Contents

  1. About System Administrators
    1. The Super Admin
    2. What is a Community
    3. Roles
    4. Print Rules and Access Control Rules
    5. Visibility of Users and Printers on Web Admin
    6. Effective Community
  2. How to…
    1. Add (sub)Administrators
    2. Link Printers to a Community
    3. Label Tags

About System Administrators

Celiveo 365 controls administrator access through two independent mechanisms:

  • Roles – decide what an administrator can do (full admin, AI features, reports, or technician operations).
  • Communities – decide what an administrator can see, defined by up to five hierarchical tags assigned to the user or group.

Roles and tags are assigned in User Management on the User Settings and Role Based Access Control tabs. The effective access of an administrator is the intersection of the role(s) they hold and the community their tags grant them.

The Super Admin

When you subscribe to Celiveo 365, an Administrator User is automatically created for the user who performed the subscription. That user must hold the Printer Administrator role in Entra ID; in Celiveo 365 they receive the Administrator role with no tag restrictions ( */*/*/*/* ), making them a Super Admin with access across the entire application.

Super Admins can appoint other domain users – or Entra ID groups – as administrators, technicians, AI administrators or report administrators, as long as those users hold the Printer Administrator or Printer Technician role in Entra ID. As soon as a user loses that Entra ID role, they can no longer sign in to the Celiveo 365 portal. This deep integration ensures end-to-end security and avoids a second user-management layer inside Celiveo 365.

What is a Community?

A community is a group of users, workstations, printers and administrators that share a common characteristic – for example, the same building or site.

The community a user or printer belongs to is determined by the tags assigned to them. Celiveo 365 supports up to five tags arranged as a hierarchy. A common pattern uses three tags to identify Country, State and City:

  • A user tagged USA / California / San Francisco belongs to the San Francisco community.
  • A user tagged USA / California / * belongs to the California community, which is a superset of San Francisco and Sacramento.
  • A user tagged * / * / * belongs to every community.

Roles

Roles control what an administrator can do. Tags control what they can see. The two combine: a Report Administrator with USA / * / * tags can read reports for every USA site but nothing outside the USA.

The four roles are:

Role What it grants
Administrator Full access to every feature and function, restricted only by the user’s tags. An Administrator with no tag restrictions ( */*/*/*/* ) is the Super Admin with access across the entire application. With narrower tags, the Administrator becomes a regular admin scoped to a sub-community.
AI Administrator Access to the AI features only – AI-DLP and AI-Doc (including AI-Doc Cohort Management).
Report Administrator Access to Reports only – Tracking Report, Quota and Power BI dashboards.
Technician Limited operational role:
  • Can add or remove printers.
  • Cannot create CVP, UPE or MUP queues.
  • Cannot create or delete profiles – can only use existing profiles.
  • Cannot change any global settings.
  • No access to Reports (including Power BI).
  • No access to AI features.
  • No access to User Management.

Roles are cumulative: a user can hold any combination of the four roles, either by direct assignment or by inheriting them from a group they belong to.

A regular Administrator (one whose tags are not all wildcards) can in turn appoint users or groups as administrators within their own community. For example, the California Administrator can promote a user in the California community to Administrator – creating either a peer for California or a sub-administrator for San Francisco or Sacramento. Administrators only see and act on their own community and its sub-communities; sibling and parent communities are hidden from them.

Legend

1- Default Admin – Super Admin created automatically at installation
2- Regular Admin – Administrator scoped to all communities within the USA
3- Regular Admin for California (including San Francisco and Sacramento)
4- Regular Admin for Sacramento
5- Regular Admin for San Francisco

Print Rules and Access Control Rules

A regular administrator has read-only access to Print Rules and Access Control Rules created by administrators above them in the community hierarchy. They can use those rules but cannot modify them. They can create and modify rules within their own community and any sub-community they own.

For example, the California Administrator can use – but not modify – rules created by the Super Admin and the USA Administrator. They can modify any rule created by the San Francisco or Sacramento administrators.

The Sacramento Administrator can use rules created by the Super Admin, the USA Administrator and the California Administrator, but cannot modify them. They have no visibility at all into rules created by the San Francisco Administrator (a sibling community).

Visibility of Printers, Profiles and Tracking Information in the Web Admin

When an administrator signs in to the Celiveo 365 Web Admin, they only see the printers, profiles and tracking information that belong to their community or to a parent community. Sibling communities are hidden.

Effective Community

An administrator can inherit community tags in more than one way:

  1. By direct assignment of tags to their user account.
  2. By assignment of tags to one or more groups they belong to.

Each tag assignment carries a priority between 0 (minimum) and 100 (maximum). When a user inherits community settings from several sources, the assignment with the highest priority wins. If priorities tie, the explicit user-level assignment overrides any group-level assignment.

The same priority rule applies to role assignments. Because roles are cumulative, the practical effect is that a user holds the union of every role granted to them by any source.

How to…

Add (sub)Administrators

  1. From the main menu, click Users .
  2. In the secondary toolbar, click Add Users to assign roles to individual users, or Add Group to assign roles to every member of an Entra ID group.
  3. In the User Settings tab, click the Search icon next to the [Search box] to list the first 1000 users (or groups) from the selected Entra ID. You can also type partial names or characters to narrow the list.
    p(banner tip). Note: Wild or special characters cannot be used for Search.
  4. Select the users (or groups) you want to add.
    p(banner important). Note: To create Universal Print queues, users must hold the Printer Administrators role in Entra ID.
  5. Specify the tags that define the community the new users will belong to.
    p(banner tip). Notes: ** The new users inherit your community by default. ** You can change only those tags marked * in your own tag assignment, allowing you to scope the new users into a sub-community of yours. ** When the new users print via Print Direct, only printers that share their community are listed. ** The tag assignment determines which printers, users and groups they can see in the Web Admin; their roles (next step) determine what they can do.
  6. Set Priority between 1 and 100. When a user inherits a community from several sources, the highest priority wins.
  7. Click Next > to switch to the Role Based Access Control tab.
  8. In the Select… dropdown, pick a role and add it. Repeat for additional roles. To remove a role, click the trash icon next to its row. The available roles are:
    • Administrator
    • AI Administrator
    • Report Administrator
    • Technician
  9. Click Save.

The new users (or group members) can now sign in to the Web Admin with the rights granted by their roles, scoped to their community.

Link Printers to a Community

  1. From the List of Printers, select the printers and click Tags .
  2. Select the tag values that define the printers’ community.
  3. If a tag dropdown is empty or does not contain the value you need:
    1. Click Add next to the dropdown.
    2. Enter the new value and click Save.
  4. Click Save. The tags are now assigned to the printers, which join the matching community.

Label Tags

  1. Click Settings .
  2. Click Tags .
  3. Edit the tag labels (for example Region, Country, State, City, Site) and click Save.

The new labels appear on every screen that uses tags – User Management, Printer settings and the rule editors.

Last modified: 4 May 2026

Feedback

Was this helpful?

Yes No
You indicated this topic was not helpful to you ...
Could you please leave a comment telling us why? Thank you!
Thanks for your feedback.

Post your comment on this topic.

Post Comment