Console Access and Roles
4 min read · Last updated · Page version 7
Squirrel has three roles. Which one somebody needs depends on whether they configure archiving, run it, or are simply working with their own files.
| Role | Where they work | What they can do |
|---|---|---|
| Squirrel administrator | Squirrel Administrator Portal, every page | Configure policies and settings, run archive and restore, view Burrow security pages |
| Archive administrator | Squirrel Administrator Portal, restricted view | Run and monitor archive and restore, review what has been archived. No policy or settings access |
| End user | SharePoint, Teams and OneDrive only | Archive and restore their own files from the buttons in their document library, or from a stub |
All three are governed by your existing Microsoft 365 identity and SharePoint permissions - there is no separate Squirrel user directory to maintain. Each role is covered in full below.
Squirrel administrators (full portal access)
Squirrel administrators sign in to the Squirrel Administrator Portal using their Microsoft 365 credentials, with Multi-Factor Authentication required. They have access to every page in the portal - it is the central administrative interface for the platform, giving them control over:
- Archiving and retention policies, including global settings and site-level custom policies
- Archive and restore queues and job history
- Dashboard metrics and reports on storage consumption and savings
- Audit logs of platform activity
- Document library and path exclusions
Only users granted full Squirrel administrator access to your organisation's personalised Squirrel URL get this complete view.
The Burrow security pages are full-administrator only. They do not appear for archive administrators, and they are not reachable by typing the URL either - the pages are gated to the same role as the tab that leads to them. Burrow surfaces who did what with company data, so it is treated as a separate privilege from running archive and restore jobs.
Archive administrators (restricted portal access)
Archive administrators sign in to the same Squirrel Administrator Portal with their Microsoft 365 credentials and MFA, but they see a restricted view built for day-to-day archive and restore work - not the configuration and policy controls. Their portal is limited to:
- Dashboard - storage and archive metrics at a glance
- Archived Files and Orphaned Files - what has been archived, and recovery of any orphaned content
- Archive/Restore by path - run archive and restore operations by path
- Activity Monitor - live archive and restore job activity
- History - a record of past archive and restore activity
They can run and monitor archive and restore activity and review what has been archived, but they cannot change archiving policies, global or site-level settings, document-library exclusions, or reporting - those stay with full Squirrel administrators.
End users
End users never leave SharePoint, and they get no access to the Squirrel Administrator Portal at all. They interact with Squirrel entirely from within SharePoint - through the archive and restore buttons in their document libraries, and by clicking the restore link inside a stub file - and their access is governed entirely by SharePoint permissions:
- Users can archive and restore content only in libraries they already have access to.
- Stub files inherit their permissions from the parent document library, so archived content remains visible only to users who could see the original file. Opening a stub and clicking its restore link brings the original file back - the same restore, initiated from the stub rather than a library button.
- External guests with access to a library can trigger a restore of archived content in that library, consistent with the access they were granted in SharePoint.
There are no separate Squirrel accounts or passwords to manage for end users - permissions follow SharePoint, so your existing access governance applies unchanged.
Summary
| Role | Access | Governed by |
|---|---|---|
| Squirrel administrator | Full portal: policies, settings, exclusions, queues, reports, audit logs | Microsoft 365 sign-in with MFA to your organisation's portal |
| Archive administrator | Restricted portal: dashboard, archived and orphaned files, archive/restore by path, activity monitor, history - no policy, settings, or reporting access | Microsoft 365 sign-in with MFA to your organisation's portal |
| End user | No portal access: archive and restore buttons in SharePoint document libraries, plus the restore link inside a stub file | Existing SharePoint permissions |
If you need to change who has Squirrel administrator or archive administrator access to your portal, contact support@smikar.com.