Device Grouping, Access Control & Role Management Guide

Overview

Use device groups, targeted user assignments, and role-based permissions to deliver a multi-tenant experience. Organize PDUs into logical collections, ensure users see only what they should, and tailor functionality access per role.


1. Organize Devices into Groups

  1. Navigate to Devices → Device Groups.
  2. Create or select a device group.
  3. Add or remove PDUs as needed.
  4. Use groups to represent departments, customer sub-tenants, or any logical segmentation.

Tip: Device groups simplify assignment to multiple users and roles in a single action.



2. Invite and Manage Users

  1. Go to Team Members to invite organization-wide users.
  2. Use Group Users to invite users scoped to a specific device group.
  3. Configure:
    • Admin privileges (organization-wide vs. scoped).
    • SSO-only access to enforce identity provider requirements.


3. Assign Device Access

Individual Users

  1. Open the user’s profile.
  2. Assign access to:
    • Specific PDUs.
    • Entire device groups.

User Groups

  1. Open the group settings.
  2. Attach device groups or individual PDUs.
  3. All members inherit the group’s device access.


4. Define and Apply Roles

Create or Edit Roles

  1. Navigate to Roles.
  2. Review permission options (e.g., view outlet states, toggle outlets, view power metrics, manage settings).
  3. Create or duplicate a role and toggle permissions to suit the use case.

Assign Roles

  • Per User: Attach the role from the user’s profile.
  • Per Group: Assign the role at the group level; members inherit it.


5. Sample Flow: Limited Access User

  1. Create a Device Group (e.g., “Customer A – East Wing”).
  2. Add only the PDUs that the customer needs to manage.
  3. Create a Role (e.g., “Read-Only Power Monitoring”) with permissions to:
    • View outlet states and power metrics.
    • Restrict outlet switching and configuration changes.
  4. Invite the customer’s user account:
    • Assign them to the “Customer A – East Wing” device group.
    • Apply the “Read-Only Power Monitoring” role.
  5. Result:
    • The customer sees only the assigned PDUs and limited controls.
    • Admin users retain full visibility and configuration access.

Capture screenshots comparing the limited user’s dashboard vs. the admin view to illustrate the difference.


Best Practices

  • Use groups liberally: They simplify repetitive assignments and keep access easy to audit.
  • Name roles clearly: Align role names with business functions (e.g., “Support Technician,” “Operations Viewer”).
  • Review periodically: Audit device groups, user memberships, and roles to ensure least-privilege access.
  • Leverage SSO: Enforce SSO-only access for enhanced security and centralized identity management.

Troubleshooting & FAQs

  • User can’t see a device: Confirm the device or device group is assigned, and that the role grants view permissions.
  • Role changes not taking effect: Reapply the role or sign out/in to refresh permissions.
  • Need custom permissions: Duplicate an existing role, adjust the toggles, and assign the new role.