Foundational Modules
Security controls who signs in and what they can reach. Use your identity provider over SAML or OIDC, or a password. Your administrators set roles and sites.
Sign-in
Use single sign-on through SAML or OIDC, or a username and password where that isn’t set up. Your session refreshes on its own, so there’s no second login. Each company signs in at its own address, with its own settings.
Users
Add a person, verify their address, and set a first password. If someone forgets a password, they reset it themselves, no call needed. Every user for the company and site shows up in one screen.
Roles and permissions
Create a role and choose which Modules and actions it can reach. Copy an existing role as the starting point for the next one. A person can hold one role or several.
Access scope
Someone assigned to two plants sees those two and nothing more. Site access is set on the person, so the same role works at every site without opening up more than it should. Adding a site is a change to one account.
Access denied
Access follows the role and the site a person is assigned to, not what an individual record says. A blocked route lands on a plain denied page. Your own administrators set every role and every site assignment.
No. Sign-in goes through your provider over SAML or OIDC, and the platform holds the roles and site access.
By the Module, the action, the role the user holds, and the sites that user is assigned to.
Yes. Site access is assigned per user, so a planner covering two plants holds one role and two sites.
The Module does not load. The person lands on a plain denied page.
30 minutes on your identity provider and how access is scoped by role and site.
We use cookies to understand how the site is used and to connect form submissions to earlier visits. No analytics or marketing cookies are set until you choose. Privacy Policy