HomeGuidesAPI ReferenceChangelog
Log In
Guides

Roles and permissions

When new users are added to the app, they are assigned a specific role that defines the operations they are authorised to perform.

This article will serve as a guide to understanding how roles and permissions work within the platform.

Roles

By default, Wizata offers predefined roles, each designed to support specific operational needs..

For instance, to streamline tasks for engineers and operators, an admin can assign them the Operate User role. This role allows them to interact with existing dashboards, explore data through the Data Explorer, and create their own dashboard components.

The following table summarizes the different permissions for all the default roles available:

RolePermissions
AdminFull access to all the modules of the platform and DSAPI. Access to modify user roles assignment, platform settings and integrations.
DesignerUser with full access to all the modules of the platform and DSAPI.
DigitizerSimilar to Operate User, with access to Data Hub section to modify common elements like datapoints, twins & labels, and DSAPI access to manipulate datapoints & twins and make queries.
Operate UserSimilar to Operate Viewer, with additional access to Data Explorer, creation of personal components and access to DSAPI for pipeline executions.
Operate ViewerRestricts a user to read-only access on Control Panel section module.
Read-OnlyRestricts a user to read-only access on all the platform's main modules and respective operations.

What each role can do

The table above describes each role in general terms. Where it matters most in practice is the AI Lab, because building and deploying pipelines is not open to every role:

OperationAdminDesignerRead-OnlyDigitizerOperate UserOperate Viewer
View pipelines and deployments✓✓✓
Create, edit and delete pipelines✓✓
Work with drafts — create, save, publish, discard✓✓
Deploy a pipeline, and pause, resume or retry a deployment✓✓
View edge devices✓✓✓✓
Act on an edge device — ping, restart, refresh✓✓✓
Edit twin registrations and template configurations✓✓✓✓
Connect or disconnect a git repository✓

Two of those are worth calling out:

  • Pipelines are invisible to Digitizer, Operate User and Operate Viewer. Not read-only — not visible. A user who needs to look at pipelines without changing them wants Read-Only.
  • Git integration is Administrator-only, including reading the connection status. See Connect a git repository.
📘

These rules are enforced by the API, which is what the platform interface itself calls. A role cannot get round them by using the Python SDK instead of the screens, and it cannot be blocked in one and allowed in the other.

Twins

By default, a user can access all data on the platform with the permissions defined in his roles. But it is possible to restrict him to some subset of data depending on its location and/or process it belongs.

Admins can restrict an user to certain twin by navigating to the User Management > Users, selecting the user and clicking on Bulk Edit

On Twins, select between the available twins from the platform.

Selecting a parent twin will automatically include all its related sub-assets.


Did this page help you?