Access Management

Access management provides the ability to grant permissions to different user accounts to resources in your environment. Resources are the organization, sub-organizations, and apps that you can use. To use an application in FactoryTalk Hub, you need to be assigned a role within an organization, sub-organization, or application. If you have a role assigned at organization or sub-organization level, you are granted access to all applications in that organization or sub-organization. If you have a role assigned only at a specific application, it grants permissions to that application. To use an application in FactoryTalk Hub, a resource role associated with the service is required. Roles control the functions in those services that are visible when the specified user account signs in to FactoryTalk Hub. The default access level without a resource-role is usually “no access” but some services do have limited access without a resource-role.
TIP: By having a role at the organization level, users automatically have access to all the services in that organization and all its sub-organizations and their services.
The access is editable for one user at a time and one user can be granted access to several resources in the whole organizational hierarchy at once. New users are added through invitations or request access links. When searching for a user, all users from a complete organizational hierarchy (parent organization and all its sub-organizations) can be selected to give additional permissions.
From the FactoryTalk menu, select
Manage User Access
. The
Manage User Access
screen appears. The owner or administrator can see all user and their roles in the whole parent organization hierarchy, even when they act from the sub-organization level. On this screen, the owner and administrators can manage the access for users in their organization or sub-organization. If a user does not appear in the list, you can add them by selecting the
Invite Users
button on the top right of the Manage User Access page.
TIP: The FactoryTalk Hub manager menu is only visible after you have created or joined an organization.
To grant access to a user accounts and manage their roles:
  1. In the search bar, enter the user name you want to add. If the user is not in the organization, they must be invited first by sending them invitations or responding to request access from the users.
  2. Select the user you want to grant access to a organization or sub-organization and from the
    Manage Direct Role
    column select the role you want to assign to the user.
    NOTE: The user's roles are inherited down in the hierarchy, which means that if you assign a role to a user in an organization, all the sub-organizations and services inherit the same role. You can assign a different role individually for specific sub-organizations or services. You can see in the
    Effective Role's Source
    column if the role is assigned directly or inherited. The role with more privileges always overrides the role with less privileges.
  3. Select
    Save Changes
    .
Manage User Access Screen
An administrator of a service who is not administrator of a specific organization or sub-organization can still change the roles of a user in this organization but only for the service. By toggling the
Show resources outside my admin access
, the administrator can see all of the roles of a user in all organizations or sub-organizations but they cannot edit them.
To remove access from a user account:
Only administrators of a resource can remove access to it.
TIP: Administrators of a resource cannot remove access to it if access is inherited from a resource higher in the hierarchy which this administrator cannot manage.
  1. On the
    Manage User Access
    screen, use the search bar or navigate through the users and select the user you want to manage access for.
  2. From the user resources list, find the resource you want to remove access to and select the delete icon.
To invite users to an organization:
  1. On the
    Manage User Access
    screen, select the
    Invite Users
    button. The
    Send invites
    screen appears.
  2. Select the resource that you are inviting the new user to have access to from the
    Resource
    drop-down list.
  3. Select the
    Role
    that the new user will have.
  4. Enter the email address or addresses of the people that you want to invite to your organization. You can add multiple emails if they will have the same resource and role privileges.
For more information, see Send Invites.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal