Global Access
SMART fleet default: Set to "Grant all servers" to automatically SMART-allow every server, new and existing. Use "Don't auto-grant" to manage SMART on a per-server basis from the Access List tab.
Firewall fleet access: Should normally stay Enabled. Disabling it flushes all managed iptables chains from every online node and blocks client API calls until you re-enable. "Disable & revoke all" does this and also deletes every per-server and per-user grant. This cannot be undone.
Hide tab when not granted: Removes the Firewall tab from servers and users without a grant. Users and servers with an explicit grant still see it regardless.
User / Server Access
Add a grant to give or deny SMART and Firewall access for a specific server or user, overriding fleet defaults. User overrides take priority over server overrides. Use the server's UUID from its admin page for server grants, and the numeric user ID from Admin > Users for user grants.
Access List
Server profiles: Live access state for every server. The profile columns show stored values; the effective columns show the final resolved state after overrides. Use the action buttons to grant or revoke on a per-server basis.
Access grants: All active per-user and per-server overrides. Remove any that are no longer needed.