Skip to main content

Roles & permissions

Xignage uses role-based access control (RBAC) layered on top of the organisation hierarchy. Roles are scoped — a role granted at one level only applies within that level's boundary.

Role hierarchy

RoleScopeTypical use
Super-adminGlobal (all tenants)Platform administrators
Tenant-adminOne tenantReseller/partner administrators
Team-adminOne teamCompany/organisation administrators
Site-adminAssigned site(s)Branch/location managers

Super-admin

Full access to everything across all tenants, teams, sites, and users. Platform-level administration only.

Tenant-admin

Full control over their tenant's teams, sites, users, and content. Manages the white-labelled instance for their organisation.

Team-admin

Full control over their team's sites, users, and content. When you create a team you automatically become its team admin. This is the role most organisation administrators use day-to-day.

Site-admin

Manages content, screens, and users for the site(s) they're assigned to. Ideal for local managers who should only control their own location.

How scoping works

Permissions are evaluated within a scope. A team admin can manage everything in their team, but nothing in another team. A site admin can manage their site's screens and content, but not the team-wide settings. This keeps each user's reach matched to their responsibility.

Team roles on creation

When a new team is created, the creator is automatically assigned the team-admin role for that team. Roles and permissions are seeded centrally, so the set of available roles is consistent across the platform.

Permissions

Beyond the broad roles, Xignage defines granular permissions for specific actions — for example managing team settings, managing team members, and viewing members. These permissions are grouped under the roles above, so you usually work with roles rather than individual permissions.

See also