📚 Browse docs

Users & security

Asternodis is built for teams and for auditors. The admin-only Users, Audit log and Automation tabs in Settings, plus dual-control, give you attributable, governed operations.

Roles (RBAC)

Every account has one of three roles:

  • Viewer: read-only access to status and configuration.
  • Operator: can run DR operations (failover, failback, DR test, protect a guest) but not change infrastructure or users.
  • Admin: full control, including remotes, pairs, licensing, networking, DR policies, users, and settings.

Manage accounts on the Users & access tab in Settings. The security-sensitive pages (Users, Audit, Automation, alert policy) are admin-only, including reads, so the roster and the security trail aren’t leaked to lower roles.

Dual-control (two-person approval)

For high-stakes operations you can require dual-control: one operator requests the action and a second must approve before it proceeds. Enable it in Settings; it gates single-guest and recovery-plan failover (DR tests, failback and abort stay direct). The requester cannot approve their own request.

Audit log

The Audit log records who did what, when: logins, DR operations, config changes. It’s attributable and tamper-evident (a hash-chained trail): the evidence behind logging controls such as 800-53 AU-2/AU-3/AU-12, ISO/IEC 27001 A.8.15 and IT-Grundschutz OPS.1.1.5, and behind access controls AC-3/AC-6 when combined with roles and two-person failover approval. See control frameworks.

Automation hooks

The Automation page wires the DR lifecycle to webhooks (before and after a failover, and before and after a DR test), so you can notify chat, ticketing, or a SIEM, or drive the rest of your runbook. Alerts, such as a guest falling behind its RPO or a change-rate anomaly, are sent to a separate webhook set under Alerting in the Replication page header. See Automation.

Next: Settings.