Skip to main content

Roles and permissions

The matrix​

A user has one Matrix role in each tenant they belong to: their product role for Entrosity Matrix in that organization on Entrosity Hub. The server enforces these permissions on every API call and, for changes, again right before the connector writes; the app only hides what you cannot use.

PermissionViewerTeacherTenant adminGlobal admin
See the rooms, their state and schedules✓Granted rooms only✓✓
See addresses and groups✓Granted rooms only✓✓
See the allowed sites✓List for all rooms and granted rooms✓✓
Read the history✓Granted rooms only✓✓
See the tenant's users✓✓✓✓
Enable and disable rooms, disable until, bulk changes, cancel re-enablesGranted rooms only✓ all rooms✓
Change computers' IPs, add computers, retry address operations✓✓
Change a room's own allowed sitesGranted rooms only✓ all rooms✓
Change the allowed sites of all rooms; see the FortiGate setup commands✓✓
Add, change and delete firewalls (including Allow editing allowed sites); store their tokens; check and refresh them✓✓
Give teachers room rights✓✓
Install and remove connectors; manage enrollment tokens✓✓
Manage sites; change tenant settings; Manage members on the Hub✓✓
Read the audit log✓✓
All tenants: overview, tenants, users, connector releases and the global audit log✓

In short: viewers look at every room, teachers see and switch only the rooms granted to them and edit those rooms' allowed sites, tenant admins (IT) set everything up and switch every room. A teacher without granted rooms sees no rooms (No rooms are assigned to you yet). Refused attempts, including a hand-made API call, are recorded in the history.

Teachers do not see other rooms

The server never sends a teacher anything about rooms not granted to them: the rooms, address groups, allowed-sites lists, re-enable schedules, history entries and live updates of other rooms are left out, and so are firewalls without any of their rooms. Asking for such a room anyway (a hand-made API call) answers 404 unknown_room, as for a room that does not exist, and is recorded as refused. History entries without a room (firewall settings, room rights, the list for all rooms) are not shown to teachers.

Internally these are the permissions rooms:read, rooms:operate, addresses:read, addresses:manage, allowed_sites:manage, history:read, users:read, firewalls:manage, grants:manage, hardware:manage, sites:manage, settings:manage, audit:read and tenants:manage (entrosity-matrix.backend/internal/rbac). The Hub's role ids are tenant_admin, teacher and viewer. allowed_sites:manage (tenant admins) covers every allowed-sites list and the setup commands; an teacher changes a room's own list with rooms:operate and a room right for that room, never the list for all rooms.

Checked again at write time

Right before every write, the connector asks Matrix whether the change is still allowed: the author must still be an active user of the tenant, not signed out on the Hub, and still a tenant admin, or a teacher with the room's right (address changes and the list for all rooms: a tenant admin). A right removed after the change was sent stops it.

Tenant isolation

Users of a tenant only reach their own tenant. A request for another tenant's data answers 404, as if it did not exist. Isolation is also enforced inside PostgreSQL with row-level security.

Managing users​

Users, invitations and roles are managed on Entrosity Hub, not in Matrix:

  • An organization admin gives members a Matrix role (or No access) on the organization's members page of the Hub (Organization members). Which rooms an teacher switches is set in Matrix (Room rights).
  • A platform admin enables Entrosity Matrix for an organization under Products (Platform administration). The organization becomes a Matrix tenant with the same ID.
  • Global admins are the Hub's platform admins. While Matrix is in beta, they are the only users who can open it (Products in beta).
  • Matrix copies users, organizations and roles from the Hub about every 30 seconds: changes reach Matrix within about a minute, including signing out disabled users.