Skip to main content
Version: 1.0.4

Permissions Reference

Every permission as it appears in Settings → Permissions, what it allows, and the default for each role.

Legend: ✅ granted by default · ❌ not granted. The matrix is editable — see Permissions.

Pipelines

PermissionGatessuperadminadmineditorviewer
View pipelinesSee pipelines and their definitions
Create pipelinesCreate a pipeline
Edit pipelinesEdit a pipeline; delete variables; query introspection
Delete pipelinesDelete a pipeline
Run pipelinesRun once; trigger a single node
Start and stop pipelinesStart/stop, and start-all/stop-all
Export pipelinesExport a pipeline
Import pipelinesImport a pipeline
Configure variable storageChange the variable persistence mode
View execution logsRead execution and node-execution logs
Clear execution logsDelete execution logs
View all users' executionsSee executions across all users
Delete all users' executionsDelete executions across all users

Connections

PermissionGatessuperadminadmineditorviewer
View connectionsList and browse; connection health; SNMP walk/MIBs/traps; store-and-forward status; historian settings; MQTT publishers and their status
Create connectionsCreate; OPC-UA discover/trust; upload MIBs; create an MQTT publisher
Edit connectionsEdit; test an AI credential; clear quarantine; historian designation, ownership and rebuilds; quarantine retry/drop; edit an MQTT publisher, turn one on or off, release a publish quarantine
Delete connectionsDelete a connection or an MQTT publisher

Namespace

PermissionGatessuperadminadmineditorviewer
View the namespaceBrowse the tree, read tags, bindings, UDTs
Create tags and foldersCreate nodes; copy subtrees; create UDT instances
Edit tags and foldersEdit, move, rename, bulk-update nodes
Delete tags and foldersDelete nodes; bulk delete; delete UDT instances
Manage tagsTag CRUD; UDT definitions, syncs, overrides, member context
Bind a tag to a protocolCreate, edit, enable, disable, delete protocol bindings
Bulk import tagsBulk import
Export the namespaceExport the namespace
Refresh the namespaceRefresh from source
Configure namespace optimisationChange namespace runtime optimization

Projects

PermissionGatessuperadminadmineditorviewer
View projectsOpen a project
Create projectsCreate; import a project backup
Edit projectsEdit name, title, description
Delete projectsDelete a project
Manage projectsEnable, disable, trash, restore, purge; project backup export/restore

Alarms

PermissionGatessuperadminadmineditorviewer
View alarmsActive list, journal, metrics, definitions
Acknowledge alarmsAcknowledge, shelve, suppress, restore
Manage alarmsCreate/delete definitions; per-tag enable; storage settings

Users & security

PermissionGatessuperadminadmineditorviewer
Manage usersList users
Create usersCreate a user
Edit usersActivate/deactivate
Delete usersDelete a user
Change a user's roleChange a user's role
Manage permissionsEdit the role-to-permission matrix
Manage sign-in settingsAuthentication policy; external-content policy
Manage LiveView sign-inRuntime (LiveView) identity sources
Access settingsSettings area; API keys; realtime health; map/WMS read

Audit

PermissionGatessuperadminadmineditorviewer
View the audit journalRead the audit journal; verify the chain
Manage the audit journalConfigure audit storage

System

PermissionGatessuperadminadmineditorviewer
View the status panelStatus panel; system and connection monitors
View system logsRead system logs
Clear system logsDelete system logs
Configure system loggingSystem log configuration
Manage servicesStart/stop/restart services; storage and WMS configuration
Manage the script sandboxScript sandbox configuration and package installation
Manage backupsGateway backup export and restore

Designer & library

PermissionGatessuperadminadmineditorviewer
Manage the DesignerDesigner authoring; view tree export/import
Manage the libraryFile library management

AI assistant

PermissionGatessuperadminadmineditorviewer
Use the AI assistantChat, conversations, proposals
Manage AI settingsAI configuration, credentials, per-connection access

Notes on the defaults

Admins can read the audit journal but cannot configure it. View the audit journal is granted; Manage the audit journal is not. Audit-storage configuration is itself a security control.

Viewers can acknowledge alarms. Acknowledgement is an operator's core duty and changes no configuration. A role that sees alarms but cannot acknowledge them leaves a permanently red banner.

Editors can clear execution and system logs but admins cannot, by default. Editors own the pipelines that produce those logs; admins are steered toward the audit journal, which cannot be cleared at all.

Manage AI settings is super-admin only because it exposes billable API credentials and the assistant's kill switch.

Manage permissions is the meta-permission. Anyone holding it can grant themselves anything. Keep it on the super admin.

Next

Permissions