September 2026 release is live Read More

Datacenter User creation

Below are the steps for creating the users in the data center

Why this matters: Mavvrik only needs read-only visibility into your vCenter environment to report on cost and utilization — it never needs to modify anything there. Creating a dedicated read-only user (rather than reusing an admin account) keeps that boundary explicit and makes it easy to see exactly what access Mavvrik has, and to revoke it cleanly if needed.

Before you start: you'll need Administration access in vCenter to create users and assign permissions.

  1. Login to vCenter and navigate to Administration Tab under the Menu section

Open vCenter Administration
Open vCenter Administration
  1. Under Left side nav bar > Single Sign On > Users and Groups. Then:

  1. In Users and groups select your domain eg: vsphere.local

  2. Click on Add User> Enter all the required details

Create the vCenter user
Create the vCenter user
  1. Then Navigate to Host and Clusters under the Menu section. Then:

  1. Then Select your Datacenter and select the Permissions tab.

  2. then click on the + symbol

Open datacenter permissions
Open datacenter permissions
  1. then add permission, select your user and select role as Read-only and check the box for Propagate to children.

Assign the Read-only role and propagate permissions
Assign the Read-only role and propagate permissions

Troubleshooting

  • If Mavvrik isn't picking up all your datacenter resources after setup, check whether Propagate to children was checked when assigning the Read-only role — without it, the permission only applies to the Datacenter object itself, not the clusters, hosts, and resources beneath it.

FAQs

Why does Mavvrik need a dedicated Read-only user instead of reusing an existing admin account?
Mavvrik only needs visibility into cost and utilization data — it never modifies anything in vCenter. A dedicated, read-only user keeps that boundary explicit, makes it easy to see exactly what access Mavvrik has, and lets you revoke it cleanly if needed.

What does "Propagate to children" actually do?
It extends the Read-only role assigned at the Datacenter level down to every cluster, host, and resource underneath it. Without checking it, the role only applies to the Datacenter object itself, leaving everything below it inaccessible.