Many organizations don't have a defined protocol for adding permissions to vCenter. It often ends up being a convuluted web of explicit user and group permissions added at various levels of vCenter. This can make it difficult to troubleshoot suspected permission related issues.
Is there a way to determine a particular user's effective rights to the environment? With just a user name, I'd like to be able to determine what permissions he has been grantedth across the vCenter permissions hierarchy.