14.10.0 14.9.0 14.8.0 14.7 14.6 14.5 14.4 14.3
14.10.0 14.9.0 14.8.0 14.7 14.6 14.5 14.4 14.3

VRS Authorization & Permissions

This document details the roles a user can assume in VRS and the permissions associated with each role.

Roles & Permissions

A user in VRS can assume any role from the following list of supported roles.

  • admin — base role; access all recordings and admin features (Recording Rules, Audit Logs, Archival, Tag Management CRUD).

  • agent — base role; access only their own recordings.

  • download — add-on role; allows downloading recording media files (WAV / MP3). Button is hidden without this role.

  • export — add-on role; allows exporting recording data to CSV. Button is hidden without this role.

  • viewtag — add-on role; see Tag column / tag information and use the Tag filter on Media Recordings. Tag dropdown is hidden. Not used for Tag Management CRUD.

  • evaluatetag — add-on role; assign, unassign (None), or change tags on Media Recordings. Not used for Tag Management CRUD.

Create add-on roles under Keycloak Realm roles and assign them on the user's Role mapping tab (keep default roles for authentication), in addition to admin or agent as needed. Role setup: Setup Keycloak for VRS.

How roles combine

Base role (admin or agent) sets which recordings a user sees; add-on roles grant extra actions.

ENABLE_AGENT_DOWNLOAD

ENABLE_AGENT_DOWNLOAD in config.env still applies in 14.10.0. When it is enabled, the download capability is turned on. The Keycloak download role then determines which individual users (agents or administrators) may download. Without the download role, the Download button is hidden.

Export is separate: it requires the Keycloak export role. Having only download does not allow export. Without export, the Export button is hidden.

After upgrading to 14.10.0

  • Create the new realm roles in Keycloak if they do not exist: download, export, viewtag, evaluatetag.

  • Assign download and/or export to users who should download or export. Without these roles, those buttons stay hidden.

  • Assign viewtag and/or evaluatetag to users who should see the Tag filter or assign tags on Media Recordings.

  • Existing admin and agent users keep their base access; add-on roles are extra and must be assigned explicitly.