Skip to content
Back to Help Center
Article In category: Operations Center

Available operations and their risk tiers

Published: 2026-08-12 Last updated: 2026-08-13

Everything you can run, split into read, safe write and guarded write, with how many routers each accepts.

These are all the operations available today. The number in brackets is the maximum routers one operation accepts — deliberately low for the dangerous ones.

Read — changes nothing on the device

  • Full diagnostic (50) — a complete report on the router's health, link and resources.
  • Check RouterOS updates (50) — installed and available versions on the selected channel.

These are completely safe and suitable for scheduled recurring runs.

Safe write — cannot affect your link to the device

  • Add a hotspot user (50)
  • Add a User Manager user (50)
  • Set the RouterOS update channel (50) — decides which release the device considers "latest", with no reboot.

Guarded write — typed confirmation, one router at a time

These touch configuration or operating state that could cut the link, so they run sequentially. Reversible configuration changes take a backup and arm automatic rollback. Upgrades, reboots and package activation have no safe remote inverse, so they use stricter preflight and prove that the same device returned instead.

Provisioning and setup

  • Provision a customer router (bridge + hotspot) (1) — detects the internet uplink, bridges the remaining ports, and builds the whole hotspot.
  • Provision hotspot on a new router (3)
  • Set up User Manager (wipe and rebuild) (1)
  • Install or enable the User Manager package (5)
  • Enable a feature blocked by device mode (1) — for devices that arrive with hotspot switched off from the factory.

Protection and maintenance

  • Block connection sharing (hotspot bridge) (50) — stops a subscriber re-sharing the service to other devices.
  • Enable NTP time sync (50) — lets the router recover the correct time after a power cut.
  • Upgrade RouterOS (3)
  • Upgrade the RouterBOOT bootloader (10)
  • Reboot the router (10)

Removal — irreversible

  • Remove the hotspot entirely (1) — removes the server, profiles, DHCP, addresses, pools and its NAT rule without touching the internet uplink or WireGuard. Vouchers and the bridge survive unless you explicitly include them.
  • Remove User Manager entirely (1) — returns the hotspot to local authentication, then removes its RADIUS client, NAS entry and User Manager NAT rules; the hotspot itself stays operational.
  • Purge all hotspot vouchers permanently (1) — disconnects active sessions, clears login cookies, then removes every hotspot user while preserving all hotspot configuration.
  • Purge all User Manager vouchers permanently (1) — removes users, their profile assignments, sessions and payment rows while preserving global profiles, limitations, NAS, RADIUS and hotspot configuration.

Advanced

  • Custom command (20) — a structured command (path + fields) whose risk is classified automatically before it is allowed. It is not a free shell: paths that could cut off management are forbidden.

Why do the router limits differ?

Read and safe-write operations accept larger sets, while provisioning and upgrades use smaller limits, and permanent deletion is limited to one router. This forces a fresh confirmation and review before each sensitive batch. To cover more devices, use Campaigns, noting that permanent voucher purges remain manual-only.

Related articles

Back to category: Operations Center

Article image viewer

Still need help?
Contact us