Roles and permissions
The matrix
A user has one Sphere role in each tenant they belong to: their product role for Entrosity Sphere in that organization on Entrosity Hub. The server enforces these permissions on every API call; the app only hides what you cannot use.
| Permission | Viewer | Operator | Tenant admin | Global admin |
|---|---|---|---|---|
| See the dashboard, sites, connectors, NVRs and cameras | ✓ | ✓ | ✓ | ✓ |
| See the tenant's users | ✓ | ✓ | ✓ | ✓ |
| Watch live video (grids and single camera view) | ✓ | ✓ | ✓ | ✓ |
| Read the alarm log | ✓ | ✓ | ✓ | ✓ |
| Save, change and delete their own camera grids | ✓ | ✓ | ✓ | ✓ |
| Search recordings and play them back | ✓ | ✓ | ✓ | |
| Move PTZ cameras, go to, store and clear presets | ✓ | ✓ | ✓ | |
| Acknowledge alarms | ✓ | ✓ | ✓ | |
| Save, change and delete camera grids shared with the tenant | ✓ | ✓ | ✓ | |
| Connect to and disconnect from NVRs, test them, see their jobs | ✓ | ✓ | ✓ | |
| Add, change and remove NVRs; change their user name and password; optimise them for live view; rename cameras and switch them off | ✓ | ✓ | ||
| Download, install and remove connectors (and rename them through the API); manage enrollment tokens | ✓ | ✓ | ||
| Manage sites | ✓ | ✓ | ||
| Change tenant settings; Manage members on the Hub | ✓ | ✓ | ||
| Read the audit log | ✓ | ✓ | ||
| Delete enrollment tokens (with the password) | ✓ | |||
| All tenants: overview, tenants, users and the global audit log | ✓ |
In short: viewers watch live video and the alarm log, operators run the security desk (playback, PTZ, alarms, NVR connections, shared grids), tenant admins set everything up. The app hides what a role cannot use: viewers do not see Playback in the sidebar, the PTZ panels or the acknowledge buttons, and only tenant admins see Add NVR, Download connector, Install a connector, the connectors' pending updates and the Audit log.
Internally these are the permissions cameras:view, alarms:read,
users:read, playback:view, ptz:operate, alarms:ack,
views:manage, nvrs:operate, nvrs:manage, sites:manage,
settings:manage, audit:read and tenants:manage
(entrosity-sphere.backend/internal/rbac). The Hub's role ids are
tenant_admin, operator and viewer.
Watching needs the permission in Sphere and, for every stream, a token the media server accepts for exactly that stream: a user of one tenant can never open another tenant's video, even with its address.
Users of a tenant only reach their own tenant. A request for another tenant's data answers 404, as if it did not exist. Isolation is also enforced inside PostgreSQL with row-level security.
Managing users
Users, invitations and roles are managed on Entrosity Hub, not in Sphere:
- An organization admin gives members a Sphere role (or No access) on the organization's members page of the Hub (Organization members).
- A platform admin enables Entrosity Sphere for an organization under Products (Platform administration). The organization becomes a Sphere tenant with the same ID.
- Global admins are the Hub's platform admins. While Sphere is in beta, they are the only users who can open it (Products in beta).
- Sphere copies users, organizations and roles from the Hub about every 30 seconds: changes reach Sphere within about a minute, including signing out disabled users.