Skip to main content
Who can do what, and how widely. The access settings screen

Why this is one screen

Roles, site scope and asset scope only mean anything together. Edited as three unrelated tables they are how somebody grants far more than they meant to.

The rule that catches people out

No grants means unrestricted. A user with no site rows can see every site.So adding somebody’s first site silently narrows them from everything to one, and deleting their last silently widens them to everything. In a plain table those two edits look identical and are opposite in effect.
This screen says “every site” in as many words where that is the situation, rather than leaving a blank column that says nothing.

People

Add a person on this screen. Each row also carries Edit and Remove. The user is issued a password and asked to change it on first sign-in, because somebody other than its owner knows it.

Roles, sites and assets for one person

Expand a person’s row and their grants appear as three panels side by side — Roles, Sites, Assets — each with its own Grant a… control. Add or remove a grant in one panel without touching the others.
The Sites panel is where the “no grants means every site” rule lives day to day. Granting the first site narrows that person to just it; removing the last site grant widens them back to every site. There is no in-between state that means “no sites.”

Roles

A role is a bundle of permissions. Give somebody more than one and they get the union. Add a role on this screen, with Edit and Delete per row. Deleting a role that people currently hold shows how many, as a warning — the people themselves aren’t deleted, just left without that role’s grants.
System roles — the built-in ones, like System Administrator or Technician — can’t be deleted. Only Edit shows for them. Deleting one could strip admin capability from the whole organisation with no way to get it back, so the option isn’t offered.
The twelve defaults cover most plants. See the role reference for exactly what each can do, and for what editing a system role does and doesn’t change.

Permissions

Open a role and its permissions are a grid: one row per resource, grouped under module headings, one column per action — View, Create, Edit, Assign, Close, Export, Delete, Approve, Admin. The dangerous verbs, Delete, Approve and Admin, are flagged so they don’t get granted by accident while scanning down a column. A cell is one of three things:
A search box finds a module or resource by name, and a filter narrows the grid to only the permissions the role already has. A live count shows how many are granted, updating as you go.
Three levels of bulk toggle, each scoped to whatever’s currently visible or filtered:
  • Column header — grant or revoke a whole verb, e.g. every Export permission on screen.
  • Module band — grant or revoke everything under one module heading.
  • Row label — grant or revoke every verb on one resource.
A bulk change shows a “Saving X of Y…” progress indicator while it applies, since granting a verb across dozens of resources is one click but many writes.

Site and asset scope

Two levels of narrowing, both optional, each its own panel on a person’s row:
  • Site access — which plants this person may reach.
  • Asset access — which machines, for cases where even one site is too wide. A contractor maintaining only the compressors is the usual reason.
Scope is enforced by the server on every read, not by hiding menu items. A user who cannot reach a site cannot reach it by typing a URL either.

Changing somebody’s access

Changes take effect on their next request. Somebody whose access is narrowed while signed in stops seeing what they lost immediately — they do not need to sign out.

Removing somebody

Remove rather than delete. Their history — the jobs they closed, the hours they booked, the readings they took — stays attached to them, which is what makes the record worth having. Removing ends their sessions and their sign-in.
Removing is permanent. There’s no undo.If the intent is temporary — leave, suspension, an investigation — don’t remove. Set their status to suspended on the person’s edit form instead. That’s reversible; removal isn’t.
If they had a handset, revoke the device too, from the Sync Center.

Users and workers

Different records. A user signs in; a worker does maintenance. Most technicians are both, and linking them is what lets the app know whose work “my work” means. Workers are managed under technicians.