Skip to main content

Roles and permissions

The matrix​

A user has one Edge role in each tenant they belong to: their product role for Entrosity Edge in that organization on Entrosity Hub. The server enforces these permissions on every API call; the app only hides what you cannot use.

PermissionViewerOperatorTenant adminGlobal admin
See the dashboard, live monitor and event history, doors, controllers, connectors, cardholders, cards, access groups, schedules and holidays✓✓✓✓
See the tenant's users, sites and settings✓✓✓✓
Add, edit and delete cardholders and cards; block, mark lost, reactivate cards✓✓✓
Add and remove access group members✓✓✓
Open doors remotely✓✓✓
Send a controller's configuration again✓✓✓
Create and edit schedules, holidays and access groups, and the doors of groups✓✓
Install and remove connectors, choose their update channel, manage enrollment tokens✓✓
Find, add, test, disable, enable and remove controllers; set their PINs; edit doors and readers✓✓
Manage sites✓✓
Change tenant settings; Manage members on the Hub✓✓
Read the audit log✓✓
Delete enrollment tokens (with the password)✓
All tenants: Overview and the global Audit log✓
List the connector releases (API)✓

In short: viewers watch, operators run the security desk (people, cards, doors), tenant admins set everything up.

Internally these are the permissions access:read, users:read, people:manage, doors:operate, policy:manage, hardware:manage, sites:manage, settings:manage, audit:read and tenants:manage (entrosity-edge.backend/internal/rbac). The Hub's role ids are tenant_admin, operator and viewer.

Tenant isolation

Users of a tenant only reach their own tenant. A request for another tenant's data answers 404, as if it did not exist. Isolation is also enforced inside PostgreSQL with row-level security.

Managing users​

Users, invitations and roles are managed on Entrosity Hub, not in Edge:

  • An organization admin gives members an Edge role (or No access) on the organization's members page of the Hub (Organization members); Manage members in the menu under your name opens it for tenant admins.
  • A platform admin enables Entrosity Edge for an organization under Products (Platform administration). The organization becomes an Edge tenant with the same ID.
  • Global admins are the Hub's platform admins.
  • Edge copies users, organizations and roles from the Hub about every 30 seconds: changes reach Edge within about a minute, including signing out disabled users.