SBC Online Help
Breadcrumbs

Roles & Permissions

Purpose and Terminology

SBC uses Roles and Permissions to control what users can see and do in a consistent, secure, and manageable way. Instead of configuring access for each individual user, permissions are grouped into roles (such as System Admin, Organisation Admin, or End User), and users are assigned one of these roles based on their responsibilities. This approach improves security by ensuring users only have access to the functions and data they need, reduces the risk of accidental or unauthorised changes, and makes user management easier to scale and maintain as organisations grow or requirements change.

As a quick summary, some definitions and terminology used:

  • User: Any user of the software, independent of its role (different from the role of End User).

  • Role: A role is a named collection of permissions that represents a set of responsibilities or a job function; users are assigned roles to conveniently and consistently define what they are allowed to do in the system.

  • Permission: A permission is a specific authorisation to perform an action or access a resource (for example, read, create, update, or delete), and these permissions are checked by the system to control the behaviour of the user interface and API.

Overview

The overview displays all roles currently defined.

Any installation of SBC comes with a set of predefined roles. Those roles cannot be modified. Their permissions can be viewed with the necessary Read Settings permissions. If you do not have these permissions, this help page serves as your reference. With the permission of Manage Settings, new roles can be created.

The overview displays the general properties of each role:

Parameter

Description

Role Name

Name identifying the role in other places.

Description

Additional information describing the role in more detail.

Role Type

Three types of roles are distinguished:

  • System: Roles of this type can only be assigned to the System Root (Level-0 organisation). They have elevated rights and are able to see and manage all resources (users, subscriptions, etc.) across all organisations at any level.

  • Sales Org: Roles of this type can only be assigned to Sales Organisations (Level-1 organisations). They can manage all resources within their sales organisation and its sub-organisations.

  • Normal: Roles of this type can be assigned to Sales Organisations (Level-1) and their sub-organisations. With the correct permissions, they can manage resources within their own organisation and its descendants, but cannot administer the sales organisation itself (even if they are assigned to one).

Predefined Role

This indicates if the role is a predefined or a user-defined role.

Users

Shows the number of users that are currently assigned to this role.

Using the view icon, you can discover all details of each role. This includes the assigned Permissions, which are visualised for easier understanding in an Overview and in a Matrix view tab.

Predefined Roles

The following roles are predefined on any installation of SBC:

Role

Description

System Admin

Full system access. Unrestricted access to all features and data.

This is the highest role, serving the master administrator who configures the system and service offering at the IT and business level.

System Operator

Manages users, subscriptions, organisations, and regions across the entire system.

This role is targeted for users responsible for the daily user and subscription management.

It can view all pages of the Admin portal, can create/update/delete Users, Regions and Organisation (but not Sales Organisations). It can create new and activate pending Subscriptions, change the owner of a Subscription, but cannot modify them any further, and it cannot modify the Settings.

System Support

Read-only access on system level.

This role is targeted for support and diagnostics tasks.

It can view all pages of the Admin portal, but cannot create new data records (e.g. Users, Subscriptions).

Sales Org Admin

Full administration of their sales organisation, users, and subscriptions.

This role is targeted for users responsible for the daily user and subscription management of a Sales Organisation.

It is able to manage all data associated to users and subscriptions within his sales organisation and their children. This includes the activation, renewal or expiration of subscriptions.

Sales Org Operator

Manages users and subscriptions within their sales organisation.

This role is targeted for users responsible for support and diagnostics within its Sales Organisation.

It can create users and activate subscriptions, but has limited capabilities to modify existing subscriptions. It can create further child organisations and can utilise all features that help supporting other members of its Sales Organisation and its children.

Organisation Admin

Manages users and roles within their own organisation.

This role is targeted for users responsible for the user management or user supervision within a sub-organisation that belongs to some Sales Organisation. E.g., it can be a dealer selling subscriptions, or it can be a supervisor of a team within a company.

It can create and modify users and observe their activity with the Admin Portal functionality. This role cannot create or modify any subscription.

Organisation Support

Read-only access within their organisation for support or supervisor tasks.

This role is targeted for users responsible for the supervision of users within a sub-organisation that belongs to some Sales Organisation.

Compared to the Organisation Admin it cannot create or modify users (except some basic properties), but only observe their activity.

End User

Standard end-user access.

This role manages its own account, views its own subscriptions, and utilises the services it's subscribed to. It has no access to Admin Portal functionality.

Users with this role may create pending Subscriptions via the Shop, if this is enabled.

Using the view icon, you can discover all details of each role. This includes the assigned Permissions, which are visualised for easier understanding in an Overview and in a Matrix view tab.

Permissions

The permissions that can be assigned to a role are organised in various groups that each relate to a certain functionality within SBC. Typically, each group has permissions for Read, Create, Update (i.e. modify) and Delete. These are so-called CRUD operations. Often a role requires at minimum reading certain information, but only a few roles require modifying or deleting data. Some of the SBC functionality requires a more specific and detailed definition of permissions. These are explained in more detail in the following sections. The basic CRUD operations will not be explained in more detail.

When viewing or modifying permissions, certain relationships like prerequisites and dependencies are highlighted using colours and the tool tip gives more information.

User Management

This group relates to the management of Users. Besides Read, Create, Update, and Delete, the following permissions can be configured:

Permission

Description

Change Role

Can change a user's role (see Account Information)

Change Organisation

Can change a user’s organisation assignement (see Account Information)

Change Status

Can change a user's status (see Account Information)

Change Password

Can change another user's password

Change Own Password

Can change its own password

Real-Time Service Access

Can modify real-time service access properties

Real-Time Service Restrictions

Can modify real-time service restrictions properties

Data Handling & Privacy

Can modify data handling and privacy properties

Subscriptions

This group relates to the management of Subscriptions. Besides Read, Create, Update, and Delete, the following permissions can be configured:

Permission

Description

Create

Can create a pending subscription.

Note that activation of a subscription is separated from its creation.

Change Owner

Can change the owner of a subscription.

Activate

Can activate (a pending) subscription.

Note that activation of a subscription is separated from its creation.

Expire

Can expire an active subscription immediately.

Renew

Can renew an expired subscription.

Assign Region

Can assign regions to a subscription.

Change Renewal Date

Can change the renewal date of a subscription.

Organisations

This group relates to the management of Organisations. Only Read, Create, Update, and Delete permissions can be configured for roles with Role Type “Normal”. For Role Type “System”, one additional permission can be defined:

Permission

Description

Manage Level 1 Organisations

Can read, create, update and delete level 1 organisations (Sales Organisations).

Articles

This group relates to the management of Articles. Besides Read, Create, Update, and Delete, the following permissions can be configured:

Permission

Description

Assign Region

Can assign regions to an article.

Regions

This group relates to the management of Regions. Besides Read, Create, Update, and Delete, the following permissions can be configured:

Permission

Description

View Menu Item

Can view regions in Service Data menu and navigate to region list page.

Real-Time Products

This group relates to the management of Real-Time Products. Besides Read, Update, and Delete, the following permissions can be configured:

Permission

Description

Show Description

Can see the description of Real-Time products

Note that there is no Create permission, as the Real-Time Products are not created within SBC but within Leica GNSS Spider.

Other Products

This group relates to the management of Other Products. Only Read, Create, Update, and Delete permissions can be configured.

Dashboard

This group relates to access to the Dashboard. Only the Read permissions can be configured and allow seeing the dashboard charts and KPIs

Settings

This group relates to all Settings that influence the general behaviour of a SBC installation. The following permissions can be defined:

Permission

Description

Read

Can read settings

Manage

Can manage settings

As Settings are considered:

  • all sub menus of the Settings menu, i.e.

  • hide/unhide specific sites on the Map View

Attention: above list should be updated, whenever we link something to this permission

Admin Portal

This group encompassed a collection of functionality that is targeted at administrative users. Administrative users are understood as users that manage, provide, and support the GNSS network services, while other users (like those with role End User) are consuming the services.

There is only one permission in this group:

Attention: this table should be updated, whenever we link something to this permission

Permission

Description

Access

Can access the admin portal.

When this is enabled, the following functionality becomes accessible:

  • Is able to see all other users within its own organisation and its child organisations.

  • Access to Service Data pages including: Users, Subscriptions, Organisations, Articles, Regions, Real-Time Products and Other Products.

  • Access to Live Status Map View without a subscription (note, that also Subscriptions-Read is required in addition, and Settings-Read allows seeing hidden sites),

  • Manage and shows private Articles (without it, just public articles are visible)

  • Access to Support Cockpit

Audit Log

This group relates to access to the Audit Log. Only the Read permissions can be configured and allow seeing the Audit Log of all changes to the SBC system.

Create User-Defined Roles

Should the predefined roles not be sufficient, there are two ways to create new, additional (user-defined) roles:

  • Using the “+ Add role” button at the top right of the Roles & Permissions overview page

  • Using the Duplicate copy-regular-full.svg icon within the Overview table

Using the “+ Add role” button, you will start with an empty definition. I.e., no permission will be assigned to this new role, and you have to select each permission individually. You have full flexibility. The built-in dependency checks and the Matrix view will support you in configuring the new role correctly.

Using the Duplicate copy-regular-full.svg icon lets you create a new role based on a copy of an existing role. This allows you to conveniently create a new role that is just slightly different from an already existing one.

The name of a role must be unique and should reflect clearly what the targeted responsibility of that role is. Always give the minimum necessary permissions to a role to fulfill its responsibilities.

It is recommended to use the user-defined roles with care. When creating a new role, check all permissions carefully and try it out, if it matches your expectations.

Update Roles

Only user-defined roles can be modified.

Any changes made to the permissions of a role take effect immediately. I.e., if a user is assigned to the modified role, and is currently using the software, he will observe potential changes with his next activity.

Delete Roles

Only user-defined roles can be deleted.

Roles can only be deleted when no user is assigned to it.