Using Areas: Roles & Permissions (DRAFT)
DRAFT
)Areas are optional and should only be used when different administrators need to manage separate parts of the system. Consult your integrator before implementing additional areas.
Default area – COMMON
Every site starts with a single area called
COMMON
. By default, every object in the site (devices, users, user groups, schedules, rules, dashboards, and events) is automatically assigned to the COMMON area. If a site uses only the default COMMON area, all new objects are automatically assigned to the COMMON area. Most sites only need the COMMON area. If a site does not use areas for administrative segmentation, all of these objects are stored in the default COMMON area.If additional areas are added, this can be done in the Global settings. <> link?
Web Access Roles and Permissions (should this be more than web? web and mobile)
[PLACEHOLDER] permissions table pending: preset role permissions and what each permission allows, THEN explain the impact of Area access on those web-access permissions.
- When setting up a new user who needs to perform administrative functions, the associated area must be assignedMANAGEaccess to COMMON. Administrative functions include commissioning and syncing locks with the mobile apps, and who need web access to manage users or devices, and monitor dashboards,
How Area Access Affects Web Access Permissions
Area access acts as a
prerequisite
for a web access user’s permissions, it determines whether those permissions can take effect within a given area at all. It does not replace or expand a user’s web access permissions. Every web access user must be assigned area access explicitly.- If a web access user hasNONEaccess to an area, they will not be able to view or modify anything within that area, regardless of their specific web access permission
- If a web access user hasVIEWaccess to an area, they can only VIEW the objects in that area, to the extent their web access permissions allow.
- If a web access user has *MANAGE * access to an area, they can VIEW and MODIFY the objects in that area, to the extent their web access permissions allow.
**Residents do not require area access in order to have. BLE or NFC mobile app. Web app. Need to have MANAGE to
To commission a lock, a web access user must have Manage access to the relevant area and the web access permissions required to manage devices. View access alone is not sufficient. (is this not the same things?)
COMMON Area This is how a site might use this…
Practical Setup Rules
- Plan areas before you configure anything else.Once a second area is added, every object in the system must be explicitly assigned to an area. This is difficult to reorganize after the fact.
- Assign each device to the area where it is physically located.A lock on a Building 2 door should be assigned to the Building 2 area.
- Determine how communal objects will be managed before assigning devices.Shared entry points lobby doors, building entrances, parking gates need to be assigned to an area that all relevant administrators can access. Physical location alone should not determine where a communal device is assigned; the site’s administrative structure should guide that decision.
- Administrators need access to every area containing objects they manage.An administrator who manages users or devices across multiple areas must have the appropriate access level on each of those areas, including COMMON if shared objects are stored there.
- Areas must exist before commissioning begins.Because every device must be assigned to an area when it is added to the system, the area structure must be defined first.
At present, all Schlage devices are commissioned to the COMMON area by default, even when other areas exist on the site. After commissioning, the device must be manually moved to its intended area in device settings. The user performing this move must have Manage access to both COMMON and the target area, as well as the web access permissions required to manage devices.