Manage users, roles, and permissions
Learn how to create and remove local users, change passwords, assign Administrator, Operator, and Custom roles, and review permissions in the Edge Portal.
The User Management page lets authorized users create local accounts, review account activity, change passwords, assign access roles, inspect permissions, and delete accounts.
The administrator PIN and a user's password serve different purposes. The PIN code is the installation's pairing passphrase and authorizes protected user-management operations. The Password belongs to an individual user and is used with their username to sign in.
Open User Management
- Sign in to the Edge Portal with an account that has the required user permissions.
- Expand Configuration in the sidebar.
- Select Users.
The summary cards show the total number of users and the number of Administrators and Operators. The user table shows each account's username, password control, last-seen time, role, and delete action.
If the Edge Portal cannot load the user list with your current session permissions, it displays a PIN code field. Enter the installation PIN and select Load users.
Understand roles
| Role | Access | How it is used |
|---|---|---|
| Administrator | Full access to all modules. | Use for accounts that must configure and administer the complete installation. |
| Operator | Read-only access to the supported operational modules. The role has no access to User Management. | Use for accounts that should monitor the installation without creating, changing, or deleting configuration. |
Understand Operator permissions
The Operator role has Read permission for these modules:
- Data
- Devices and instances
- Exports
- Files
- Items
- Imports
- License
- Mappings
- Network
- Notifications
- Plugins and Connectors
- Settings
- Updater
- Fleet
For these modules, Create, Edit, and Delete are disabled. All User Management permissions are disabled for Operators.
Understand permission actions
| Permission | What it allows |
|---|---|
| Read | View or retrieve information in the module. |
| Create | Add new records or configuration in the module. |
| Edit | Change existing records or configuration in the module. |
| Delete | Remove records or configuration from the module. |
The available pages and actions can still depend on the installed software, Connectors, and gateway configuration.
Inspect a user's permissions
- Find the user in the table.
- Point to or focus the role icon beside the username.
- Review the displayed role or enabled module permissions.
Administrators are shown as having full access. Operators are identified as read-only. For a Custom role, the tooltip lists each module and its enabled actions.
Create a user
Your account needs full access or the Users: Create permission to create another user.
- Select Add user.
- Enter a Username.
- Enter the user's initial Password.
- Select an initial Role:
- Administrator - full access
- Operator - read-only access
- Enter the administrator PIN code. The Edge Portal can prefill it when the installation PIN is available to your session.
- Select Create user.
A successful operation displays Account created successfully. The new account then appears in the user table.
Only Administrator and Operator can be selected during account creation. A Custom access profile can be assigned afterward when an existing Custom profile is available.
Change a user's role
- Find the user in the table.
- Open the Role selector.
- Select Administrator, Operator, or an available Custom role.
- Wait for User role updated successfully.
The role change is sent as soon as you select a different role. Administrator applies full access. Operator applies the read-only permission set described above.
Changing your own role can remove your ability to administer the installation. Confirm that another Administrator account is available before reducing your own access.
Change a user's password
- Find the user in the table.
- Enter a new value in Set new password.
- Select Set.
- Select Change password.
A successful operation displays Password changed successfully. The user must use the new password the next time they sign in.
The Edge Portal only checks that a new password was entered. Any additional password requirements returned by the gateway must also be followed.
Delete a user
- Find the user in the table.
- Select the delete action.
- Select Delete user.
A successful operation displays User deleted successfully.
Deleting a user permanently removes the account and cannot be undone. The Edge Portal prevents deletion when only one user remains because the installation must retain at least one account.
Understand the Last seen value
Last seen shows the last activity time returned for the user and formats it according to your browser's locale. It displays Never when no activity time is available.
Troubleshoot User Management
| Message or symptom | What to do |
|---|---|
| PIN code is required. | Enter the installation's administrator PIN. Do not enter the user's sign-in password. |
| Unable to load users. | Check that your account has permission to read users. If the PIN entry is displayed, enter the correct PIN and select Load users. Refresh the page if the problem continues. |
| Failed to load PIN code. | Enter the installation PIN manually. Check communication with the gateway if the error continues. |
| Username is required. | Enter a non-empty username. |
| Password is required. | Enter an initial password for the new account. |
| Failed to create account. | Check the PIN, username, and your Users: Create permission. The gateway can display a more specific error, such as an existing username. |
| The user was created, but the Operator role could not be applied. | The account exists, but its role update failed. Refresh the user table, find the new account, and select Operator from the Role selector again. |
| User action failed. | Check your permissions and PIN, then refresh the user list and retry the role, password, or delete action. |
| Unable to delete "[username]". At least one user is needed in SIA. | Create another Administrator account before deleting the last remaining account. |
| No role found. | Clear the Role search. |