Automatically enabled when you configure Domotz permissions in your agent workflow. No manual toggle needed.
What It Does
- Find the client’s collectors from the Organization Mapping. A client with several sites has one collector per site
- Read a collector’s devices with their status, uptime, latency and history, and the site’s speed tests, IP conflicts and network topology
- Read device metrics, sensors, activity logs and the account audit log
- Edit a device’s details (name, type, model, vendor, importance, room, zone, serial, notes) and its inventory values; tag it, add a sensor or an external host, and start a configuration backup
- Read alert events with the rules, profiles and contact channels behind them, and resolve an alert once the device is back
- Change what Domotz watches: alert rules and their bindings, excluded and hidden devices, monitoring state
- Power a device on, off or through a cycle on its PoE switch port or PDU outlet, reboot it, or run a custom driver action
- Change a collector’s scan policies and routed networks, close a VPN session, and manage Organizations, their contacts and the account’s users
domotz as the vendor id. Sandbox scripts can call Domotz too, under the same permissions.
Permission Groups
A write in Monitoring Coverage can stop an alert without anyone noticing: a hidden or unmanaged device, or an unbound alert rule, raises nothing. A write in Collector Settings or Users & Account can change what a collector finds or who reaches the account. Each is a separate group so you can ask for approval on those writes alone.
Access Profiles
Read Only
Read Only
Every group Read Only. The agent can look up any collector, device, history or alert, but never changes anything.
Helpdesk
Helpdesk
Resolves alerts on its own. Every other change waits on a technician.
IT Admin
IT Admin
Changes devices, runs power actions, resolves alerts and manages Organizations on its own. Monitoring Coverage, Collector Settings and Users & Account changes wait on a technician.
Full Automation
Full Automation
Nothing waits on a technician, except the two operations below.
Not available through Neo
Neo refuses these before it calls Domotz:- Opening a remote connection to a device or a collector VPN session, because the response is a working access link or VPN configuration
- The text of a stored device configuration, which can contain passwords. The agent reads the backup list and its checksums, to see when a configuration changed
- Camera snapshots, because the response is an image the agent cannot read
- Bulk deleting a collector’s offline devices, because the call names no device. The agent can delete devices one at a time
- Wiping the account’s whole inventory, which deletes every field and value on every device
