Purpose and Terminology
SBC uses Roles and Permissions to control what users can see and do in a consistent, secure, and manageable way. Instead of configuring access for each individual user, permissions are grouped into roles (such as System Admin, Organisation Admin, or End User), and users are assigned one of these roles based on their responsibilities. This approach improves security by ensuring users only have access to the functions and data they need, reduces the risk of accidental or unauthorised changes, and makes user management easier to scale and maintain as organisations grow or requirements change.
As a quick summary, some definitions and terminology used:
-
User: Any user of the software, independent of its role (different from the role of End User).
-
Role: A role is a named collection of permissions that represents a set of responsibilities or a job function; users are assigned roles to conveniently and consistently define what they are allowed to do in the system.
-
Permission: A permission is a specific authorisation to perform an action or access a resource (for example, read, create, update, or delete), and these permissions are checked by the system to control the behaviour of the user interface and API.
Overview
The overview displays all roles currently defined.
Any installation of SBC comes with a set of predefined roles. Those roles cannot be modified. Their permissions can be viewed with the necessary Read Settings permissions. If you do not have these permissions, this help page serves as your reference. With the permission of Manage Settings, new roles can be created.
The overview displays the general properties of each role:
|
Parameter |
Description |
|---|---|
|
Role Name |
Name identifying the role in other places. |
|
Description |
Additional information describing the role in more detail. |
|
Role Type |
Three types of roles are distinguished:
|
|
Predefined Role |
This indicates if the role is a predefined or a user-defined role. |
|
Users |
Shows the number of users that are currently assigned to this role. |
Using the view icon, you can discover all details of each role. This includes the assigned Permissions, which are visualised for easier understanding in an Overview and in a Matrix view tab.
Predefined Roles
The following roles are predefined on any installation of SBC:
|
Role |
Description |
|---|---|
|
System Admin |
Full system access. Unrestricted access to all features and data. This is the highest role, serving the master administrator who configures the system and service offering at the IT and business level. |
|
System Operator |
Manages users, subscriptions, organisations, and regions across the entire system. This role is targeted for users responsible for the daily user and subscription management. It can view all pages of the Admin portal, can create/update/delete Users, Regions and Organisation (but not Sales Organisations). It can create new and activate pending Subscriptions, change the owner of a Subscription, but cannot modify them any further, and it cannot modify the Settings. |
|
System Support |
Read-only access on system level. This role is targeted for support and diagnostics tasks. It can view all pages of the Admin portal, but cannot create new data records (e.g. Users, Subscriptions). |
|
Sales Org Admin |
Full administration of their sales organisation, users, and subscriptions. This role is targeted for users responsible for the daily user and subscription management of a Sales Organisation. It is able to manage all data associated to users and subscriptions within his sales organisation and their children. This includes the activation, renewal or expiration of subscriptions. |
|
Sales Org Operator |
Manages users and subscriptions within their sales organisation. This role is targeted for users responsible for support and diagnostics within its Sales Organisation. It can create users and activate subscriptions, but has limited capabilities to modify existing subscriptions. It can create further child organisations and can utilise all features that help supporting other members of its Sales Organisation and its children. |
|
Organisation Admin |
Manages users and roles within their own organisation. This role is targeted for users responsible for the user management or user supervision within a sub-organisation that belongs to some Sales Organisation. E.g., it can be a dealer selling subscriptions, or it can be a supervisor of a team within a company. It can create and modify users and observe their activity with the Admin Portal functionality. This role cannot create or modify any subscription. |
|
Organisation Support |
Read-only access within their organisation for support or supervisor tasks. This role is targeted for users responsible for the supervision of users within a sub-organisation that belongs to some Sales Organisation. Compared to the Organisation Admin it cannot create or modify users (except some basic properties), but only observe their activity. |
|
End User |
Standard end-user access. This role manages its own account, views its own subscriptions, and utilises the services it's subscribed to. It has no access to Admin Portal functionality. Users with this role may create pending Subscriptions via the Shop, if this is enabled. |
Using the view icon, you can discover all details of each role. This includes the assigned Permissions, which are visualised for easier understanding in an Overview and in a Matrix view tab.
Permissions
The permissions that can be assigned to a role are organised in various groups that each relate to a certain functionality within SBC. Typically, each group has permissions for Read, Create, Update (i.e. modify) and Delete. These are so-called CRUD operations. Often a role requires at minimum reading certain information, but only a few roles require modifying or deleting data. Some of the SBC functionality requires a more specific and detailed definition of permissions. These are explained in more detail in the following sections. The basic CRUD operations will not be explained in more detail.
When viewing or modifying permissions, certain relationships like prerequisites and dependencies are highlighted using colours and the tool tip gives more information.
User Management
This group relates to the management of Users. Besides Read, Create, Update, and Delete, the following permissions can be configured:
|
Permission |
Description |
|---|---|
|
Change Role |
Can change a user's role (see Account Information) |
|
Change Organisation |
Can change a user’s organisation assignement (see Account Information) |
|
Change Status |
Can change a user's status (see Account Information) |
|
Change Password |
Can change another user's password |
|
Change Own Password |
Can change its own password |
|
Real-Time Service Access |
Can modify real-time service access properties |
|
Real-Time Service Restrictions |
Can modify real-time service restrictions properties |
|
Data Handling & Privacy |
Can modify data handling and privacy properties |
Subscriptions
This group relates to the management of Subscriptions. Besides Read, Create, Update, and Delete, the following permissions can be configured:
|
Permission |
Description |
|---|---|
|
Create |
Can create a pending subscription. Note that activation of a subscription is separated from its creation. |
|
Change Owner |
Can change the owner of a subscription. |
|
Activate |
Can activate (a pending) subscription. Note that activation of a subscription is separated from its creation. |
|
Expire |
Can expire an active subscription immediately. |
|
Renew |
Can renew an expired subscription. |
|
Assign Region |
Can assign regions to a subscription. |
|
Change Renewal Date |
Can change the renewal date of a subscription. |
Organisations
This group relates to the management of Organisations. Only Read, Create, Update, and Delete permissions can be configured for roles with Role Type “Normal”. For Role Type “System”, one additional permission can be defined:
|
Permission |
Description |
|---|---|
|
Manage Level 1 Organisations |
Can read, create, update and delete level 1 organisations (Sales Organisations). |
Articles
This group relates to the management of Articles. Besides Read, Create, Update, and Delete, the following permissions can be configured:
|
Permission |
Description |
|---|---|
|
Assign Region |
Can assign regions to an article. |
Regions
This group relates to the management of Regions. Besides Read, Create, Update, and Delete, the following permissions can be configured:
|
Permission |
Description |
|---|---|
|
View Menu Item |
Can view regions in Service Data menu and navigate to region list page. |
Real-Time Products
This group relates to the management of Real-Time Products. Besides Read, Update, and Delete, the following permissions can be configured:
|
Permission |
Description |
|---|---|
|
Show Description |
Can see the description of Real-Time products |
Note that there is no Create permission, as the Real-Time Products are not created within SBC but within Leica GNSS Spider.
Other Products
This group relates to the management of Other Products. Only Read, Create, Update, and Delete permissions can be configured.
Dashboard
This group relates to access to the Dashboard. Only the Read permissions can be configured and allow seeing the dashboard charts and KPIs
Settings
This group relates to all Settings that influence the general behaviour of a SBC installation. The following permissions can be defined:
|
Permission |
Description |
|---|---|
|
Read |
Can read settings |
|
Manage |
Can manage settings |
As Settings are considered:
-
all sub menus of the Settings menu, i.e.
-
hide/unhide specific sites on the Map View
Attention: above list should be updated, whenever we link something to this permission
Admin Portal
This group encompassed a collection of functionality that is targeted at administrative users. Administrative users are understood as users that manage, provide, and support the GNSS network services, while other users (like those with role End User) are consuming the services.
There is only one permission in this group:
Attention: this table should be updated, whenever we link something to this permission
|
Permission |
Description |
|---|---|
|
Access |
Can access the admin portal. When this is enabled, the following functionality becomes accessible:
|
Audit Log
This group relates to access to the Audit Log. Only the Read permissions can be configured and allow seeing the Audit Log of all changes to the SBC system.
Create User-Defined Roles
Should the predefined roles not be sufficient, there are two ways to create new, additional (user-defined) roles:
-
Using the “+ Add role” button at the top right of the Roles & Permissions overview page
-
Using the Duplicate
icon within the Overview table
Using the “+ Add role” button, you will start with an empty definition. I.e., no permission will be assigned to this new role, and you have to select each permission individually. You have full flexibility. The built-in dependency checks and the Matrix view will support you in configuring the new role correctly.
Using the Duplicate
The name of a role must be unique and should reflect clearly what the targeted responsibility of that role is. Always give the minimum necessary permissions to a role to fulfill its responsibilities.
It is recommended to use the user-defined roles with care. When creating a new role, check all permissions carefully and try it out, if it matches your expectations.
Update Roles
Only user-defined roles can be modified.
Any changes made to the permissions of a role take effect immediately. I.e., if a user is assigned to the modified role, and is currently using the software, he will observe potential changes with his next activity.
Delete Roles
Only user-defined roles can be deleted.
Roles can only be deleted when no user is assigned to it.