Skip to main content

Roles and permissions

The matrix​

A user has one role in each tenant they belong to (their product role for Entrosity Axis in that organization on Entrosity Hub), and can belong to several tenants (for example tenant admin of one customer and viewer of another). The role of the tenant you are working in applies. The server enforces these permissions on every API call (the portal only hides what you cannot use). Users of several tenants choose one after signing in and switch with the tenant menu in the sidebar.

Teacher has only the screen wall, for the rooms granted to them in Entrosity Matrix, without the session bar on the computers; Axis shows them nothing else.

PermissionViewerTechnicianTenant adminGlobal adminTeacher
See devices, inventory, metrics, alerts, connectors, AD computers✓✓✓✓
See packages and deployments✓✓✓✓
See the tenant's users✓✓✓✓
Device actions: inventory, reboot, shut down, uninstall, wake, cancel a job✓✓✓
Acknowledge and resolve alerts✓✓✓
Create deployments, pause/resume/cancel them, retry targets✓✓✓
See and run scripts, see script runs✓✓✓
Remote desktop (view and control a device's screen)✓✓✓
Remote desktop without asking the user, or without the session bar✓✓
Screen wall: watch up to 26 screens of an Entrosity Matrix room, view only✓ (every room)✓ (every room)✓ (every room)✓ (rooms granted in Matrix)
Edit, merge and decommission devices✓✓
Create and edit packages (winget search)✓✓
Create and edit scripts✓✓
Create and edit alert rules✓✓
Link to the organization's members on the Hub (Manage members)✓✓
Manage sites✓✓
Manage enrollment tokens✓✓
Delete enrollment tokens (with the password)✓
Configure Active Directory, delete connectors, push the agent✓✓
Read the audit log✓✓
Change tenant settings✓✓
Global library; agent releases; all tenants✓

Internally these are the permissions devices:read, devices:operate, devices:remote, devices:remote_unattended, screens:view, devices:manage, deployments:read, deployments:create, packages:manage, scripts:run, scripts:manage, alerts:manage, users:read, users:manage, sites:manage, enrollment:manage, adsync:configure, audit:read, settings:manage and tenants:manage (entrosity-axis.backend/internal/rbac).

Tenant isolation

Users of a tenant can only reach their own tenant. Any request for another tenant's data returns 404, as if it did not exist. Isolation is also enforced inside PostgreSQL; see Multi-tenancy.

Managing users​

Users, invitations and roles are managed on Entrosity Hub, not in Axis:

  • Tenant members and their Axis roles are listed and changed on the organization's members page of the Hub (Manage members in the menu under your name, for tenant admins; Organization members). Changing members there needs the Hub's organization admin role, which is separate from the Axis role.
  • Invitations, display names, disabling and removing users happen on the Hub; Axis follows within about a minute, even for open browser tabs.
  • Global admins are the Hub's platform admins (Global admins).