Might be dumb question, but won't this configuration need admin ssh access to add required rules and local server to log that traffic?
Though if there are other remote access vulnerabilities, someone may be able to use the feature maliciously once they're in.
> Calea provided options are available only for specific RouterOS user, as Calea server configuration as "tap" configuration. Specific user should have 'sniff' policy enabled at RouterOS user configuration
So the admin has to set up a user account on the device.
So it can be both - dedicated user with the appropriate permission, or admin himself.