User Roles and Permissions

From Network for Advanced NMR
Jump to navigationJump to search

NAN Users and NMRbox Users and NMRhub Users—Oh My!

  • NMRbox and NAN were both developed at UConn Health and operate on shared computational resources hosted by the HPC facility. NMRbox has served the NMR community for over a decade, during which users had NMRbox accounts.
  • With the introduction of NAN, we wanted to avoid YAUAYet Another User Account. To streamline access, we created the NMRhub landing site, which provides links to all computational resources hosted at UConn Health. At the same time, we rebranded NMRbox accounts as NMRhub users.
  • As a result, there is no functional difference between a NAN user and an NMRbox user — throughout the documentation, the terms NAN user and NMRhub user are used interchangeably.

The Role of Vetted PIs

A key change introduced with NAN was the concept of vetted PIs and the formal linking of users to PI-led lab groups. Previously, users self-declared their roles (e.g., PI, graduate student), but these designations were not verified.

Because dataset ownership in NAN is PI-based, we added mechanisms for:

  • Users to update their account and request PI status
  • The NAN team to verify and approve PI status
  • Users to request access to a PI's lab group, which must be approved by the PI or their delegate

Seamless Access Through SSO

We have implemented Single Sign-On (SSO) across all NMRhub resources — including NMRbox, NAN, NUScon, and the virtual NAN Operations Center — to enable seamless navigation and access across the ecosystem.

Public User

A user who is not authenticated with an NMRhub account.

They have view-only access to:

Standard NAN User

An authenticated user with an NMRhub account.

They have access to:

Principal Investigator (PI)

Includes everything a standard NAN User sees, plus:

  • Access to Lab Administration for:
    • Creating and managing Projects
    • Adding funding sources
    • Managing lab users and permissions
  • The PI Dashboard of vNOC (summary of lab-wide data)
  • Ability to create Literature Vignettes

PI Delegate

A lab-group member designated by the PI with delegate permissions.

  • Can switch into the PI account to perform actions on their behalf (like the su command in Linux)
  • Does not have PI privileges in their own account directly
  • All actions are performed as the PI once switched

Facility Staff

Each facility must have at least one staff member assigned when it is created. Facility staff are defined on the Facility Information page (viewable only by users with edit rights). Staff with the Roles of Administrator, Director, or Facility Manager have special privileges, including the ability to edit facility information, manage users, and access all data harvested by NDTS from the facility, as described below.

Users may hold more than one role: Administrator, Director, Engineer, Facility Manager, Researcher, Technician, or Approver. Users who are NOT listed as an Administrator, Director, or Facility Manager do not have special privileges beyond being recognized as facility staff.

Users assigned the roles of Administrator, Director, or Facility Manager have:

  • Access to the Facility Dashboard to:
    • Edit facility, instrument, and probe details
    • Manage users and instrument records
    • Download NDTS software
  • Real-time updates to the portal based on dashboard changes
  • Unrestricted access to all datasets collected within their facility
  • Ability to reassign or purge datasets collected within their facility
  • Access to the Facility Dashboard of vNOC

Knowledgebase / Website Content Provider

A NAN user with content editing privileges.

They can:

  • Create and edit Knowledgebase content
  • Assign datasets as KB Datasets
  • Edit any page with built-in content management tools on the portal

UHF Reviewer

A user added to the reviewer pool for Ultra-High Field (UHF) requests.

  • All PIs from labs with access to 1.1 GHz instruments are automatically added

UHF Administrator

A privileged user who helps run the UHF system.

  • Has full access to manage UHF requests
  • Assists the UHF Operations Committee and current cycle chair

UHF Operations Committee Member

A user with broad oversight of UHF review activities.

They can:

  • Manage and review UHF requests
  • Assign reviewers
  • Modify user roles and expertise areas
  • Change the status of UHF requests
  • One member serves as the Chair for each review cycle