Previously, it was only possible to grant permissions to users at the organizational level, either through roles or via user-specific permissions.
Now, it is also possible to assign roles to a user at the site level. The user then gets the permissions of this role only for that specific site. It is not possible to grant user-specific permissions at the site level.
Be aware that not all permissions can be granted at the site level, such as the user management permission. An overview of this is provided in Explanation of user permissions (Building Automation).
Not only for users, but also for applications, you can now assign roles at the site level.
Follow the next steps to start applying roles at the site level:
- Get informed: Before you begin: Read the articles in Roles to learn more about creating roles. Read Roles and site access to learn more about assigning roles and what permissions result when you assign roles that contain both site-specific and organization-wide permissions at the organization and site levels.
-
Manage roles: Make a good plan of how you want to set up roles within your organization. Consider what permissions you want to assign to your users at the site level from now on.
- Delete unused roles that you do not plan to use. Find out which roles are unused by going to the Roles tab and clicking one by one on each role to see whether they have role members. Role members only shows roles assigned at the organization level. Roles assigned at site level can only be viewed per user. Therefore, perform this cleanup action before assigning roles at site level.
- Create new roles that you plan to assign at the site level containing the desired site-specific permissions.
- Adjust existing roles so that they only contain permissions that you want to be granted at the organizational level.
- Assign roles: Assign roles to all users one by one according to your plan. At the organization level, you can assign roles both via the Users tab per user and via the Roles tab per role. At the site level, you can only assign roles per user via the Users tab: click a user in the Users tab > click the three dots button > click Assign roles.