Manage user accounts, access controls, and system-wide settings from the Management panel on the left sidebar. Use these administrative actions to oversee account security, define permission tiers, and configure core integration parameters.
Important
Access to this panel is restricted to users with the Admin role privilege. Non-admin users who navigate to a restricted page receive a 403 access denied page. Destructive actions prompt for confirmation before proceeding.
Managing the user lifecycle
Monitor account status and provision new access credentials with the WEM Users tab.
- Check the header cards for Total Users, Active Users, Locked Users, and Admin Users. A non-zero Locked Users count indicates that users have exceeded the failed login threshold. Investigate potential security incidents or assist users with password resets.
- Provision new users by selecting the Add WEM User button. In the Database Authentication section, link the WEM account to an existing WHPG user by selecting from the WarehousePG Username dropdown, or create a new WHPG identity by entering a username directly.
- Assign users to one of the three built-in profiles:
- Admin: Full system control.
- Operator: Operational dashboard access, including query management and cancellation.
- Viewer: Read-only access to metrics.
- Use the Active toggle when editing or creating a user to revoke access immediately without deleting the account's history.
- To require a user to change their password at next login, select the key icon for that user. The user is prompted to set a new password the next time they log in to WEM.
- Regularly review the Admin Users count. Keeping the number of high-privileged accounts to a minimum is a core security best practice.
Managing profiles
Review the built-in profiles and their user assignments with the Profiles tab. The Profiles table lists each profile's name, description, and the number of users currently assigned to it.
Defining role-based access control
Control what your team can see and do within the platform with the Permissions tab. You can grant a profile access to individual actions within a panel, instead of only all-or-nothing access to the entire panel.
- Expand a panel's row to grant or revoke View Access and each of its actions per profile, using the Admin, Operator, and Viewer columns, or select Expand All or Collapse All to open or close every row at once. Selecting a panel's own checkbox grants or revokes view access and every eligible action together, and the text below it summarizes the profile's current standing, no access, View Access only, Full access, or View Access plus a count of granted actions.
- An admin-only panel or action carries a lock icon and can't be granted to the Operator or Viewer profiles. Revoking a profile's view access to a panel also revokes every action you granted inside it, since an action grant requires view access to its panel.
- Select Save Changes to review a summary of additions and removals per profile before applying them, or Discard Changes to revert unsaved edits.
- If permissions become misconfigured, select Reset to Defaults to revert every profile's view access and action grants to the factory-recommended state. This can't be undone.
Note
Set WEM_ACTION_PERMISSIONS_ENABLED to false in wem.conf to fall back to admin-only access for every action, regardless of what's granted in the Permissions tab, as an emergency rollback. Restart the WEM service for the change to take effect. See Configuration reference.
Auditing administrative actions
Maintain a chronological record of every administrative action performed in the system with the Audit Log tab.
- Filter by time range (Last 24 hours, Last 7 days, Last 30 days, Last 90 days) and by action type to narrow results.
- Filter by Failed Login to identify potential brute-force attempts. Filter by Login and Logout to verify user activity during specific incident windows.
- Apply the Update User and Create User filters to see who modified accounts or security flags.
Managing host agent registrations
Track and control every host agent connecting to WEM with the Host Agents tab. See Installing the host agent for the full self-registration and approval workflow.
- Approve a pending agent or revoke an approved one from its row's actions menu, or handle several at once by selecting multiple agents and choosing Approve selected, Revoke selected, or Delete selected from the toolbar's Actions menu. Deleting an agent removes its registration entirely, and the agent must register again to reappear.
- Confirm you're approving the agent you expect by comparing its Verification Token against the join token on the host itself (
cat /etc/edb/acp-host-agent/join-token) before approving a pending agent. - Track each agent's registration state, Pending, Approved, or Revoked, in the Status column, and its OTel Collector state in the Telemetry Status column. Request a live status check instead of waiting for WEM's periodic cache by selecting Refresh.
- Show additional bookkeeping columns, such as Approved By and Approved At and hidden by default to keep the table uncluttered, using the columns selector.
Configuring system integration settings
Perform configuration changes to your existing WEM installation with the Settings tab.
- Configure the WarehousePG database connection in the WHPG Database Connection section by editing the coordinator host name, port, database name, and credentials.
- Configure WEM's own state database in the WEM Database Connection section.
Note
Changes to database connection settings or the application port require a restart of the WEM service to take effect.
- Set your cluster's display name and environment (
dev,uat, orprod) in the Cluster Identity section. - In the WHPG Settings section, adjust the
HIGH_LOAD_MODE,LONG_RUNNING_THRESHOLD, andLOG_MIN_DURATION_STATEMENTparameters, each shown by its description rather than its parameter name.LOG_MIN_DURATION_STATEMENTdefines what constitutes a slow query in milliseconds, controlling which queries are captured for performance analysis. See Configuration reference for what each parameter does. - Configure ClickHouse connectivity in the ClickHouse section, and the OTel gateway collector endpoint, if you use one, in the OTel Gateway Collector section. A health indicator next to the ClickHouse section title shows whether WEM can currently reach it.
- Configure the integrated AI Assistant's API key and model in the AI Assistant section.
- URL, integer, and duration fields are validated inline. Navigating away or closing the browser with unsaved changes triggers a warning. Changes to critical connectivity settings (database host, port, or credentials) require an additional confirmation before saving.