Skip to content

Roles & Access

Fleet Manager is multi-tenant. What you can see and do is governed by two things:

  1. Your role inside the current tenant (organization) — admin, operator, or viewer.
  2. Any system role you hold across the whole platform — SUPERUSER or SUPPORT.

The sidebar only shows the modules your role can use, so two people signed into the same tenant may see different menus.

Every member of a tenant has exactly one of these roles:

RoleIn a nutshell
adminFull control of the tenant — everything below, plus users, API keys, settings
operatorDay-to-day operations — manage devices, deployments, groups, registries
viewerRead-only — see devices, groups, applications, and deployments

“Edit” means create and update; “Manage” additionally means delete. A blank cell means the module is not shown to that role.

Areavieweroperatoradmin
DashboardViewViewView
DevicesViewEditManage
GroupsViewEditManage
ApplicationsViewViewManage
DeploymentsViewEdit + roll outManage + approve
Repositories (Git/OCI)EditManage
CertificatesViewManage
UsersViewManage
API KeysManage
Audit LogsViewView
Settings (tenant)Manage
Profile (your own)YesYesYes

Notes:

  • Deployments: operators can create and roll out deployments; approving a deployment (where approval is required) is an admin capability.
  • Viewers see only Dashboard, Devices, Groups, Applications, Deployments, and their own Profile. Repositories, Certificates, Users, API Keys, and Audit Logs are hidden for viewers.
  • API Keys are administered from Settings → Security and are available to admins only.

System roles are granted at the platform level and apply across every tenant.

System roleWhat it grants
SUPERUSERCross-tenant administration: act in any organization, create and administer tenants, switch tenant context. Bypasses tenant role checks.
SUPPORTElevated access for support and troubleshooting, similar in spirit to SUPERUSER.

A superadmin (SUPERUSER) sees the Tenants module and can switch between organizations. Tenant switches are recorded in the audit log.

  • Everyone sees Dashboard, Devices, Groups, Applications, Deployments, and their Profile.
  • Repositories, Certificates, Users, Audit Logs appear for admins and operators.
  • API Keys and tenant Settings appear for admins.
  • Tenants appears only if you belong to more than one tenant or hold a system role.

See each module guide for the exact actions available on that page.