Vault Configuration
Overview
This section describes the configuration and operational management of the Inextor Vault.
It covers:
- Vault setup
- Business configuration parameters
- Azure API Management
- Common actions
- Entities and roles
- Profiles and users
- Product groups and products
- Factories and lines
- Product licensing
- Request management
- User rights
- Managing settings
- Vault management and processes
- Vault business scenarios
- Operation drivers
The purpose of Vault configuration is to provide Vault users with the information needed to handle operation, authentication, access rights, and management aspects through the Vault website and Vault Administration tools.
Production data uploaded on Vault and Vault data are kept for at least five years.
1 Vault Setup
All operations needed to set up a Vault are listed below.
If a specific regulation is used, additional steps are listed in the corresponding operational guide.
| When to do the action | What to do | Documentation reference |
|---|---|---|
| Always | Define the Vault code, usually three letters | Vault website: Administration - Production Line |
| Always | Define the Liz ranges associated to the customer | Inextor Liz ranges documentation |
| If it is a Small Tobacco Manufacturer | Import the TP certificates in the root Vault to generate licenses from there | Certificate Tool |
| Always | Import the root, TP, and Vault certificates in the Windows Certificate Store of the machines running the Vault Service | Certificate Tool / Certificate Manager |
| Always | Create Vault certificates and import them into the Vault database | Certificate Tool / Certificate Manager |
| Always | Create the Vault database using the DACPACs | Vault database administration guide |
| Always | Check that the .NET framework installed on the server is aligned with the version defined in the specifications | General installation procedures / Vault Service |
| If it is an Azure Vault | Ask the IT & Infrastructure team to deploy the Vault | Internal deployment process |
| If it is an on-premises Vault | Copy binaries, set up services and IIS, and configure Azure pipelines for future upgrades | IIS configuration / Vault Proxy IIS configuration |
| Always | Create an entity with the LE and MAN roles for the factory | Vault Business Scenarios / Vault website: Administration - Entity |
| Always | Create a factory associated to the entity created above. The License All Products checkbox should be enabled | Vault website: Administration - Factory |
| Always | Create a connection with the request file provided by the Gate | Vault website: Administration - Factory |
| If it is an Azure Vault | Create IAM users to be accessed using the Inextor account | Vault website: Administration - User |
| Always | Enable the Audit Log manager | Audit Log Manager documentation |
2 Business Configuration Parameters
The Vault can be configured to grant different levels of access to the site.
These privileges are user-account based and are usually decided by the Vault owner or administrator.
These settings are defined in the VaultService.exe.config configuration file.
| Parameter | Description | Possible values |
|---|---|---|
LizApprovalRequired | Defines whether approval is required when a Liz is registered on the Vault. Approval is done by an account with GOV role, or by a GOV-role user with the relevant Liz validation operation right | false / true |
LizApprovalRequired | An approval request is initiated on the Liz Configuration GUI by clicking Register online. This creates a request on the Vault request page, under the Liz tab, where the request must be approved or rejected | |
MSKApprovalRequired | Defines whether approval is required when an MSK is generated on the Vault and downloaded to a Liz | false / true |
MSKApprovalRequired | An approval request is initiated on the Liz Configuration GUI by clicking Register MSK. This creates a request on the Vault request page, under the MSK tab, where the request must be approved or rejected | |
SKUApprovalRequired | Defines whether the government or administrator must approve Stock Keeping Units | None, Local, Import, Local Import |
SKUApprovalRequired | None: no approval required. Local: only local-origin Stock Keeping Units require approval. Import: only imported Stock Keeping Units require approval. Local Import: all Stock Keeping Units require approval | |
ProductionOutdatedInterval | Defines how long a Gate and its serializers can be disconnected from the Vault before production batches are marked as invalid with the error code Outdated | [NumberOfDays]d |
ProductionOutdatedInterval | By default, the status remains outdated even if the connection is restored. This behavior is configurable with the key OutdatedStatusBlocked | |
GateReportType | Defines whether only printed codes are reported or whether generated codes are also reported | None / AdditionalQty |
GateNotifyType | Defines whether Gates with a production connection should send Stock Keeping Units and production data to this Vault when the Stock Keeping Units or production batches belong to another Vault | None, SKU, PROD, SKU PROD |
3 Using Azure API Management
Overview
A firewall protects the Vault as the primary security measure.
Usually, additional security can be applied by restricting access to internal company IP addresses or a small set of external machines. For the Vault, this is not always possible because all Gates linked to the Vault must be able to access it.
Azure API Management can be used as an additional security layer.
Azure API Management provides a controlled set of machines, with a small range of known IP addresses, through which clients must pass to access the Vault. The Vault firewall can then be configured to accept incoming connections only from those machines.
This service is implemented through the Vault Azure API Management Operation Driver.
Configuration guide
To use Azure API Management, the following steps are needed:
| Step | Description |
|---|---|
| 1 | Create or reuse an Azure API Management instance. Copy its subscription ID, resource group name, and service name into the configuration window |
| 2 | Create or reuse an application registration in Azure. Write down its application ID in the configuration. It does not need API permissions or authentication platform details |
| 3 | Create a client secret for the application registration and write it down in the configuration window |
| 4 | In the Azure API Management instance, add the Contributor role to the service principal mapped to the application registration |
| 5 | In the Azure API Management instance, upload the three certificates of the internal certification authorities of the Vault. These are usually found in a Gate .licx file: root, TP, and Vault certificates |
Certificate note
Azure API Management requires a password for uploaded .pfx certificates. It may be necessary to import and export certificates again for this purpose.
If the IIS hosting the Vault API uses a self-signed certificate, it is recommended to upload it as well.
4 Common Actions
The table below defines common actions executed on the Vault website.
Action types describe the phase where the action typically occurs:
- Initial: a new entity is being onboarded to the Vault
- Running: normal operation
- Manage: typical administration tasks during normal operation
| Action type | Role | Action | Reference |
|---|---|---|---|
| Initial | ADM | Create entities and add roles | Entities and Roles |
| Initial | ADM | Create administration profile for the new entity | Profiles and Users |
| Initial | ADM | Create administration user for the new entity | Profiles and Users |
| Initial | ADM | Create product groups | Product Groups and Products |
| Initial | Any | Create additional profiles for the new entity | Profiles and Users |
| Initial | Any | Create additional users for the new entity | Profiles and Users |
| Initial | LE | Create products, may require ADM approval | Product Groups and Products |
| Initial | MAN / IMP | Add factories, requires ADM approval | Factories and Lines |
| Initial | MAN / IMP | Manage factory connections | Factories and Lines |
| Initial | LE | Add product licenses to a manufacturer or importer | Product Licensing |
| Initial | MAN / IMP | Add product licenses to factories | Product Licensing |
| Initial | - | Line registration, may require ADM approval | Factories and Lines |
| Initial | - | MSK registration and MSK download, may require ADM approval | Factories and Lines |
| Initial / Running | ADM | Approve or reject account, role, product, factory, production line, MSK, and volume control requests | Request Management |
| Running | Any | Check code | Code Checking |
| Running | Any | Monitor production batches | Managing Production in the Vault |
| Running | Any | Production reports | Managing Production in the Vault |
| Running | LE | Manage volume control orders for manufacturers/importers, requires ADM approval | Serialization with Volume Control - Operation |
| Running | LE | Manage volume control assignments to factories | Serialization with Volume Control - Configuration |
| Manage | ADM | Manage entities and roles | Entities and Roles |
| Manage | Any | Manage users | Profiles and Users |
| Manage | Any | Manage profiles | Profiles and Users |
| Manage | LE | Manage products, may require ADM approval | Product Groups and Products |
| Manage | MAN / IMP | Manage factories, requires ADM approval | Factories and Lines |
| Manage | MAN / IMP | Manage factory connections | Factories and Lines |
| Manage | LE | Manage licensed products to a manufacturer or importer | Product Licensing |
| Manage | MAN / IMP | Manage licensed products to factories | Product Licensing |
Only users associated with an entity having the specified role can execute the specified action. In addition, the user must have the specific operation rights required for that action.
5 Entities and Roles
Introduction
Entities and roles are managed from the Vault website under Administration - Entity.
- GOV users can manage entities and roles if they have the required operation rights
- Non-GOV users can manage roles for their own entity if they have the required operation rights
- Changes made by non-GOV users must be approved by a GOV user before activation
Operation rights required
| Action | Operation rights required |
|---|---|
| Create entity | Account - List, Create |
| Create entity with authorized status | Account - Validate |
| Add role | Role - List, Create |
| Add role with authorized status | Role - Validate |
| Edit entity | Account - List, Edit |
| Edit entity with authorized status | Account - Validate |
| Edit role | Role - List, Edit |
| Edit role with authorized status | Role - Validate |
Entity creation and adding roles
| Step | Action |
|---|---|
| 1 | The stakeholder requests an account with specified roles. This step is performed outside the Vault |
| 2 | Go to the Entity Management page |
| 3 | Click Create on the Entity Management page. A wizard is launched |
| 4 | In the Entity step, enter the entity details and click Next. The status must be Authorized to activate the account |
| 5 | In the Role step, click Create Role. A popup window opens |
| 6 | Select a role and enter the role details. Click Save. The status must be Authorized for the role to be activated |
| 7 | Repeat the previous two steps for every new role to assign to the entity |
| 8 | In the Role step, click Next |
| 9 | In the Validate step, review all entries and click Validate. The wizard closes |
| 10 | If the entity or role requires approval, see Request Management |
Edit entities
| Step | Action |
|---|---|
| 1 | Go to the Entity Management page |
| 2 | In the grid, expand the entity to be edited and click Edit. A wizard starts |
| 3 | In the Entity step, edit the fields and click Next. The status must be Authorized to activate the change |
| 4 | In the Role step, click Next |
| 5 | In the Validate step, review all entries and click Validate. The wizard closes |
| 6 | If the entity requires approval, see Request Management |
6 Profiles and Users
Introduction
Profiles and users are managed from the Vault website:
- Administration - Profile for profiles
- Administration - User for users
Any user can manage profiles and users if they have the required operation rights.
GOV users can manage profiles and users for any entity. Non-GOV users can manage profiles only for their own entity.
Operation rights required
| Action | Operation rights required |
|---|---|
| Create profile | Profile - List, Create |
| Edit profile | Profile - List, Edit |
| Delete profile | Profile - List, Delete |
| Create user | User - List, Create |
| Edit user | User - List, Edit |
| Delete user | User - List, Delete |
Create profile
| Step | Action |
|---|---|
| 1 | Go to the Profile Management page |
| 2 | Click Create. A wizard starts |
| 3 | In the Actor step, pick the entity that the profile is assigned to and click Next |
| 4 | In the Profile step, enter profile details and click Next |
| 5 | In the Operation step, select profile operations and click Next |
| 6 | In the Validate step, review all entries and click Validate. The wizard closes |
Edit profile
| Step | Action |
|---|---|
| 1 | Go to the Profile Management page |
| 2 | Click the Pen icon of the profile to edit. A wizard opens |
| 3 | In the Profile step, edit the profile details and click Next |
| 4 | In the Operation step, select profile operations and click Next |
| 5 | In the Validate step, review all entries and click Validate. The wizard closes |
Delete profile
| Step | Action |
|---|---|
| 1 | Go to the Profile Management page |
| 2 | Click the Recycle bin icon of the profile to delete. A confirmation popup opens |
| 3 | Click Yes to delete the profile |
Create user
The PDF begins this procedure with:
| Step | Action |
|---|---|
| 1 | Go to the User Management page |
The uploaded extraction only provided the first step of the Create User procedure. If needed, we can extract this specific page separately and rebuild the full procedure.
7 Product Groups and Products
Introduction
Product groups are managed from the Vault website under Administration - Product Group.
Products are managed from the Vault website under Administration - Product.
For business cases where product groups are required, product groups must be created before products are added to the system.
- ADM users can manage product groups if they have the necessary operation rights
- LE users, or ADM users acting on their behalf, can manage products if they have the necessary operation rights
Product groups are part of a Vault add-on and may not be available or enabled on all installations.
Operation rights required
| Action | Operation rights required |
|---|---|
| Create product group | TaxLevel - List, Create, Validate |
| Edit product group | TaxLevel - List, Edit |
| Create products | SKU - List, Create |
| Edit products | SKU - List, Edit |
| Approve products | SKU - List, Validate, ADM user only |
The Vault can be configured for auto-approval of products. In that case, Legal Entities can manage products without approval from an ADM user with Validate rights on the SKU operation.
Product groups and products can be created or edited using the Excel Import Interface.
Create product group
| Step | Action |
|---|---|
| 1 | Go to the Product Group Management page |
| 2 | Click Create. A popup dialog opens |
| 3 | Enter a product group code and details. Click Save. The status must be Authorized to activate the product group |
Edit product group
| Step | Action |
|---|---|
| 1 | Go to the Product Group Management page |
| 2 | In the grid, expand the product group to edit and click Edit. A popup dialog opens |
| 3 | Enter product group details and click Save. The status must be Authorized before changes come into effect |
Create product
| Step | Action |
|---|---|
| 1 | Go to the Product Management page |
| 2 | Click Create. A wizard launches |
| 3 | In the Owner step, pick the Legal Entity that owns the product. Click Next |
The uploaded extraction only provided the beginning of the Create Product procedure. If needed, we can extract this page separately and complete the full flow.
8 Factories and Lines
Introduction
Factory management is handled from the Vault website under Administration - Factory.
Production line management is handled from the Vault website under Administration - Production Line.
- MAN / IMP users, or GOV users acting on behalf of a Legal Entity, can manage factories if they have the necessary operation rights
- Production Line and MSK registration requests are done from the Liz Configuration GUI through the factory Gate, not directly on the Vault
The Vault can be configured for auto-approval of Liz instances. In that case, factories can register Liz instances without approval from a Government user.
The Vault can be configured for auto-approval of MSKs. In that case, factories can register MSKs without approval from a Government user.
Operation rights required
| Action | Operation rights required |
|---|---|
| Create factory | Gate - List, Create |
| Approve factory | Gate - Validate |
| Edit factory | Gate - List, Edit |
| Approve factory after edit | Gate - Validate |
| Manage connection | Gate - List, Edit |
| Line registration | Not applicable; executed from factory |
| Approve line | Liz - List, Validate |
| MSK registration | Not applicable; executed from factory |
| Approve MSK | Liz - List, Validate |
Enable secure access to Vault through Azure API Management
If secure factory-to-Vault connection is required, the Azure API Management Operation Driver must be activated.
Create factories
| Step | Action |
|---|---|
| 1 | Go to the Factory Management page |
| 2 | Click Create. A wizard launches |
| 3 | In the Owner step, pick the Manufacturer or Importer that owns the factory. Click Next |
| 4 | In the Details step, enter factory details. Click Next. Check License All Products to enable automatic licensing of all products to the factory |
| 5 | In the Validate step, review all entries and click Validate. The wizard closes |
| 6 | A GOV user must approve the factory. See Request Management |
Edit factories
| Step | Action |
|---|---|
| 1 | Go to the Factory Management page |
| 2 | In the grid, expand the factory to edit and click Edit. A wizard opens |
| 3 | In the Details step, edit factory details and click Next |
| 4 | In the Validate step, review all entries and click Validate. The wizard closes |
| 5 | A GOV user must approve the factory. See Request Management |
Manage connection details
| Step | Action |
|---|---|
| 1 | Using the Gate Administration GUI at the factory, request a new connection and download a certificate request file. For license versions 3.2.0.0 or older, this step should be omitted |
| 2 | Go to the Factory Management page |
| 3 | In the grid, expand the factory and click Manage Connection. A popup opens |
| 4 | Select a connection type and license version |
| 5 | Click Issue Certificate. Upload the certificate request file and download the license file. For license versions 3.2.0.0 or older, click Renew Certificate to download the license file |
| 6 | Click Save. The popup closes |
| 7 | Using the Gate Administration GUI at the factory, import the license file and enter the connection details |
Production line registration
| Step | Action |
|---|---|
| 1 | A Liz registration request is done from the Serializer Configuration GUI, not from the Vault |
| 2 | If the Liz Configuration reports message 227: Serializer {0} is signed by a non-trusted Certificate Authority, a GOV-role user with the required certificate operation rights must set the root certificate for the Liz as trusted |
| 3 | Optionally, a GOV user must approve the production line. See Request Management |
MSK registration
| Step | Action |
|---|---|
| 1 | From the Liz Configuration GUI, request an MSK |
| 2 | Depending on configuration, a GOV user may need to approve the MSK. The MSK is downloaded to the production line through the factory Gate |
| 3 | The MSK status eventually changes from Pending to Not Registered. From the Liz Configuration GUI, register the MSK |
| 4 | Only one MSK can be registered per Vault. If an MSK is already registered for the Vault, it must be unregistered before a new MSK can be registered |
| 5 | Depending on configuration, a GOV user may need to approve the MSK. See Request Management |
9 Product Licensing
Introduction
Product licensing to a Manufacturer or Importer is managed from the Vault website under Administration - Entity.
Product licensing to factories is managed from the Vault website under Administration - Factory.
- LE users, or GOV users acting on behalf of a Legal Entity, can manage product licensing to MAN / IMP entities if they have the required operation rights
- MAN / IMP users, or GOV users acting on behalf of a Legal Entity, can manage product licensing to their factories if they have the required operation rights
Operation rights required
| Action | Operation rights required |
|---|---|
| Add license to MAN / IMP | SKU2MAN - List, Create |
| Edit license to MAN / IMP | SKU2MAN - List, Edit |
| Add license to factory | SKU2Gate - List, Create |
| Edit license to factory | SKU2Gate - List, Edit |
License products to MAN / IMP and license products to a factory can be created or edited using the Excel Import Interface.
Add licensed products to a Manufacturer or Importer
If an entity has both LE and MAN and/or IMP roles, licensing is automatic for that entity and the steps below are unnecessary.
| Step | Action |
|---|---|
| 1 | Go to the Entity Management page |
| 2 | In the grid, expand the entity that products are licensed to and click Add or Edit Products. A wizard launches |
| 3 | In the Products step, click Show Product Picker. A popup opens |
| 4 | In the popup, select the products to license. Click Validate. The popup closes. Click Next |
| 5 | In the Validate step, review all entries and click Validate. The wizard closes |
Edit licensed product to a Manufacturer or Importer
| Step | Action |
|---|---|
| 1 | Go to the Entity Management page |
| 2 | In the grid, expand the entity that products are licensed to and click Add or Edit Products. The wizard launches |
| 3 | In the Products step, click Edit Product. A popup dialog opens |
| 4 | In the popup, edit the license and click Validate. The popup closes. Click Next |
| 5 | In the Validate step, review all entries and click Validate. The wizard closes |
License products to a factory
| Step | Action |
|---|---|
| 1 | Go to the Factory Management page |
| 2 | In the grid, expand the factory to license products to and click Edit. A wizard opens |
| 3 | In the Details step, click Next |
| 4 | In the Products step, click Show Product Picker. A popup dialog opens |
The uploaded extraction only provided the first part of the factory product licensing flow. If needed, this can be completed through a more focused extraction.
10 Request Management
Introduction
The requests feature was originally designed for use with a governmental Vault system.
Over time, the feature has become largely obsolete in some scenarios due to practical considerations.
Current state
Stock Keeping Units transmitted from a factory through the Gate system are automatically marked as approved in INEXLINE / INEXPRESS.
This automatic approval process exists for several reasons:
- Individual approval of each Stock Keeping Unit was time-consuming and impractical, even for governmental Vault systems
- The system evolved to streamline operations and may automatically approve Stock Keeping Units from trusted sources such as Gate
- The Stock Keeping Unit approval process is considered deprecated, although it may still exist for backward compatibility
Request visibility and approval
- Users associated with an entity having the GOV role can approve or reject requests if they have the necessary operation rights
- Users associated with any entity can view their own entity’s requests if they have the necessary operation rights
Operation rights required
| Request type | Operation | Rights required | Description |
|---|---|---|---|
| Account | Account | List | View or reject own pending entity requests |
| Account | Account | Validate | Accept or reject pending entity requests |
| Account | Account | Delete | Set entity as deleted |
| Certificates | Certificates | List, View, Manage | Accept or reject pending certificate requests |
| AdminTool | AdminTool | List, Create, Edit, Manage, Validate | Vault website plugin management, including Liz License Manager and SMDL subscription request management |
| Liz | Liz | List | View pending production line requests |
| Liz | Liz | Validate | Accept or reject pending production line requests |
| Estamp | Estamp2MAN | List | View or reject own pending e-stamp requests |
| Estamp | Estamp2MAN | Validate | Accept or reject pending e-stamp requests |
| Export | Export | List | View pending export requests |
| Export | Export | Validate | Accept or reject pending export requests |
| Factory | Gate | List | View pending factory requests |
When Liz approval is enabled, the government or administrator must explicitly approve each Liz registration.
11 User Rights
Introduction
On the Vault, roles are associated to an account.
Each role has a set of rights determined by the Vault owner. These mappings are defined in the RoleOperationMapping.xml configuration file.
Each account holder can create Vault users with their own credentials. The account holder can assign each user a set of rights, limiting access on the Vault.
The rights that a user can receive are limited by the rights associated with the roles held by the account holder.
Once a user is created, that user can create additional users if they have the required rights.
Operations
Rights are divided into operations, and operations are divided into levels.
The following operations exist on Vaults:
| Operation | Description |
|---|---|
| Account | Management of accounts |
| AdminTool | Plugin management on the Vault website, including Liz License Manager and SMDL replication |
| ApplicationSettings | Read and update Vault application settings |
| AuditHistory | View audit history, including configuration changes |
| Certificates | Register Liz configured with a license from another Vault |
| CheckCallCenter | Defines whether a city can be associated with a checked code when using call center |
| CheckCounterfeited | Defines whether a code can be marked as counterfeited |
| CheckOrigin | Defines which call types can be selected when checking a code |
| CheckPermutation | Defines whether a code can be rechecked with permutations, for example exchanging similar characters |
| CheckSUPI | Rights for checking a code and defining what information is shown when checking a code |
| CheckUsed | Defines whether a code can be marked as already used |
| CheckWaste | Defines whether a code can be seen and marked as waste |
| CodeExport | Defines whether a code can be marked as exported |
| ReportDamages | Defines whether a code can be marked as non-repairable damaged |
| ReportEndOfLife | Defines whether a code can be marked as end-of-life |
| ReportStolen | Defines whether a code can be marked as stolen |
| Liz | Management of MSKs, for backward compatibility only |
| Dashboard | Access to the dashboard |
| DlrMessages | Management and history of DLR messages if the DLR communication driver is enabled |
| EconomicOperators | Management of TPD Economic Operators |
| Estamp2MAN | Deprecated. Management of volume control allocations to MAN / IMP |
| Estamp2Gate | Deprecated. Management of volume control allocations to factories |
| Export | Export management |
| Facilities | Management of TPD facilities |
| FactoriesCodeFormats | Read access to the list of factory code formats |
| IdIssuers | Management of TPD ID issuers |
| IdIssuerHorizons | Configuration of horizons for TPD ID issuers |
| Machines | Management of TPD machines |
| Routing | Management of TPD routing rules |
| Messaging | Management of messages in the Vault Administration application |
| Monitoring | Read access to the Monitoring screen |
| MyReportInstance | Deprecated. Execution of private SSRS reports |
| MyReportItem | Deprecated. Management of private SSRS reports |
| MyReportSchedule | Deprecated. Management of private SSRS report schedules |
| PublicReportInstance | Deprecated. Management of public SSRS reports |
| ReportClass | Deprecated. Management of SSRS report user classes |
| ReportItem | Deprecated. Management of existing SSRS reports |
| ReportSchedule | Management of public report schedules |
| OperationDrivers | Management of operation drivers in Vault Administration |
| Orders | Management of TPD orders and primary code checks |
| PbiReportItem | Management of Power BI reports |
| PbiReportSchedule | Management of Power BI report schedules |
| PbiReportScheduleSub | Management of Power BI report subscriptions |
| PbiReportUserTag | Management of Power BI report users |
| SerializationOrders | Management of serialization orders |
| SatCodeReports | Management of SAT security code reports |
| SatReferenceData | Management of SAT reference data |
| SecurityCodeOrder | Management of SAT security code orders |
| SSCC | Management of SSCC |
| SSrsUsers | Deprecated. Management of SSRS users |
| Logs | Rights for viewing logs |
| Gate | Management of Gates |
| MSK | Accept or reject MSK requests |
| PROD | Management of production batches |
| Profile | Management of user profiles |
| ReferenceData | Management of serialization configurations |
| Role | Management of roles associated to an account |
| ServerInfo | Access to server information plugin |
| SKU | Management of Stock Keeping Units |
| SKU2MAN | Management of Stock Keeping Unit licensing from LE to MAN / IMP |
| SKU2Gate | Management of Stock Keeping Unit licensing from MAN / IMP to Gate |
| TaxLevel | Management of product groups when tax level support is enabled |
| User | Management of users |
| Waste | Management of waste |
| VirtualLizs | Management of virtual Liz instances |
| VaultAdminReporting | Access to Vault Administration reports |
An operation is mostly related to access rights for a given web page or related subpages. For operations starting with Check, the operations relate to functions and features on the Check Code page.
12 Managing the Settings
Vault settings are documented in the Vault Administration application settings.
Default values ensure a correct installation. If needed, settings can be adjusted for specific scenarios with help from the support team.
Cleanup settings are documented separately in the cleanup configuration documentation.
13 Vault Management and Processes
Entities, roles, users, and profiles
The Vault access model is based on the following structure:
| Object | Description |
|---|---|
| Entity | Typically one per stakeholder |
| Role | Defines permissions and functionalities inherited by the entity |
| Profile | Defines a set of permissions for a group of users |
| User | Assigned a subset, or all, of the privileges that the entity has |
An entity can have several roles.
Multiple profiles can exist per entity.
Multiple users can exist per entity.
A user receives privileges either through assigned profiles or explicit permission assignment.
The privileges given to a role are configurable and are defined by the Vault owner.
Vault roles
There are four roles on government Vaults.
ADM / GOV role
The ADM role, also referred to as GOV, is for entities that own or administer the Vault.
Depending on the industry, this entity can represent a governmental institution. The terms ADM and GOV are used interchangeably in the source document.
Main tasks:
- Control and monitor the Vault
- Manage users
LE role
The LE role is for a Legal Entity.
Main tasks:
- Register and manage products intended to be sold on the local market controlled by the administrator entity
- License products to a domestic Manufacturer and/or Importer entity
- Place e-stamp orders and assign them to a domestic Manufacturer or Importer entity
- Manage users
MAN role
The MAN role is for a domestic Manufacturer.
This means a manufacturer that has production sites in the same country as the Vault, with the intention to sell on the local market and/or export to other markets.
Main tasks:
- Register manufacturing sites and machines
- License products to factories
- Assign e-stamps to factories
- Monitor production
- Manage users
IMP role
The IMP role is for an Importer.
Importers import products intended to be sold on the local market where the Vault is installed. Products are produced at manufacturing sites in another country.
Main tasks:
- Register manufacturing sites and lines
- License products to factories
- Assign e-stamps to factories
- Monitor production
- Manage users
14 Products and Product Licensing Process
The product and licensing process can be summarized as follows:
- An entity with the LE role registers products, meaning Stock Keeping Units
- Optionally, GOV approves or rejects the products
- The LE licenses products to MAN and/or IMP entities
- MAN / IMP entities license products to factories
- Factories, represented by Gates, can then use the licensed products
15 Vault Business Scenarios
Overview of Vault types and structure
Inextor uses two main types of Vaults to store and manage production data:
- Private Vaults: used by manufacturers to manage their own production data
- Government Vaults: used by government agencies to monitor production in their jurisdiction
Core components
Every Vault consists of:
- Entities, representing manufacturers, factories, or markets
- Users, representing people who need access to Vault data
- Roles, defining permissions and data access
- Data segregation rules, controlling what data each user can see
Main roles
| Role | Description |
|---|---|
| Administrator / ADMIN | Has full access to all data and functions, can override data segregation rules, but permissions can still be restricted per user |
| Legal Entity / LE | Can define and create products in the Vault and controls product definitions |
| Manufacturer / MAN | Produces goods and belongs to the Vault owner entity; used for affiliates or subsidiaries |
| Importer / IMP | Produces goods but does not belong to the Vault owner; used for third-party manufacturers |
Access control flow
- Each user is assigned to exactly one entity
- Entities are given roles that define base permissions
- Users inherit permissions from their entity’s roles
- Individual user permissions can be restricted within the entity’s roles
Role combinations and rules
- A factory can be either MAN or IMP depending on its relationship to the Vault owner
- An entity with LE and MAN roles can have factories only as MAN
- An entity with LE and IMP roles can have factories only as IMP
- An entity with MAN and IMP roles can have factories as either MAN or IMP
Data segregation methods
Data visibility can be controlled in four ways.
By market
Users see data for specific assigned markets.
This shows production from all factories for those markets. Users cannot see production for other markets.
By factory
Users see data from specific assigned factories.
This shows all markets those factories produce for. Users cannot see data from other factories.
By market and factory
This is the most restrictive option.
Both criteria must match for the user to see the data.
No segregation
Administrators have full visibility of all data.
Production order data access
There are two key entity associations per production order:
- Product-owning entity
- Factory-owning entity
Users can see production data from their assigned entity perspective.
Gate-Vault connections
- Each Gate connects to only one Vault
- Each Gate reports data under a single Vault entity
- A one-to-one relationship is required
Product definition setup
Product definitions, or Stock Keeping Units, can be created in two ways:
- Created on Gate and sent to Vault, which is the most common flow
- Created directly in Vault
16 Managing the Operation Drivers
Operation drivers can be managed from:
- Plugins in the Vault website
- Configuration → Op. Drivers in the Vault Administration Client
Operation drivers are custom components that expose either:
- Web services
- Background tasks
Vault operation drivers
| Operation driver name | When to use |
|---|---|
| Vault ATTP Communication Driver | To link the Vault to ATTP in order to send commissioning events or code pairing events |
| Vault Azure API Management Driver | To use Azure API Management to secure access to the Vault |
| Vault Code Storage Driver | To store SUPIs generated during productions involving Inextor codes |
| Code Transmission Driver | Obsolete and unused |
| Dentsu Primary Repository Code Transmission Driver | To upload codes into the Dentsu Primary Repository as if it were the EU Router, for testing purposes |
| DLR Communication Driver | To send commissioning or code pairing events to DeLaRue for productions involving TPD and DLR regulations |
| External Code Driver | To extract the contents of a code chunk, typically 20,000 codes, using the Vault administration program |
| Primary Code Check Driver | To check that TPD codes received from an ID issuer are considered valid by the Primary |
| TPD Notification Driver | To notify an external system about specific TPD events on the Vault, such as order sent to ID issuer, downloaded codes, or errors |
| User Notifications Driver | To send mail when events occur on the Vault |
| Vault Telemetry Driver | To measure and store traffic between Gate and Vault |
| Zetes Driver | To send TPD external codes received by the Vault to the Zetes repository |
17 Installation Types
Azure deployment
Azure deployment:
- Requires coordination with the IT & Infrastructure team
- Uses Azure IAM for user management
- Uses the Vault website user administration process for user management details
On-premises deployment
On-premises deployment:
- Requires local server access
- Requires IIS configuration
- Requires manual service setup
- Requires local infrastructure and application configuration
18 Pre-Installation Tasks
Certificate preparation
For Small Tobacco Manufacturer scenarios:
- Import TP certificates to the root Vault
- Generate required licenses
- Use the Certificate Tool
Certificates to import into the Windows Certificate Store:
- Root certificate
- TP certificate
- Vault certificate
Database preparation
Database preparation includes:
- Verifying SQL Server installation
- Ensuring appropriate permissions
- Following Vault database administration guidance
.NET Framework verification
.NET Framework verification includes:
- Checking the installed version against the technical overview
- Installing required components where needed
19 Installation Steps
Azure deployment
- Contact the IT & Infrastructure team for deployment
- Verify Azure subscription and permissions
- Follow the deployment process specified by the IT team
On-premises deployment
IIS setup
- Follow IIS configuration setup
- Configure application pools
- Apply required IIS configuration
Binary file deployment
- Copy software files to the designated location
- Configure services
Database installation
Deploy the database using DACPAC according to the Vault database administration guidance.
20 Post-Installation Configuration
Vault configuration
- Define the Vault code, typically three letters
- Configure Liz ranges for the customer
Entity setup
- Create the entity with LE and MAN roles according to Vault Business Scenarios
- Configure it using the Vault website under Administration - Entity
Factory configuration
- Create a factory associated with the entity
- Enable the License All Products option
- Use the Vault website under Administration - Factory
Connection setup
- Process the Gate request file
- Establish connections
- Follow the Vault website Factory Administration process
User management for Azure
- Create IAM users
- Configure access permissions
Audit configuration
- Enable Audit Log manager
- Configure audit settings according to Audit Log Manager guidance
21 Verification
After setup, verify:
- Database connectivity
- Certificate installation
- Entity and factory setup
- Connections
- Audit logging