User roles
Only where the portal has user roles.
A role is a named set of permissions that can be handed to a user in one place and taken away again in one place. Setting permissions directly grants one permission to one user on one resource; assigning a role grants everything the role holds, and revoking it takes all of that back at once.
The two are separate systems. A user can hold the same permission through both, and removing it from one leaves the other standing — see User permissions for reading a permission a role gave.
Every role name on every role screen opens the same read-only summary of what it holds:
A role is usable in exactly one scope — the portal, a single site, or a single multi-site — and that scope decides which permissions it may hold and where it can be assigned.
For portal owners:
Role Management
Permissions → User Roles holds two sub-tabs: Role Management, which is the roles themselves, and Role Assignments, which is who holds them.
The Scope column is where the role can be used, Permissions opens the summary above, and Defaults names the events that hand the role out on their own.
System roles and custom roles
Cloud ships thirteen system roles covering the usual jobs, three at portal level and five each for a site and a multi-site. They carry a System Role badge, and they cannot be edited or deleted — those options stay in the menu and are greyed out. They can be duplicated, and the copy is yours to change.
Role Scope What it is for Portal Owner Portal Owner-level access to every site and multi-site in the portal, and assigning roles Portal Admin Portal The same, plus creating and deleting sites, multi-sites and roles themselves Portal End User Portal Day-to-day use of every site and multi-site: firing tasks, scheduling, reading devices Owner Site Full control of one site, its devices and its people. Given automatically to whoever creates a site Scheduling Site The task scheduler and its schedules in one site Control Panel Site Opening one site's Control Panel and firing its tasks, and nothing else End User Site Day-to-day use of one site, scheduling included Default Site The read-only baseline: the site, its users, its Control Panel, its tasks and its devices. Given automatically to a user added to a site Multi-Site Owner Multi-site Full control of one multi-site, including which sites belong to it. Given automatically to whoever creates a multi-site Multi-Site Scheduling Multi-site The task scheduler and its schedules in one multi-site Multi-Site Control Panel Multi-site Opening one multi-site's Control Panel and firing its tasks Multi-Site End User Multi-site Day-to-day use of one multi-site, scheduling included Multi-Site Default Multi-site The read-only baseline for a multi-site. Given automatically to a user added to one The four marked as given automatically are the ones that arrive with an Auto assign when trigger already set; the rest are assigned by hand.
Two controls exist for a portal that would rather not use them:
- Hide System Roles above the table leaves only the roles you made. It appears once the portal holds a custom role, since there is nothing to hide before that.
- Disable All System Roles switches every one of them off in a single step. Custom roles are untouched, and system roles can be switched back on one at a time afterwards. It asks you to type a word to confirm, and it says how many roles it will affect.
Creating a role
- Select Create Role.
- Give it a Name, and a Description if it needs one.
- Choose the one scope it can be used in under Can be used in.
- Tick the permissions it grants. They arrive as a tree, grouped the way the permissions table groups them, and a group's own tick box takes the whole group.
- Optionally choose the triggers under Auto assign when.
One scope only
Changing the scope clears the permissions already ticked, because the new scope does not offer them — so you are asked to confirm first. A portal-scoped role has no auto-assign triggers at all; the option is only there for site and multi-site roles.
The triggers on offer follow the scope: a site role can be assigned automatically when a user creates a site or when a user is added to one, and a multi-site role when a user creates a multi-site or is added to one. A role with no trigger is only ever assigned by hand.
Editing, copying and removing a role
Each row's Options menu offers:
Option What it does Edit Reopens the same form. Editing a role changes what it grants everywhere it is already assigned Duplicate Copies the role, including its permissions — the way to start from a system role Delete Removes the role permanently The Enabled switch in the row is the reversible one. Disabling a role suspends everything it grants: everyone keeps the assignment but loses the permissions until it is enabled again.
Copy Permissions above the table replaces one role's permissions with another's. The source can be any role, the target only a custom one.
Role Assignments
Role Assignments lists every assignment in the portal, whatever scope it was made at, so a person's access can be found without visiting each site in turn.
Scope type is the level the role was assigned at and Target the site or multi-site it was assigned on — a portal-wide assignment shows Portal, because it is not limited to one resource. Select users above the table narrows the list to the people you name; with nobody named it shows everyone. The table is paged, and both the filter and the page are kept in the address, so a filtered list can be linked to.
- Assign Role takes one or more users, a scope, the site or multi-site to assign on, and the role. The role's permissions are previewed under the choice before you commit.
- Revoke Role takes an assignment away from several people at once. A single assignment is revoked from its own row's Options menu.
Who may manage roles
The Portal permissions tab carries a Roles section with four permissions, each granted portal-wide rather than on one site:
Permission Allows Add Create a role, and duplicate one Edit Change a role, copy permissions onto it, and switch it on or off Delete Delete a role Assign Assign and revoke roles anywhere in the portal The Portal Admin system role holds all four. Portal Owner holds only Assign, and so does ownership itself: owning the portal, a site or a multi-site carries the right to hand a role out, never to author one. A control someone lacks is not shown to them at all, rather than shown and refused.
For readers who are not portal owners:
Roles themselves are made and named at portal level, so the set you can assign is the one the portal owner has set up. Ask them if you need a role that does not exist yet, or one changed.
Roles on a site or a multi-site
A site's Users tab holds everything about who can do what, as sub-tabs: Users for membership, Roles for the roles those people hold, and Permissions for the permissions table. A multi-site's Users tab works the same way. Each sub-tab has its own address, so one can be linked to or returned to with the browser's back button.
Every assignment on this tab targets the site you are in, so there is no scope to choose — only the people and the role. One row per person lists every role they hold here, and a disabled or system role is tagged in place.
- Select users above the table chooses whose roles to show. The selection is shared with the Permissions sub-tab and remembered per site.
- Assign Role above the table assigns one role to one or more of them; Assign new role in a row's Options menu does the same for that person alone.
- The bin beside a role revokes that one assignment.
Reading a role's effect on the Permissions sub-tab
The permissions table shows what a user can do from every source at once, so a permission a role gave is visible where it applies rather than only where it was assigned. It is drawn as a ring around an empty dot: the user holds the permission, but nothing on that table granted it, so clearing the dot cannot take it away. Hovering names the role and the level it was assigned at, and points at the tab that would remove it — which is not always the tab you are standing on, since a portal-wide role cannot be unassigned from a site.
See User permissions for the markers in full.