Password manager
1. Access control management
Under the menu item "Password Manager," you will find the menu item "Access control management“

First, templates for access points (e.g., for servers) are stored here.
A new access area (template) is created via "New access area."

The templates created are then assigned properties (e.g., server name, user name, password, etc.)

A new property is created via "New Property."

Each of these properties must have a type assigned to it (e.g., integer, text, etc.)

Encrypted
The encrypted function displays the password in a sealed form.
Logical term (Yes/No)
For this type, a checkbox is actively set
File
A file must be selected here.
Picture
An image must be stored here
Numerical
A number must be stored, e.g., an IP address
Integer
Here, you must enter a whole number (without a period or comma), e.g., a phone number
Date
A date must be entered xx.xx.xxxx
Text
A short text must be entered
Text (max. 400 characters)
A long text (400 characters) can be stored here
Hyperlink
A hyperlink to a website must be provided
An "application" (e.g., TeamViewer, Remote Desktop, etc.) can then be assigned to this access area. You can then use these applications to connect directly to the target object via the access area.

2. Policy management
A policy is now created in policy management for the previously created access area. This policy now allows you to make the access areas and the associated access points and applications available to specific departments or employees. You can also assign the access area to specific customers.

A new policy is created via "New Policy."

This policy may then be assigned limited validity and one or more departments. To grant a department access to this access area, simply select the relevant department under "Department." If you want to make this available to individual employees in addition to departments, you can do so via "Employees."

Each of the stored employees can be individually authorized via the "Rights" area (e.g., view access data or change access data).

Rights: Access data visible
The employee can only view the access data but cannot change it
Edit access data
The employee can view and also edit/change the access data
Sealing
Each access can be sealed. Once the password has been sealed, only an employee with the right to "break the seal" can view the password. With the right to "sealthe employee can reseal the broken seal.
Break open the lock
Since every access point can be sealed, this right also allows the employee to break seals. This right can be further subclassified.
o 2-factor authentication
Here, the employee breaking the seal must authenticate themselves again.
o Notification
This right allows all employees who have the right to "break seals" to be informed when a seal has been broken by a colleague.
Manage VPN access
With this right, the employee can also manage the "applications" of the access areas (e.g., VPN, etc.).
If these accesses or this policy do not apply to all customers, this can be provided for specific customers via "Customers." If no customer is selected, this policy can be stored for every customer

3. Access/Password Manager
Employees must log in here before they can access the system. A customer can then be selected under "Customers" and assigned to a previously created area. The access area can now be stored for the customer via "New access."

Under "Permissions," all employees are displayed with the respective rights that have been assigned to them via "Policy Management."