectively include or exclude metadata from the federation's metadata aggregate based on specific criteria. This helps manage which entities are trusted and ensures that only relevant and up-to-date metadata is processed for authentication and authorization purposes.
    {% endstep %}

{% step %}
To save your edits, click **Save**.
{% endstep %}
{% endstepper %}

## Manage Onyx Portal User Accounts

The Onyx Portal supports creating and managing user accounts for users to monitor and manage their enterprise/private networks.

User privileges are strictly regulated by Role-based Access Control (RBAC). Users, such as Support Engineers, can be granted access to only view specific data while restricting their ability to create, modify, or delete configurations.

The Onyx Portal supports the following user roles:

* **GXC Administrator** – The highest level in the Onyx Portal user hierarchy. Can create and manage partner and customer accounts.
* **GXC Partner Administrator** – System Integrators (SI) or Value-added Resellers (VAR). Can perform all configuration and management tasks for associated customer accounts.
* **Super Administrator** – Can perform all configuration and management tasks within the managed network.
* **Administrator** – Can perform equipment-level operations and management within the managed network.
* **Viewer** – Can only monitor the managed network.

The following table summarizes user administration privileges across user roles.

The privileges indicated in the following tables follows the CRUD convention:

* C – Create or add new entries.
* R – Read, retrieve, search, or view existing entries.
* U – Update or edit existing entries.
* D – Delete, deactivate, or remove existing entries.

<p align="center"><strong>User Administration Privileges</strong></p>

<table><thead><tr><th valign="top">User Role</th><th valign="top">Account</th><th valign="top">GXC Partner</th><th width="138.8333740234375" valign="top">Super Administrator</th><th width="139.666748046875" valign="top">Administrator</th><th width="97.166748046875" valign="top">Viewer</th></tr></thead><tbody><tr><td valign="top">GXC Administrator</td><td valign="top">Super CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td></tr><tr><td valign="top">GXC Partner</td><td valign="top">R for associated accounts</td><td valign="top">R</td><td valign="top">CR</td><td valign="top">CRUD</td><td valign="top">CRUD</td></tr><tr><td valign="top">Super Administrator</td><td valign="top">R for self account</td><td valign="top">CRUD for self account</td><td valign="top">R</td><td valign="top">CRUD</td><td valign="top">CRUD</td></tr><tr><td valign="top">Administrator</td><td valign="top">No</td><td valign="top">R</td><td valign="top">R</td><td valign="top">R</td><td valign="top">RUD</td></tr><tr><td valign="top">Viewer</td><td valign="top">No</td><td valign="top">R</td><td valign="top">R</td><td valign="top">R</td><td valign="top">R</td></tr></tbody></table>

The following table summarizes Onyx Portal RBAC across user roles.

<p align="center"><strong>Onyx Portal Administration Privileges</strong></p>

**Venues**

<table><thead><tr><th width="99.6666259765625">Module</th><th width="139.833251953125">GXC Administrator</th><th>GXC Partner</th><th width="138">Super Administrator</th><th width="137.1666259765625">Administrator</th><th>Viewer</th></tr></thead><tbody><tr><td>Venue</td><td>CRUD</td><td>CRUD</td><td>CRUD</td><td>RU</td><td>R</td></tr><tr><td>Floors</td><td>CRUD</td><td>CRUD</td><td>CRUD</td><td>RU</td><td>R</td></tr></tbody></table>

**Equipment**

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Onyx Edge</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">R</td></tr><tr><td valign="top">Onyx Edge Upgrade Groups</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">R</td><td valign="top">R</td></tr><tr><td valign="top">Access Point</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">R</td></tr><tr><td valign="top">Access Point Upgrade Groups</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">R</td><td valign="top">R</td></tr><tr><td valign="top">Mesh Node</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">R</td></tr><tr><td valign="top">Mesh Node Upgrade Groups</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">R</td><td valign="top">R</td></tr><tr><td valign="top">FHM</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">R</td></tr><tr><td valign="top">FHM Upgrade Groups</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">CRUD</td><td valign="top">R</td><td valign="top">R</td></tr></tbody></table>

**Subscribers**

| Subscriber Secrets                                | CRUD | Unauthorized | Unauthorized | Unauthorized | Unauthorized |
| ------------------------------------------------- | ---- | ------------ | ------------ | ------------ | ------------ |
| Subscriber Info / Traffic Policy, APN Association | RU   | RU           | RU           | RU           | R            |
| Subscriber Info - IMEI Association                | RU   | RU           | RU           | RU           | R            |
| Bulk Export / Import                              | CRUD | Unauthorized | Unauthorized | Unauthorized | Unauthorized |
| Session Monitoring                                | R    | R            | R            | R            | R            |

**Network**

| Network      | CRUD | CRUD | CRUD | R | R |
| ------------ | ---- | ---- | ---- | - | - |
| Network List | CRUD | CRUD | CRUD | R | R |

**Traffic**

| Policies | CRUD | CRUD | CRUD | CRUD | R |
| -------- | ---- | ---- | ---- | ---- | - |
| Profiles | CRUD | CRUD | CRUD | CRUD | R |

**Alerts**

| Alerts Visibility | R    | R    | R    | R   | R |
| ----------------- | ---- | ---- | ---- | --- | - |
| Rules             | CRUD | R    | R    | R   | R |
| Receivers         | CRUD | CRUD | CRUD | CRU | R |

**Analytics**

| Generate Reports | R | R | R | R | R |
| ---------------- | - | - | - | - | - |

**Audit Logs**

| Audit Logs Visibility | R | R | R | Unauthorized | Unauthorized |
| --------------------- | - | - | - | ------------ | ------------ |

### Onyx Portal User Idle Session Timeout

While users inherit partner or customer account timeout settings by default, administrators can configure custom timeouts for individual users based on their roles, operational needs, or security policies.

The custom timeout setting can be configured when adding or editing a user account.

The custom timeout setting can be configured in one of the following ranges:

* 5–59 minutes
* 1–23 hours
* 1–7 days

For SSO user accounts, idle session timeout in Onyx Portal is independent of the SSO/SAML IdP configuration. If the Onyx Portal timeout is shorter than the IdP's, users are logged out but silently reauthenticated if the IdP session is still valid. If the Onyx Portal timeout is longer, users must fully reauthenticate once the IdP session expires.

For multi-tenant user accounts, the idle session timeout is determined by the base tenant's setting.

### View User Accounts

{% hint style="info" %}
**NOTE:** If you are a GXC Administrator, when you are in the GXC Root account, you can view all Onyx Portal users irrespective of their account hierarchy.
{% endhint %}

{% hint style="info" %}
**NOTE:** If you are a GXC Partner Administrator, when you are in your own partner account, you can view all users within your own partner account and those in your direct customer accounts.
{% endhint %}

{% hint style="info" %}
**NOTE:** If you are a Super Administrator or an Administrator, you can view all users within your own customer account.
{% endhint %}

{% hint style="info" %}
**NOTE:** To view, create, and manage users in a particular Onyx Portal account, you must switch to that account.
{% endhint %}

* View User Accounts under Non-GXC Root Accounts
* View User Accounts under the GXC Root Account

#### View User Accounts under Non-GXC Root Accounts

{% hint style="info" %}
**NOTE:** You can view user accounts under non-GXC Root accounts only if you are a GXC Administrator or Partner Administrator.
{% endhint %}

**To view user accounts under non-GXC Root accounts:**

{% stepper %}
{% step %}
Switch to the required Onyx Portal account.

To switch between Onyx Portal accounts, in the upper-right corner of the page, click the current Onyx Portal account's name, then select the required account.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab displays the list of active user accounts from across all Onyx Portal accounts.

* **Users (n)** – The count and list of user accounts in the selected Onyx Portal account.
  * **User Email** – The user's email address.
  * **User Name** – The user's name.
  * **User Role** – The user's role—Super Admin, Admin, Viewer.
  * **Network** – The networks under the selected Onyx Portal customer account that the user has permission to manage.
  * **Actions** – Shortcut options to edit and delete the user account.
    {% endstep %}

{% step %}
To search for a particular user account, in the **Search** field, enter your search term.
{% endstep %}
{% endstepper %}

#### View User Accounts under the GXC Root Account

{% hint style="info" %}
**NOTE:** You can view user accounts under the GXC Root account only if you are a GXC Administrator.
{% endhint %}

**To view user accounts under the GXC Root account:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
To view all existing user accounts under the GXC Root account:

1. Click **Administration** > **Users** tab.

   The **Administration** page > **Users** tab displays the list of active user accounts from across all Onyx Portal accounts.

   * **Name** – The user's name.
   * **Role** – The user's role—GXC Admin, Super Admin, Admin, Viewer.
   * **Email** – The user's email address.
   * **Status** – The user account's status—Verified, Verification Pending, Forgot Password.
   * **Account Name** – The Onyx Portal account that the user is associated with.
   * **Parent Account Name** – The parent account of the Onyx Portal account that the user is associated with.
   * **Actions** – Shortcut options to edit, delete, and suspend the user account.

   To search for a particular user account, in the upper-right corner of the page, in the **Search** field, enter your search term.
   {% endstep %}

{% step %}
To view user accounts under a particular GXC partner account:

1. Click **Administration** > **Partners** tab.\
   The summary details of all GXC partner accounts are displayed.
2. Click the GXC partner account's name.\
   The ***\<partner name>*** page is displayed.\
   The **Own Users** section lists the user accounts under the GXC selected partner account.
   {% endstep %}

{% step %}
To view the user accounts under a particular customer account:

1. Click **Administration** > **Customers** tab.\
   The list of customer accounts is displayed.
2. Click the customer account's name.\
   The ***\<customer name>*** page is displayed.\
   The **Own Users** section lists the user accounts under the selected customer account.
   {% endstep %}
   {% endstepper %}

### Create User Accounts

This section describes creating the following types of user accounts:

* Create direct user accounts:
  * Create Direct Super Administrator, Administrator, or Viewer User Accounts
  * Create GXC Administrator User Account
* Create upstream IdP user accounts

#### Create Direct Super Administrator, Administrator, or Viewer User Accounts

{% hint style="info" %}
**NOTE:** If you are a GXC Administrator or a GXC Partner Administrator, you can add Super Administrator, Administrator, and Viewer user accounts. If you are a Super Administrator, you can add Administrator and Viewer user accounts.
{% endhint %}

**To create a direct Super Administrator, Administrator, or Viewer user account under non-GXC Root accounts:**

{% stepper %}
{% step %}
Switch to the required GXC partner or customer account.

To switch between Onyx Portal accounts, in the upper-right corner of the page, click the current Onyx Portal account's name.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab displays the list of active user accounts.
{% endstep %}

{% step %}
In the upper-right corner of the page, click **Add User**.

The **Create User** page is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fx59igEIhcuzuFDkhRQGf%2Fimage.png?alt=media&amp;token=19b81f15-dbd6-46c0-8fd5-fbb25862b427" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details:

* **User Email** – (Required) The user's email address.

{% hint style="info" %}
**NOTE:** If the email ID that you enter is already associated with a user account in another Onyx Portal customer account, the user can be invited to manage the current Onyx Portal customer account with any role.
{% endhint %}

* **Invite user to manage the current Onyx Portal customer account** – (Displayed only if the email ID is already associated with an existing user account in any other Onyx Portal customer account.) To invite the user to manage the current Onyx Portal customer account, select the check box.
* **User Name** – (Required) The user's full name.
* **Role** – (Required) The user's role. Select from **Super Admin**, **Admin**, **Viewer**.
* **Network** – Click to select from the list of networks in the customer account, all or specific networks that the user must have access to manage. To remove access to a particular network, clear the corresponding checkbox. Default value: **All Networks**.
* **Use account-level idle session timeout setting** – To inherit the GXC partner/customer account level user idle timeout setting, select the checkbox. To configure a custom value, clear the checkbox and enter a value from one of the following ranges.
  * 5–59 minutes
  * 1–23 hours
  * 1–7 days
    {% endstep %}

{% step %}
To save the user account, in the upper-right corner of the page, click **Save User**.
{% endstep %}
{% endstepper %}

#### Create Upstream IdP Super Admin, Admin, and Viewer User Accounts

Upstream IdP users are users who authenticate and are managed via a customer's IdP service rather than being managed directly by the Onyx Portal. If a customer's IdP cannot release the user attributes required for SSO user authentication (onyxPortalTenantId and onyxPortalRole) to the Onyx IdP, user accounts for Onyx Portal users in the customer's organization are created in the Onyx Portal.

{% hint style="info" %}
**NOTE:** If you are a GXC Administrator or a GXC Partner Administrator, you can add Super Administrator, Administrator, and Viewer user accounts. If you are a Super Administrator, you can add Administrator and Viewer user accounts.
{% endhint %}

**To create an upstream IdP Super Admin, Admin, or Viewer user account:**

{% stepper %}
{% step %}
Switch to the required GXC partner or customer account.

To switch between Onyx Portal accounts, in the upper-right corner of the page, click the current Onyx Portal account's name.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab displays the list of active user accounts.
{% endstep %}

{% step %}
In the upper-right corner of the page, click **Add Upstream IdP User**.

The **Create User** page is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FvsUCrNaksVjoTmOo99ue%2Fimage.png?alt=media&amp;token=fa61b571-7481-4531-b89c-4defc14f05ff" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details:

* **User Email** – (Required) The user's email address.

{% hint style="info" %}
**NOTE:** If the email ID that you enter is already associated with a user account in another Onyx Portal customer account, the user can be invited to manage the current Onyx Portal customer account with any role.
{% endhint %}

* **Invite user to manage the current Onyx Portal customer account** – (Displayed only if the email ID is already associated with an existing user account in any other Onyx Portal customer account.) To invite the user to manage the current Onyx Portal customer account, select the check box.
* **User Name** – (Required) The user's full name.
* **Role** – (Required) The user's role. Select from **Super Admin**, **Admin**, **Viewer**.
* **Network** – Click to select from the list of networks in the customer account, all or specific networks that the user must have access to manage. To remove access to a particular network, clear the corresponding checkbox. Default value: **All Networks**.
  {% endstep %}

{% step %}
To save the user account, in the upper-right corner of the page, click **Save User**.
{% endstep %}
{% endstepper %}

### Edit User Accounts

{% hint style="info" %}
**NOTE:** If you are a GXC Administrator, you can edit Super Administrator, Administrator, and Viewer user accounts. If you are a GXC Partner or a Super Administrator, you can only edit Administrator and Viewer user accounts.
{% endhint %}

This section applies to editing both direct and upstream IdP user accounts under non-GXC Root accounts.

{% hint style="info" %}
**NOTE:** You can edit a user account only to change the user's name. Details such as the user's email address and role are not editable.
{% endhint %}

**To edit a user account under non-GXC Root accounts:**

{% stepper %}
{% step %}
Switch to the required GXC partner or customer account.

To switch between Onyx Portal accounts, in the upper-right corner of the page, click the current Onyx Portal account's name.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab > **Users** section displays the list of active user accounts.
{% endstep %}

{% step %}
For the user account that you want to edit, in the **Actions** column, click the corresponding ⋮ (options) icon, then click **Edit**.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FxdxwTyBfpPBnx6seqVcE%2Fimage.png?alt=media&amp;token=25a7f022-be19-4c0c-a887-0c7bc66b0d98" alt="" width="162"><figcaption></figcaption></figure></div>

The **Edit User Access** page is displayed.
{% endstep %}

{% step %}
Edit the user's name or allowed networks as required.

* **User Email** – (View-only field) The user's email address.
* **User Name** – (Required) The user's name.
* **Role** – (View-only field) The user's role.
* **Network** – Click to select from the list of networks in the customer account, all or specific networks that the user must have access to manage. To remove access to a particular network, clear the corresponding checkbox. Default value: **All Networks**.
* **Use account-level idle session timeout setting** – To inherit the GXC partner/customer account level user idle timeout setting, select the checkbox. To configure a custom value, clear the checkbox and enter a value from one of the following ranges.
  * 5–59 minutes
  * 1–23 hours
  * 1–7 days
    {% endstep %}

{% step %}
To save your edits, in the upper-right corner of the page, click **Save User**.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
**NOTE:** You can edit user accounts under the GXC Root account only if you are a GXC Administrator.
{% endhint %}

{% hint style="info" %}
**NOTE:** You can edit a user account only to change the user's name. Details such as the user's email address and role cannot be edited.
{% endhint %}

**To edit user accounts under the GXC Root account:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab displays the list of active user accounts.
{% endstep %}

{% step %}
For the user account that you want to edit, in the **Actions** column, click the corresponding ⋮ (options) icon, then click **Edit**.

The **Edit User Access** page is displayed.
{% endstep %}

{% step %}
Edit the user's name as required.

* **User Email** – (View-only field) The user's email address.
* **User Name** – (Required) The user's name.
* **Role** – (View-only field) The user's role.
* **Use account-level idle session timeout setting** – To inherit the GXC partner/customer account level user idle timeout setting, select the checkbox. To configure a custom value, clear the checkbox and enter a value from one of the following ranges.
  * 5–59 minutes
  * 1–23 hours
  * 1–7 days
    {% endstep %}

{% step %}
To save your edit, in the upper-right corner of the page, click **Save User**.
{% endstep %}
{% endstepper %}

### Reset User MFA Secrets

If a user's mobile phone is compromised or lost, and the user's MFA backup codes are unavailable or exhausted, you can reset the user's MFA secrets. Resetting a user's MFA secrets is equivalent to deleting the user's MFA registration, allowing the user to set up MFA again as if for a new user.

{% hint style="info" %}
**NOTE:** If a user does not have access to his/her phone temporarily, the user can use the backup codes to log in. For more information, see *Reset Your MFA Secrets*.
{% endhint %}

**To reset a user's MFA secrets:**

{% stepper %}
{% step %}
Switch to the required GXC partner or customer account.

To switch between Onyx Portal accounts, in the upper-right corner of the page, click the current Onyx Portal account's name.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab displays the list of active user accounts.
{% endstep %}

{% step %}
For the user account that you want to reset MFA secrets, in the **Actions** column, click the corresponding ⋮ (options) icon, then click **Reset MFA Secrets**.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F5k6Mk5pyVSuKjWU3HFaV%2Fimage.png?alt=media&amp;token=74c5889f-4908-49ef-a117-640761cb4eb4" alt="" width="162"><figcaption></figcaption></figure></div>

A confirmation dialog box is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FG4Oq0AgeYqtUWDrlMZhH%2Fimage.png?alt=media&amp;token=ead4acda-4b4d-431d-9c16-85445e203c09" alt="" width="430"><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
To confirm resetting the user's MFA secrets, click **Yes**.
{% endstep %}
{% endstepper %}

### Suspend User Accounts

**To suspend a user account:**

{% stepper %}
{% step %}
Switch to the required Onyx Portal account.

To switch between Onyx Portal accounts, in the upper-right corner of the page, click the current Onyx Portal account's name, then select the required account.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab displays the list of active user accounts.
{% endstep %}

{% step %}
For the user account that you want to suspend, in the **Actions** column, click the corresponding ⋮ (options) icon, then click **Suspend Account**.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FJcBW0HWGYUFUV8iDNpdi%2Fimage.png?alt=media&amp;token=e8fa45b2-2513-48c3-9dd6-75d8e0f71e23" alt="" width="162"><figcaption></figcaption></figure></div>

A confirmation dialog box is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F012dHyVYUbq6mzd7oqOv%2Fimage.png?alt=media&amp;token=a7e988d9-e339-40e4-9d4d-41f80adbf2bf" alt="" width="315"><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
To confirm, click **Yes**.

The user account is suspended.
{% endstep %}
{% endstepper %}

### Activate Suspended User Accounts

**To activate a suspended user account:**

{% stepper %}
{% step %}
Switch to the required Onyx Portal account.

To switch between Onyx Portal accounts, in the upper-right corner of the page, click the current Onyx Portal account's name, then select the required account.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab displays the list of active user accounts.
{% endstep %}

{% step %}
For the suspended user account that you want to activate, in the **Actions** column, click the corresponding ⋮ (options) icon, then click **Activate Account**.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fy0spDsYbCHKGvG12Y4Hy%2Fimage.png?alt=media&amp;token=4d5281a8-8e40-4f78-9a2a-96bcb1208c9b" alt="" width="164"><figcaption></figcaption></figure></div>

A confirmation dialog box is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FAhKNyjbB0VDa7tVboYdt%2Fimage.png?alt=media&amp;token=48d75b32-0f2e-4b46-a98e-8cd20f101981" alt="" width="311"><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
To confirm, click **Yes**.

The user account is activated.
{% endstep %}
{% endstepper %}

### Delete User Accounts

{% hint style="info" %}
**NOTE:** If you are a GXC Administrator, you can delete Super Administrator, Administrator, and Viewer user accounts. If you are a GXC Partner Administrator or a Super Administrator, you can delete Administrator and Viewer user accounts. If you are an Administrator, you can delete Viewer user accounts.
{% endhint %}

**To delete a user account from an Onyx Portal account:**

{% stepper %}
{% step %}
Switch to the required Onyx Portal account.

To switch between Onyx Portal accounts, in the upper-right corner of the page, click the current Onyx Portal account's name, then select the required account.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab displays the list of active user accounts.
{% endstep %}

{% step %}
For the user account that you want to delete, in the **Actions** column, click the corresponding ⋮ (options) icon, then click **Delete**.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FAW9vpf39UkcED4UjgdaH%2Fimage.png?alt=media&amp;token=dc5914ae-1a57-4c24-b65d-924ca933ea48" alt="" width="162"><figcaption></figcaption></figure></div>

A confirmation dialog box is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fev8R9tu7KNDrI08hL5fQ%2Fimage.png?alt=media&amp;token=a05e7c40-16bd-4761-875e-5e8c8cac4ef9" alt="" width="323"><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
To confirm, click **Yes**.

The user account is deleted.
{% endstep %}
{% endstepper %}

## View Onyx Portal Operations Audit Logs

{% hint style="info" %}
**NOTE:** You can view the Onyx Portal Operations Audit Logs only if you are a GXC Administrator, GXC Partner Administrator, or a Customer Super Administrator.
{% endhint %}

The Onyx Portal supports audit logging of important Onyx Portal user operations, such as user log on and log out, all create, update, and delete operations, software upgrades, equipment restarts, log and cert file downloads, etc.

The audit logs are retained for a period of 60 days and can be downloaded as a .csv file.

The audit logs record details include the operation, the timestamp at which the operation occurred, the responsible user, client IP address, operation's category and sub-category, operation's status, and so on.

**To view the Onyx Portal Operations Audit Logs:**

{% stepper %}
{% step %}
Switch to the GXC Root account.

To switch to the GXC Root account, in the upper-right corner of the page, click the current Onyx Portal account's name, then click **Other Accounts** > **Select GXC Root**.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Operations Audit Logs** tab.

The **Administration** page > **Operations Audit Logs** tab displays the list of Onyx Portal Operations Audit Logs for the selected duration and customer account.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fo9FDbsyb69jUNhq5Eo4W%2Fimage.png?alt=media&amp;token=099fda6c-e77c-4bdf-9a44-4cd6f3537dd1" alt=""><figcaption></figcaption></figure></div>

* **Audit Logs (n)** – The total number of audit logs.
* **Timestamp** – The timestamp at which the operation occurred.
* **Email** – The email address of the user responsible for the operation. To filter logs for a particular user, in the **Search Email** box, enter the user's email address.
* **Operation Name** – The operation's name—Post, Put, Delete. To filter logs based on operation name, in the dropdown select the required operation name.
* **Operation Category** – The operation's category. To filter logs based on operation category, in the dropdown select the required operation category.
* **Operation Sub-Category** – The operation's subcategory. To filter logs based on operation sub-category, in the dropdown select the required operation sub-category.
* **Operation Status** – The operation's status—Success, Failure, Blank. To filter logs based on operation status, in the dropdown select the required operation status.
* **Client IP** – The client IP address from which the operation occurred.
* **Request Details** – Click <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fe9sbWyjTaTv7H9Uxf1aX%2Fimage.png?alt=media&amp;token=7dcb1613-80c5-455a-a3b3-9d6a80171763" alt="" data-size="line"> (view details) to view the object's details. The **Details** dialog box displays the object's details.
* **Request Object** – If available, click <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fm8UzH0qwmGi2Q11yURsZ%2Fimage.png?alt=media&amp;token=4d61a6a8-b41f-43a1-a059-9a4a85e62393" alt="" data-size="line"> (view details) to view the request details. The **Details** dialog box displays the object's request details.
* **Additional Details** – If available, click <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FQTNk3Zb3t3kTfEWbk1AJ%2Fimage.png?alt=media&amp;token=c2fac062-515d-4284-9552-6f0b1f80ebd3" alt="" data-size="line"> (view details) to view additional object details, such as Onyx Edge or AP configuration, etc. The **Details** dialog box displays additional details.
  {% endstep %}

{% step %}
By default, logs are displayed for all customer accounts. To view logs for a specific customer account, in the **Tenant** dropdown, select the customer account's name.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FWZjeGLeK6OoqzFLm1TDY%2Fimage.png?alt=media&amp;token=b2a5ab5d-4293-4165-afcd-7e5530a1dcdb" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
To change the selected duration for which logs are displayed, select the required from and to timestamps.
{% endstep %}

{% step %}
To search for logs using keywords, enter your search term in the **Search keyword** box.
{% endstep %}

{% step %}
To download the logs as a .csv file, click **Download**, and specify where to save the file.
{% endstep %}
{% endstepper %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.gxc.io/docs/network-configuration-and-operations-guides/5g-onyx-portal-4.x-operations/administration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
