Privileged Endpoints
The endpoints in this section require permissions beyond plain authentication, but they are not uniformly admin-only — the required role varies and is stated on each subsection (or individual endpoint):
- Most infrastructure-management writes (hierarchy, collectors, SNMP targets & credential profiles, alert rules, notification channels, maintenance windows, device/link deletion) require engineer or admin — the
operator role receives 403.
- System-administration endpoints (user management, system settings, sessions, audit log, backup/restore, license upload) require admin — engineer and operator receive
403.
- A few read-only reporting/diagnostic endpoints nested here (Reports, Simulation, IP-Conflict Diagnostics, Traffic History) are open to all authenticated roles.
Always defer to the per-endpoint Auth/role line where present.