Access Controller manual Download PDF

Chapter 12

Users, roles and permissions

A user is a staff login for the panel. Users belong to one tenant and have a role that decides which pages they can see and which they can change. People who open doors (chapter 6) are not users and never log in.

The Users page: the user list with role badges and password reset, the add-user toolbar, and the custom roles section.
The Users page: the user list with role badges and password reset, the add-user toolbar, and the custom roles section.

The built-in roles

RoleCan seeCan changeNotes
Super adminEverything in every tenant, plus the Tenants pageEverythingThe provider's account. Switches between tenants. Created only from the server command line (chapter 16), never from the panel.
AdminEvery page in their own tenantEverything in their tenantThe normal account for an owner or office manager. Can create other admins, viewers and custom roles.
ViewerEvery operational page in their tenant (not Settings)NothingRead-only. Edit controls are hidden, not merely disabled, and any attempt to post a change is refused. Good for front-desk staff who only need to look people up and watch the log.
CustomExactly the pages ticked in the roleExactly the pages ticked as "change"Built by an admin on the Users page.

The role of the signed-in user is shown as a badge at the bottom of the sidebar.

Creating a user

On Users, in Add user: type a username, a password of at least 8 characters, choose Viewer, Admin or one of your custom roles, and press Create user. Usernames must be unique across the whole panel. The new user can sign in straight away.

Resetting a password

There is no self-service reset. In the user's row type a new password (at least 8 characters) into Reset password and press Set. Tell the user the new password out of band and ask them to change it. (Users change their own password the same way, on their own row.)

Removing a user

Press Remove on the row (not available on your own account). Any session the user has is ended.

Custom roles

A custom role is a tick list of pages. Open Users, type a role name in New role ("Front desk", "Membership team", "Installer") and press Create and pick pages.

The role editor: the page tree with a View and a Change tick per page, and quick-set buttons.
The role editor: the page tree with a View and a Change tick per page, and quick-set buttons.

The editor shows the pages as a tree in sidebar order. For each page:

Some pages behave differently:

Quick set buttons tick all View, tick all Change, or untick everything. Press Save role. Pages not ticked disappear from the user's sidebar, and opening them by address redirects the user to the first page they may see with the message "You do not have access to that page". Any attempt to post a change to a page without the Change tick is refused with "read-only account".

Assign a custom role when creating a user (the role appears in the role drop-down as "custom role"). On the Users page the role name is a link to its editor, and the Custom roles table shows how many users each role has and a summary of what it grants. Delete on a role turns its users into viewers.

Suggested roles

RoleViewChangeFor
Front deskDashboard, People, Log(none)Reception staff who look people up and read the log. Or simply use Viewer.
Membership teamDashboard, People, LogPeople, Enrolment & importStaff who add members and fobs but must not touch doors or schedules.
InstallerDoors, ControllersDoors, Controllers, Flash & adopt, SettingsA contractor commissioning hardware who should not see people.
Managereverything except Users and SettingsPeople, Enrolment, Access levels, Schedules, DoorsA site manager who runs the day to day but does not administer accounts.
ConciergeDashboard, People, Log, BookingsBookingsFront-desk staff for a block with bookable rooms: they can take a booking at the desk, mark a bank transfer paid and cancel, but cannot change people or doors.

What permissions do not cover