Who can reach what
There are three cases here, and only the first is what people assume. Every setting, credential and run control is checked on the server when it runs, not in the page when it loads. Reading is not checked at all. And Check now is neither: it is offered wherever the panel renders, which means anyone who can view the work item, and the server acts on the device id it is given rather than re-deriving who is asking — which is why it is rate-limited. This table is what actually happens rather than what a button looks like.
Reading is open
The dashboard and the CSV export are available to any licensed Jira user. It is a list of your hardware estate — treat it as you would a Jira project people can browse. A non-administrator is told plainly why the run controls are unavailable, in text, rather than shown four disabled buttons and left to press one.
Acting is not
Every setting, every credential and every run control is administrators only, enforced server-side. Check now is the one deliberate exception: any viewer of a work item may press it, because the repair-or-replace decision belongs to whoever is holding the ticket. It spends a real manufacturer lookup, so it is rate-limited to once every fifteen minutes for a given device.