Skip to content

Add Required Permissions sections to Host Discovery wizard pages - #1315

Open
tay-caliguiri wants to merge 2 commits into
devfrom
naa-host-discovery-lpm-doc
Open

Add Required Permissions sections to Host Discovery wizard pages#1315
tay-caliguiri wants to merge 2 commits into
devfrom
naa-host-discovery-lpm-doc

Conversation

@tay-caliguiri

Copy link
Copy Markdown
Contributor

Documents the permission requirements for each Host Discovery source type (IP scan, AD queries, CSV/database import) and for the optional Inventory Refresh chained onto each.

Documents the permission requirements for each Host Discovery source type (IP scan, AD queries, CSV/database import) and for the optional Inventory Refresh chained onto each, carried over from the staged LPM drafts.

Generated with AI

Co-Authored-By: Claude Code <ai@netwrix.com>
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Documentation PR Review

This PR appends a Required Permissions section to each of the six Host Discovery Wizard source pages, in both the 11.6 (Enterprise Auditor) and 12.0 (Access Analyzer) versions. The new content is well-organized, appropriately scoped for a security-conscious admin audience, and placed sensibly at the end of each procedure. The findings below are mostly consistency issues; none block merge.

Editorial Review

Recurring across all 12 files — bolded option name doesn't match the wizard

Every new section refers to the Inventory option as Refresh inventory every time the host discovery query completes, but Step 5 in the body of each same page labels the control Refresh inventory every time when the host discovery query completes (note the "when"). A reader who cross-references the bolded text back to the Inventory page will see two different labels for the same checkbox.

  • Clarity — Align the bolded option name in each Required Permissions section with the exact label used in Step 5 (or vice versa) so the UI reference is verbatim. Applies to: addomaincontrollers.md, adexchange.md, adgeneral.md, csv.md, database.md, and ipnetwork.md in both 11.6/ and 12.0/.

docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/addomaincontrollers.md (and 12.0/…/addomaincontrollers.md)

  • Structure — Line 145 (11.6) / ~143 (12.0): The inventory caveat is placed inside the :::info admonition here, combined with the "high-value target" note. On the sibling pages (adgeneral.md, csv.md, database.md, ipnetwork.md) the equivalent inventory paragraph sits as standalone body text after the admonition. Consider a consistent treatment across the wizard set so the pages read uniformly. Suggested fix: keep the DC-specific "high-value target" guidance in the :::info block and move the generic "Refresh inventory…" sentence out to a following paragraph, matching the other pages.

docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/adexchange.md (and 12.0/…/adexchange.md)

  • Clarity — Lines 120–125 (11.6): The section uses three phrasings for the same forest-wide store — "Exchange Configuration container", "Configuration partition", and "Configuration naming context" — within two sentences. A newer admin may not realize these refer to the same thing. Suggested fix: use one term consistently (for example, "Configuration partition") or add a short clause noting the naming context and the partition are the same store.
  • Bold option name — See the recurring finding above.

docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/adgeneral.md (and 12.0/…/adgeneral.md)

  • No issues found beyond the recurring bold-option-name finding above. The :::info note on Tier 0 / restricted OUs is a helpful, well-placed caveat.

docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/csv.md (and 12.0/…/csv.md)

  • Clarity — Lines 132–136 (11.6): "the Console service account's own permissions" introduces the phrase "Console service account," while the surrounding text uses "the Enterprise Auditor Console server" (11.6) / "Access Analyzer Console server" (12.0). Suggested fix: make the connection explicit on first use — for example, "the Console service account (the account the Console runs under)" — so the reader knows which credential is meant.
  • Bold option name — See the recurring finding above.

docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/database.md (and 12.0/…/database.md)

  • No issues found beyond the recurring bold-option-name finding above. The :::info least-privilege note and the "Use Windows NT Integrated security" paragraph both tie back cleanly to Step 3.

docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/ipnetwork.md (and 12.0/…/ipnetwork.md)

  • Clarity — Lines 151–154 (11.6): The :::info block refers to "Host Inventory Refresh," but the actual control is the Refresh inventory every time… checkbox on the Inventory page. Using an informal name risks the reader looking for a control that isn't labeled that way. Suggested fix: use the exact option name, e.g. "…only becomes relevant if Refresh inventory every time the host discovery query completes is also enabled (see below)."
  • Bold option name — See the recurring finding above.

Summary

1 recurring consistency issue (bolded option name vs. the Step 5 label) across all 12 files, plus 3 file-specific clarity notes and 1 structural-consistency note. No blocking issues — the sections are accurate, appropriately scoped, and correctly placed. Vale and Dale issues are auto-fixed separately.


What to do next:

Comment @claude on this PR followed by your instructions to get help:

  • @claude fix all issues — fix all editorial issues
  • @claude help improve the flow of this document — get writing assistance
  • @claude explain the voice issues — understand why something was flagged

You can ask Claude anything about the review or about Netwrix writing standards.

Automated fixes are only available for branches in this repository, not forks.

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

94 issues fixed, 27 skipped across 12 files

Category Fixes
Contractions 38
Substitutions 10
AllowsYouTo (rewrite) 2
FollowTheStepsTo (rewrite) 12
FormalHedging (rewrite) 12
TypeVsEnter (rewrite) 4
Dale: passive-voice 12
Dale: positional-references 4
Skipped (needs manual review) Reason
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/addomaincontrollers.md:30 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label (contrasts with 'Credentials in this connection profile'); changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/addomaincontrollers.md:109 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/adexchange.md:31 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/adexchange.md:89 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/adgeneral.md:31 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/adgeneral.md:113 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/csv.md:41 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/csv.md:105 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/database.md:36 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/database.md:129 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/ipnetwork.md:30 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/11.6/admin/hostdiscovery/wizard/ipnetwork.md:120 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/addomaincontrollers.md:30 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/addomaincontrollers.md:108 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/adexchange.md:31 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/adexchange.md:87 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/adgeneral.md:31 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/adgeneral.md:112 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/csv.md:41 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/csv.md:104 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/database.md:36 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/database.md:128 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/ipnetwork.md:30 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/ipnetwork.md:119 — Netwrix.FirstPerson 'Credentials in my default connection profile' is a verbatim product UI radio-button label; changing 'my' would misrepresent the interface
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/database.md:165 — Dale: passive-voice 'If Use Windows NT Integrated security is selected' is an idiomatic UI conditional used consistently throughout the wizard docs; rewriting would break established style.
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/csv.md:130 — Dale: passive-voice 'No domain credentials are required' is a stative construction; an active rewrite would force second person and change the neutral overview tone.
docs/accessanalyzer/12.0/admin/hostdiscovery/wizard/ipnetwork.md:155 — Dale: xy-slop 'This confirms network reachability, not that any particular service is running' is a genuine clarification of scope, not filler negative-positive slop; removing it would lose meaning.

Ask @claude on this PR if you'd like an explanation of any fix.

@tay-caliguiri tay-caliguiri added the access-analyzer This change or issue involves Access Analyzer. label Aug 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

access-analyzer This change or issue involves Access Analyzer.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants