Skip to content
Web APIUser Roles

User Roles

Which role grants each Web API permission.

Include chainreadonlyusermanageradminreadonly is the root and includes nothing.
API permissions by user role. Rows are permissions grouped by resource; columns are the published roles in privilege order. Each cell states whether the role is granted the permission directly, inherits it, or does not have it.
Permission 18 totalreadonly8user15manager18admin18
Anchors2
anchors.manageanchors.manage: not granted to readonly.anchors.manage: not granted to user.anchors.manage: granted here — manager is the minimum role.anchors.manage: inherited by admin from manager.
anchors.readanchors.read: granted here — readonly is the minimum role.anchors.read: inherited by user from readonly.anchors.read: inherited by manager from readonly.anchors.read: inherited by admin from readonly.
Assignments2
assignments.manageassignments.manage: not granted to readonly.assignments.manage: granted here — user is the minimum role.assignments.manage: inherited by manager from user.assignments.manage: inherited by admin from user.
assignments.readassignments.read: granted here — readonly is the minimum role.assignments.read: inherited by user from readonly.assignments.read: inherited by manager from readonly.assignments.read: inherited by admin from readonly.
Buildings2
buildings.managebuildings.manage: not granted to readonly.buildings.manage: not granted to user.buildings.manage: granted here — manager is the minimum role.buildings.manage: inherited by admin from manager.
buildings.readbuildings.read: granted here — readonly is the minimum role.buildings.read: inherited by user from readonly.buildings.read: inherited by manager from readonly.buildings.read: inherited by admin from readonly.
Devices4
devices.path.readdevices.path.read: not granted to readonly.devices.path.read: granted here — user is the minimum role.devices.path.read: inherited by manager from user.devices.path.read: inherited by admin from user.
devices.position_overwrites.managedevices.position_overwrites.manage: not granted to readonly.devices.position_overwrites.manage: granted here — user is the minimum role.devices.position_overwrites.manage: inherited by manager from user.devices.position_overwrites.manage: inherited by admin from user.
devices.readdevices.read: not granted to readonly.devices.read: granted here — user is the minimum role.devices.read: inherited by manager from user.devices.read: inherited by admin from user.
devices.status.readdevices.status.read: not granted to readonly.devices.status.read: granted here — user is the minimum role.devices.status.read: inherited by manager from user.devices.status.read: inherited by admin from user.
Geofences2
geofences.managegeofences.manage: not granted to readonly.geofences.manage: not granted to user.geofences.manage: granted here — manager is the minimum role.geofences.manage: inherited by admin from manager.
geofences.readgeofences.read: granted here — readonly is the minimum role.geofences.read: inherited by user from readonly.geofences.read: inherited by manager from readonly.geofences.read: inherited by admin from readonly.
Live pings1
livepings.readlivepings.read: granted here — readonly is the minimum role.livepings.read: inherited by user from readonly.livepings.read: inherited by manager from readonly.livepings.read: inherited by admin from readonly.
Orders2
orders.manageorders.manage: not granted to readonly.orders.manage: granted here — user is the minimum role.orders.manage: inherited by manager from user.orders.manage: inherited by admin from user.
orders.readorders.read: granted here — readonly is the minimum role.orders.read: inherited by user from readonly.orders.read: inherited by manager from readonly.orders.read: inherited by admin from readonly.
Pings1
pings.readpings.read: granted here — readonly is the minimum role.pings.read: inherited by user from readonly.pings.read: inherited by manager from readonly.pings.read: inherited by admin from readonly.
Transponders2
transponders.managetransponders.manage: not granted to readonly.transponders.manage: granted here — user is the minimum role.transponders.manage: inherited by manager from user.transponders.manage: inherited by admin from user.
transponders.readtransponders.read: granted here — readonly is the minimum role.transponders.read: inherited by user from readonly.transponders.read: inherited by manager from readonly.transponders.read: inherited by admin from readonly.

the table scrolls sideways on a narrow screen; the permission column stays put.

admin grants no permission of its own here — it holds exactly what it inherits, the same 18 permissions as manager. Anything more it can do lies outside this API.

Every cell carries its state as a sentence for screen readers — the glyph and the tint are never the only cue. Permission names link to the matching entry on the Permissions page.