Roles and permissions¶
Every protected action in Whisker.io, from editing account details down to sending a command from one HMI widget, is controlled by a role you choose. This page explains how roles work and where each permission is set.
How roles work¶
A role is a named group of users. Permissions are not stored on the role. Instead, each protected feature asks: "which role is allowed to do this?"
So securing your account is always the same two steps:
- Create roles and put users in them: Admin, Managers, Operators, Maintenance, whatever fits your organization.
- Go to each thing you want to protect (the account, a location, an HMI, a dashboard) and choose which role gets each permission.
Warning
For most permissions, leaving the role blank means everyone on the account can do it. Choosing a role is what locks the feature down. When you review your security, look for blanks. The exceptions are listed under Account-level permissions.
Permissions are set in four places:
| Scope | Where it's set | Examples |
|---|---|---|
| Account | Assign Account Roles dialog | Who can manage users, locations, dashboards; who sees Alert History and the Audit Log |
| Location | Edit Location dialog | Who can view or change one location and its equipment |
| HMI | Create New HMI View / Edit HMI dialogs | Who can view, edit or send commands from one HMI screen |
| Dashboard | Create New Dashboard / Configure Dashboard dialogs | Who can view or edit one dashboard |
New accounts start with three roles: Admin, Manager and View. Admin holds the account administration permissions, and Manager holds the day-to-day add and edit permissions.
Create and rename roles¶
- Go to Control Panel → Roles. The grid lists each Role Name and the number of Users with this Role.
- Click Create New Role, enter a name in the New Role dialog and save. You'll see "Role '\<name>' Succesfully Added!!". Role names must be unique in your account.
- To rename a role, click its row, then Edit Selected Role.
Note
Roles cannot be deleted in the portal, so choose names with care. Renaming a role doesn't change who is in it or what it grants.
Create New Role and Edit Selected Role need the Add/Edit Users permission. Assign Roles needs Account Admin.
Put users in roles¶
A user's roles are set with the Roles: list in the Create New User and Edit User dialogs (Control Panel → Account Users): tick the roles, click Apply in the list, then save the dialog. See Managing users.
Note
Lockout protection: you can't remove a role from the last user who holds it if that role grants Account Admin, Add/Edit Users, Add/Edit Alert Contacts or another account-level permission. You'll see "Unable to remove \<Role> role. (This is the last user that has this role.)" Add a second person to the role first.
Account-level permissions¶
Account-wide permissions are set in the Assign Account Roles dialog. Open it with Assign Roles on Control Panel → Account or Control Panel → Roles. Choose a role for each row and click Save; you'll see "Account Role Assignments Succesfully Updated!!".
| Row | What the chosen role can do | If left blank |
|---|---|---|
| Account Admin Role: | Edit account details and the HMI PIN code policy, manage scheduled reports, open this dialog, and view the Audit Log. The master administrative permission: guard it closely | Everyone |
| Add/Edit Users: | Create and edit users, change their passwords, reset their PINs, create and rename roles | Everyone |
| Add/Edit Alert Contacts: | Create and edit alert contacts | Everyone |
| Add/Edit Locations: | Create locations from the map | Everyone |
| Add/Edit Dashboards: | Create, edit and delete dashboards (together with each dashboard's edit role) | Everyone |
| Create HMI: | See the + (new HMI) tab at every location | Everyone |
| Local Device Login: | Sign in at on-site panels with an HMI PIN code | Falls back to the Account Admin role |
| View Alert History: | See the Alert History tab under Alerts (every notification sent, and its result). See Alert history and notes | Nobody |
| Receive Delivery Problem Reports: | Receive the email about alert contacts whose number or email stopped working, or who opted out of texts. See Texts, emails and calls | Holders of Add/Edit Alert Contacts, or else the account's administrators |
| View Audit Log: | See the Audit Log tab in the Control Panel. Account Admins always can. See Audit log | Account Admins only |
Creating and editing alerts is controlled by the location's modify role (see below), not by an account-level row.
Tip
A sound start: point Account Admin Role at a small Admin role with at least two people (see the lockout rule above), point the Add/Edit rows at a Managers role, point Local Device Login at the people who service equipment on site, and choose deliberately who gets View Alert History and Receive Delivery Problem Reports.
Location-level permissions¶
Each location has two permissions of its own, set in the Edit Location dialog. Open it with the gear next to the location's name at the top of the location page, or the gear in the location's tooltip on the map.
| Field | Effect |
|---|---|
| Which role can view this location? | People outside the role can't open the location: its name is plain text, not a link, on the map and table |
| Which role can modify this location? | Controls changes to the location and everything in it: devices, channels, alerts, snoozes, adding products and moving equipment on the map |
Click Save Changes ("Location Successfully Edited!!!"). The same two fields are in the New Location dialog, so a location can be locked down from the start.
HMI-level permissions¶
Each HMI screen has three roles, set when it is created and changed later with the gear on the HMI's tab. See Locations and HMIs.
| Field | Effect |
|---|---|
| View HMI Role | Only people in the role see the HMI's tab |
| Modify HMI Role | Shows the Edit Mode (wrench) button: move, resize, add and delete widgets and change the background image |
| Remote Command Role | Allows double-clicking a writeable widget to send a value or command to equipment |
This split lets one location serve different people safely: operators see the screen, supervisors can command equipment from it, and only engineering can rearrange it.
Dashboard-level permissions¶
When you create or configure a dashboard (see Dashboards):
- Which role can view this dashboard? The dashboard appears in a person's Current Dashboard: list only if they hold this role (or the edit role).
- Which role can edit this dashboard? Controls adding, configuring and deleting panels and widgets, and deleting the dashboard.
"Why can't this person do X?"¶
| Symptom | Check |
|---|---|
| No Create New User or Edit User button | Add/Edit Users |
| No Assign Roles button, or the account details are read-only | Account Admin Role |
| No Create New Contact button under Alerts → Alert Contacts | Add/Edit Alert Contacts |
| No Alert History tab under Alerts | View Alert History (blank means nobody) |
| No Audit Log tab in the Control Panel | View Audit Log or Account Admin Role |
| No New Location on the map | Add/Edit Locations |
| Location name not clickable on the map | The location's view role |
| Can't edit devices or alerts at a location | The location's modify role |
| An HMI tab is missing | That HMI's View HMI Role |
| No wrench (Edit Mode) on an HMI | That HMI's Modify HMI Role |
| Double-clicking a widget does nothing | That HMI's Remote Command Role |
| No + (new HMI) tab | Create HMI |
| Dashboard missing from the list | That dashboard's view role |
| PIN refused at a panel | Local Device Login, and that the account's PIN policy is on |
| No Control Panel in the menu at all | The person is a View Only user |
Who did what¶
To see who changed a permission, or anything else, use the Audit log or the History tab of a location (see Locations and HMIs).