Every permission as it appears in Settings → Permissions, what it allows, and the default for
each role.
Legend: ✅ granted by default · ❌ not granted. The matrix is editable —
see Permissions.
Pipelines
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| View pipelines | See pipelines and their definitions | ✅ | ✅ | ✅ | ✅ |
| Create pipelines | Create a pipeline | ✅ | ✅ | ✅ | ❌ |
| Edit pipelines | Edit a pipeline; delete variables; query introspection | ✅ | ✅ | ✅ | ❌ |
| Delete pipelines | Delete a pipeline | ✅ | ✅ | ✅ | ❌ |
| Run pipelines | Run once; trigger a single node | ✅ | ✅ | ✅ | ❌ |
| Start and stop pipelines | Start/stop, and start-all/stop-all | ✅ | ✅ | ✅ | ❌ |
| Export pipelines | Export a pipeline | ✅ | ✅ | ✅ | ❌ |
| Import pipelines | Import a pipeline | ✅ | ✅ | ✅ | ❌ |
| Configure variable storage | Change the variable persistence mode | ✅ | ✅ | ✅ | ❌ |
| View execution logs | Read execution and node-execution logs | ✅ | ✅ | ✅ | ✅ |
| Clear execution logs | Delete execution logs | ✅ | ❌ | ✅ | ❌ |
| View all users' executions | See executions across all users | ✅ | ❌ | ❌ | ❌ |
| Delete all users' executions | Delete executions across all users | ✅ | ❌ | ❌ | ❌ |
Connections
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| View connections | List and browse; connection health; SNMP walk/MIBs/traps; store-and-forward status; historian settings; MQTT publishers and their status | ✅ | ✅ | ✅ | ✅ |
| Create connections | Create; OPC-UA discover/trust; upload MIBs; create an MQTT publisher | ✅ | ✅ | ✅ | ❌ |
| Edit connections | Edit; test an AI credential; clear quarantine; historian designation, ownership and rebuilds; quarantine retry/drop; edit an MQTT publisher, turn one on or off, release a publish quarantine | ✅ | ✅ | ✅ | ❌ |
| Delete connections | Delete a connection or an MQTT publisher | ✅ | ✅ | ✅ | ❌ |
Namespace
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| View the namespace | Browse the tree, read tags, bindings, UDTs | ✅ | ✅ | ✅ | ✅ |
| Create tags and folders | Create nodes; copy subtrees; create UDT instances | ✅ | ✅ | ✅ | ❌ |
| Edit tags and folders | Edit, move, rename, bulk-update nodes | ✅ | ✅ | ✅ | ❌ |
| Delete tags and folders | Delete nodes; bulk delete; delete UDT instances | ✅ | ✅ | ✅ | ❌ |
| Manage tags | Tag CRUD; UDT definitions, syncs, overrides, member context | ✅ | ✅ | ✅ | ❌ |
| Bind a tag to a protocol | Create, edit, enable, disable, delete protocol bindings | ✅ | ✅ | ✅ | ❌ |
| Bulk import tags | Bulk import | ✅ | ✅ | ✅ | ❌ |
| Export the namespace | Export the namespace | ✅ | ✅ | ✅ | ❌ |
| Refresh the namespace | Refresh from source | ✅ | ✅ | ✅ | ✅ |
| Configure namespace optimisation | Change namespace runtime optimization | ✅ | ❌ | ❌ | ❌ |
Projects
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| View projects | Open a project | ✅ | ✅ | ✅ | ✅ |
| Create projects | Create; import a project backup | ✅ | ✅ | ✅ | ❌ |
| Edit projects | Edit name, title, description | ✅ | ✅ | ✅ | ❌ |
| Delete projects | Delete a project | ✅ | ✅ | ✅ | ❌ |
| Manage projects | Enable, disable, trash, restore, purge; project backup export/restore | ✅ | ✅ | ❌ | ❌ |
Alarms
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| View alarms | Active list, journal, metrics, definitions | ✅ | ✅ | ✅ | ✅ |
| Acknowledge alarms | Acknowledge, shelve, suppress, restore | ✅ | ✅ | ✅ | ✅ |
| Manage alarms | Create/delete definitions; per-tag enable; storage settings | ✅ | ✅ | ✅ | ❌ |
Users & security
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| Manage users | List users | ✅ | ✅ | ❌ | ❌ |
| Create users | Create a user | ✅ | ✅ | ❌ | ❌ |
| Edit users | Activate/deactivate | ✅ | ✅ | ❌ | ❌ |
| Delete users | Delete a user | ✅ | ✅ | ❌ | ❌ |
| Change a user's role | Change a user's role | ✅ | ❌ | ❌ | ❌ |
| Manage permissions | Edit the role-to-permission matrix | ✅ | ❌ | ❌ | ❌ |
| Manage sign-in settings | Authentication policy; external-content policy | ✅ | ❌ | ❌ | ❌ |
| Manage LiveView sign-in | Runtime (LiveView) identity sources | ✅ | ❌ | ❌ | ❌ |
| Access settings | Settings area; API keys; realtime health; map/WMS read | ✅ | ❌ | ❌ | ❌ |
Audit
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| View the audit journal | Read the audit journal; verify the chain | ✅ | ✅ | ❌ | ❌ |
| Manage the audit journal | Configure audit storage | ✅ | ❌ | ❌ | ❌ |
System
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| View the status panel | Status panel; system and connection monitors | ✅ | ✅ | ✅ | ✅ |
| View system logs | Read system logs | ✅ | ✅ | ✅ | ✅ |
| Clear system logs | Delete system logs | ✅ | ❌ | ✅ | ❌ |
| Configure system logging | System log configuration | ✅ | ✅ | ❌ | ❌ |
| Manage services | Start/stop/restart services; storage and WMS configuration | ✅ | ❌ | ❌ | ❌ |
| Manage the script sandbox | Script sandbox configuration and package installation | ✅ | ❌ | ❌ | ❌ |
| Manage backups | Gateway backup export and restore | ✅ | ❌ | ❌ | ❌ |
Designer & library
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| Manage the Designer | Designer authoring; view tree export/import | ✅ | ❌ | ❌ | ❌ |
| Manage the library | File library management | ✅ | ❌ | ❌ | ❌ |
AI assistant
| Permission | Gates | superadmin | admin | editor | viewer |
|---|
| Use the AI assistant | Chat, conversations, proposals | ✅ | ✅ | ✅ | ❌ |
| Manage AI settings | AI configuration, credentials, per-connection access | ✅ | ❌ | ❌ | ❌ |
Notes on the defaults
Admins can read the audit journal but cannot configure it. View the audit journal is granted; Manage the audit journal
is not. Audit-storage configuration is itself a security control.
Viewers can acknowledge alarms. Acknowledgement is an operator's core duty and changes no
configuration. A role that sees alarms but cannot acknowledge them leaves a permanently red banner.
Editors can clear execution and system logs but admins cannot, by default. Editors own the
pipelines that produce those logs; admins are steered toward the audit journal, which cannot be
cleared at all.
Manage AI settings is super-admin only because it exposes billable API credentials and the
assistant's kill switch.
Manage permissions is the meta-permission. Anyone holding it can grant themselves anything.
Keep it on the super admin.
Next
→ Permissions