Console Access and Roles
4 min read · Last updated · Page version 4
Squirrel separates access into three roles: Squirrel administrators, who manage the whole platform through the Squirrel Administrator Portal; archive administrators, who use a restricted view of the same portal for day-to-day archive and restore operations; and end users, who archive and restore content directly in SharePoint. Each role has a distinct set of capabilities, and access for all three is governed by your existing Microsoft 365 identity and SharePoint permissions.
Squirrel administrators (full portal access)
Squirrel administrators sign in to the Squirrel Administrator Portal using their Microsoft 365 credentials, with Multi-Factor Authentication required. They have access to every page in the portal - it is the central administrative interface for the platform, giving them control over:
- Archiving and retention policies, including global settings and site-level custom policies
- Archive and restore queues and job history
- Dashboard metrics and reports on storage consumption and savings
- Audit logs of platform activity
- Document library and path exclusions
Only users granted full Squirrel administrator access to your organisation's personalized Squirrel URL get this complete view.
Archive administrators (restricted portal access)
Archive administrators sign in to the same Squirrel Administrator Portal with their Microsoft 365 credentials and MFA, but they see a restricted view built for day-to-day archive and restore work - not the configuration and policy controls. Their portal is limited to:
- Dashboard - storage and archive metrics at a glance
- Archived Files and Orphaned Files - what has been archived, and recovery of any orphaned content
- Archive/Restore by path - run archive and restore operations by path
- Activity Monitor - live archive and restore job activity
- History - a record of past archive and restore activity
They can run and monitor archive and restore activity and review what has been archived, but they cannot change archiving policies, global or site-level settings, document-library exclusions, or reporting - those stay with full Squirrel administrators.
End users
End users never leave SharePoint, and they get no access to the Squirrel Administrator Portal at all. They interact with Squirrel entirely from within SharePoint - through the archive and restore buttons in their document libraries, and by clicking the restore link inside a stub file - and their access is governed entirely by SharePoint permissions:
- Users can archive and restore content only in libraries they already have access to.
- Stub files inherit their permissions from the parent document library, so archived content remains visible only to users who could see the original file. Opening a stub and clicking its restore link brings the original file back - the same restore, initiated from the stub rather than a library button.
- External guests with access to a library can trigger a restore of archived content in that library, consistent with the access they were granted in SharePoint.
There are no separate Squirrel accounts or passwords to manage for end users - permissions follow SharePoint, so your existing access governance applies unchanged.
Summary
| Role | Access | Governed by |
|---|---|---|
| Squirrel administrator | Full portal: policies, settings, exclusions, queues, reports, audit logs | Microsoft 365 sign-in with MFA to your organisation's portal |
| Archive administrator | Restricted portal: dashboard, archived and orphaned files, archive/restore by path, activity monitor, history - no policy, settings, or reporting access | Microsoft 365 sign-in with MFA to your organisation's portal |
| End user | No portal access: archive and restore buttons in SharePoint document libraries, plus the restore link inside a stub file | Existing SharePoint permissions |
If you need to change who has Squirrel administrator or archive administrator access to your portal, contact support@smikar.com.