Nexeed
    • Introduction
    • User manual
      • Condition monitoring and its tabs
        • Live
        • Counters
        • Measurements
        • Events
        • Rules
        • View configuration
        • Details
      • Rules management
        • Rule types and standard functions
        • Rule details
      • Function configuration
      • Condition Monitoring widgets
      • Access Management
        • Application Roles
        • Fine-Grained Access Control and Configuration
        • How to Configure Organization Roles
    • Operations manual
      • Overview
      • System architecture and interfaces
        • System components
      • System requirements
        • General notes
        • cm/condition-monitoring-core
        • cm/rule-service-app
        • cm/rule-function-executor
        • cm/rule-result-aggregator
        • cm/rule-value-aggregator
        • cm/rule-value-provider
        • cm/stateful-function-executor
      • Migration from previous versions
        • Migration to 2.1+
        • Migration from CPM 1.5.4 to CM and RM 3.0.x (Nexeed IAS 2023.02.00.xx)
          • CPM to CM relational database migration
          • CPM to RM relational database migration
          • CM Influx database migration
          • Deletion of an old CPM installation
        • Resources mapping from MES to IAS Condition Monitoring
        • Migration to 4.0.0+ (Nexeed IAS 2024.01.00.xx)
        • Migration to 4.3.x (Nexeed IAS 2024.02.01.x)
        • Migration to 4.5.x (Nexeed IAS 2025.01.00.x)
        • Migration to 4.6.x (Nexeed IAS 2025.01.01.x)
        • Migration to 4.8.x (Nexeed IAS 2025.02.00.x)
        • Migration to 4.9.x (Nexeed IAS 2025.02.01.x)
      • Setup and configuration
        • Manual MACMA configuration after setting up a new tenant
        • RabbitMQ
        • Influx configuration
        • Kafka topics
        • Condition Monitoring - Helm Configuration
        • Advanced configuration parameters
          • cm/condition-monitoring-core
            • Common shared variables
            • Portal shared variables
            • MDM shared variables
            • RabbitMQ shared variables
            • OTEL shared variables
          • cm/rule-service-app
            • Rules Management shared variables
            • KAFKA shared variables
          • cm/rule-function-executor
          • cm/rule-result-aggregator
          • cm/rule-value-aggregator
          • cm/rule-value-provider
          • cm/stateful-function-executor
      • Start and shutdown
      • Regular operations
      • Failure handling
        • Rule Management Light Helm installation failing when Kafka is disabled or Kafka is not configured at all
        • User manual injection into Rule Management
        • Infrastructure outages: health verification Endpoints
        • OPP/PPMP are not received in CM
        • Master data (Devices, Facilities, Measuring Points, DeviceTypes) is missing in CM
        • CM is not visible in the portal
        • How to verify if the broker is out of sync
      • Backup and Restore
      • Logging and monitoring
        • General logging characteristics
        • Required monitoring
        • General logging format
        • Request-based logging format
        • Security logging format
        • Lifecycle logging format
        • Module health Endpoints and K8s probes
      • Known limitations
    • API documentation
      • Condition Monitoring HTTP API
      • Rules Management HTTP API
    • Glossary
Condition Monitoring
  • Industrial Application System
  • Core Services
    • Block Management
    • Deviation Processor
    • ID Builder
    • Multitenant Access Control
    • Notification Service
    • Ticket Management
    • Web Portal
  • Shopfloor Management
    • Andon Live
    • Global Production Overview
    • KPI Reporting
    • Operational Routines
    • Shift Book
    • Shopfloor Management Administration
  • Product & Quality
    • Product Setup Management
    • Part Traceability
    • Process Quality
    • Setup Specs
  • Execution
    • Line Control
    • Material Management
    • Order Management
    • Packaging Control
    • Rework Control
  • Intralogistics
    • AGV Control Center
    • Stock Management
    • Transport Management
  • Machine & Equipment
    • Condition Monitoring
    • Device Portal
    • Maintenance Management
    • Tool Management
  • Enterprise & Shopfloor Integration
    • Archiving Bridge
    • Data Publisher
    • Direct Data Link
    • Engineering UI
    • ERP Connectivity
    • Gateway
    • Information Router
    • Master Data Management
    • Orchestrator

Nexeed Learning Portal

  • Condition Monitoring
  • User manual
  • Access Management
  • Fine-Grained Access Control and Configuration
preview 4.10.0

Fine-Grained Access Control and Configuration

This page explains how to configure facility-level access control for Condition Monitoring and Rules Management applications.

Overview

Fine-grained access control allows you to restrict user access to specific facilities, areas, lines, or stations. This works in addition to the application roles described in Application Roles.

How Fine-Grained Access Works

Plant Hierarchy Example

Plant Hierarchy Structure

The system organizes resources in a hierarchical structure:

  • Plant (highest level)

    • Area (production area)

      • Line (production line)

        • Station (individual work station)

Access Inheritance

  • Permissions granted at a higher level automatically apply to all lower levels

  • Example: Access to an Area includes access to all Lines and Stations within that Area

Configuring Access Permissions

Configuring Facility-Level Permissions

To configure fine-grained access control for specific facilities, you need to create facilities in Master Data Management and then assign facility-specific permissions.

Step 1: Create Facilities in Master Data Management

Before assigning facility-level permissions, the facilities must exist in the system:

  • Create the facility in Master Data Management (Plant, Area, Line, Station)

    For detailed instructions: Add Facility in Master Data Management

Step 2: Assign Application Roles

Ensure users have the appropriate application roles:

  • condition-monitoring-user for basic Condition Monitoring access

  • rule-management-user for basic Rules Management access

  • Higher-level roles (expert, admin) as needed

Step 3: Create Custom Roles and Assign Facility Permissions

Create custom roles that combine application roles with facility-specific permissions:

  1. Create a custom role in the Multitenant Access Control system

  2. Assign facility-specific permissions to the role

    For detailed instructions: Adding a Role

Step 4: Assign Roles to Users

Assign the custom roles to users who need facility-level access:

  1. Navigate to user management in Multitenant Access Control

  2. Assign the appropriate roles to users

    For detailed instructions: Assigning a User to a Role

Resource Types and Permissions

Condition Monitoring Resources

Available Permissions:

  • Read: View condition monitoring data

  • Add: Create new monitoring configurations

  • Modify: Edit existing configurations

  • Delete: Remove monitoring configurations

Facility-Level Resources:

  • Machine data viewing and export

  • View configuration management

  • Machine counter access

  • Error sequence detection

Rules Management Resources

Available Permissions:

  • Read: View rules and configurations

  • Add: Create new rules

  • Modify: Edit existing rules

  • Delete: Remove rules

Facility-Level Resources:

  • Rule creation and management

Related Topics

  • Application Roles - Overview of available roles

  • Organization Roles Configuration - Manual MACMA role configuration guide

  • Multitenant Access Control - General access control documentation

  • Master Data Management - Creating facilities and equipment

  • Adding Custom Roles - Role creation guide

  • User Role Assignment - Assigning roles to users

Contents

© Robert Bosch Manufacturing Solutions GmbH 2023-2025, all rights reserved

Changelog Corporate information Legal notice Data protection notice Third party licenses