Skip to content

Roles and permissions

Eriga has four roles, organized on two levels: space and unit.

Owner (space)
└─ Admin (space)
└─ Operator (unit)
└─ Viewer (unit)
  • Owner and Admin can see and manage the entire space
  • Operator and Viewer can only see the units they are assigned to
ActionOwnerAdminOperatorViewer
Rename the spaceYes
Delete the spaceYes
Add/remove adminsYes
ActionOwnerAdminOperatorViewer
Create unitsYesYes
Rename/delete unitsYesYes
Register resourcesYesYes
Edit/delete resourcesYesYes
Define actionsYesYes
Edit/delete actionsYesYes
Associate resources/actions with unitsYesYes
Assign roles on unitsYesYes
ActionOwnerAdminOperatorViewer
Issue certificatesYesYesYes*
Edit certificatesYesYesYes*
Revoke certificatesYesYesYes*
Manage attachmentsYesYesYes*
View complianceYesYesYes*Yes*

*Only for units they are assigned to.

Visible dataOwnerAdminOperatorViewer
All unitsYesYesOwn onlyOwn only
All resourcesYesYesOwn units onlyOwn units only
All actionsYesYesOwn units onlyOwn units only
All certificatesYesYesOwn units onlyOwn units only
DashboardYesYesFilteredFiltered
  • Owner: the person who creates the space. Not transferable.
  • Admin: assigned by the Owner on the Settings page.
  • Operator / Viewer: assigned by the Owner or an Admin in the unit detail.

A user can have only one role per unit. Assigning a new role replaces the previous one.