Roles & permissions
Xignage uses role-based access control (RBAC) layered on top of the organisation hierarchy. Roles are scoped — a role granted at one level only applies within that level's boundary.
Role hierarchy
| Role | Scope | Typical use |
|---|---|---|
| Super-admin | Global (all tenants) | Platform administrators |
| Tenant-admin | One tenant | Reseller/partner administrators |
| Team-admin | One team | Company/organisation administrators |
| Site-admin | Assigned site(s) | Branch/location managers |
Super-admin
Full access to everything across all tenants, teams, sites, and users. Platform-level administration only.
Tenant-admin
Full control over their tenant's teams, sites, users, and content. Manages the white-labelled instance for their organisation.
Team-admin
Full control over their team's sites, users, and content. When you create a team you automatically become its team admin. This is the role most organisation administrators use day-to-day.
Site-admin
Manages content, screens, and users for the site(s) they're assigned to. Ideal for local managers who should only control their own location.
How scoping works
Permissions are evaluated within a scope. A team admin can manage everything in their team, but nothing in another team. A site admin can manage their site's screens and content, but not the team-wide settings. This keeps each user's reach matched to their responsibility.
Team roles on creation
When a new team is created, the creator is automatically assigned the team-admin role for that team. Roles and permissions are seeded centrally, so the set of available roles is consistent across the platform.
Permissions
Beyond the broad roles, Xignage defines granular permissions for specific actions — for example managing team settings, managing team members, and viewing members. These permissions are grouped under the roles above, so you usually work with roles rather than individual permissions.