Access Management
User access on Xyte is managed via two distinct methods, which combine: tenant-wide access, granted by membership of the automatically-created global groups, and space-level access, granted per space to a user or a group.
Both apply to users created in this tenant and to external users given explicit access.
Each Space in the Overview tree has its own access rights and can be managed independently. Space-level access defines what the user can do in and to the Space, and to all the Devices directly inside of it.
Inheritance
Any changes to the access levels of a Space automatically propagate to all the Spaces below it. Giving View access to a user on a "UK" Space will therefore grant the same permission on all its child and grandchild Spaces, such as "London".
Levels
Space level access can be of three different levels — View, Edit or Admin. Each level covers everything the level to its left covers, plus more:
| Action | View | Edit | Admin |
|---|---|---|---|
| View spaces, devices, assets, incidents, history | ✅ | ✅ | ✅ |
| Add devices and assets to the space | ❌ | ✅ | ✅ |
| Edit device details, configuration, notes | ❌ | ✅ | ✅ |
| Send commands to devices | ❌ | ✅ | ✅ |
| Open, update and close incidents | ❌ | ✅ | ✅ |
| Move devices between spaces | ❌ | ✅ | ✅ |
| Delete devices and assets | ❌ | ❌ | ✅ |
| Replace, merge and split devices | ❌ | ❌ | ✅ |
| Manage licenses and warranties | ❌ | ❌ | ✅ |
| Create, edit, move and delete sub-spaces | ❌ | ❌ | ✅ |
| Grant and revoke access to the space | ❌ | ❌ | ✅ |
Deleting a device requires AdminEdit covers day-to-day device work — claiming, configuring, sending commands, handling incidents and moving devices — but it does not include deleting a device or an asset. If a team needs to decommission devices, grant them Admin on the spaces they are responsible for.
"Admin" means Admin on the spaceSpace-level Admin is not the same as an organization administrator. A user — or a group — can hold Admin on one space and no access at all elsewhere. Organization administrators can do everything above in every space, and are the only ones who can manage users, groups, API keys and billing.
Access Level Computation
A user might be granted different access levels to the same space, if that user belongs to one or more Groups that have access to the Space.
To calculate the actual access rights, Xyte picks the highest access level granted to the user, directly or indirectly via Groups.
Access Management
Access control is done via Overview → Space → Manage Access.
See Space Access Management for the full flow, including a worked example of giving a customer's team view-only access to a single room.
Xyte supports the concept of Global Administrators and Global Viewers. This is determined by the user being a member of the automatically-created groups administrators or Viewers respectively.
Membership of both groups is managed by users already in the global administrators group — by default, the user who created the tenant is granted membership and can add additional administrators.
See Users & Groups for how to create users and add them to global groups via the Settings tab.
Global Administrators
Users in the global administrators group have full read and write access to all tenant features. This includes access to all spaces and devices, store management, connectors, integrators, settings, etc.
Global administrators are also the only users who can manage users, groups, API keys and billing.
Global Viewers
Users in the global Viewers group have read-only access to the following:
- All Spaces and Devices
- Incidents
- Assets
- Files
- Contracts
- Store
- Products
- Tickets
Tenant-wide access cannot be reduced on an individual spaceA global administrator has full access to every space, and a global viewer can read every space, regardless of what is granted or withheld on the space itself. If someone should only see one space, they must not be a member of either global group — scope them with space-level access instead.
Updated 16 days ago
