Facility-Related Access Control
Through the integration of an Access Control List (ACL), resources are automatically created in the Multitenant Access Control module for access control in Condition Monitoring , Rules Management , Deviation Notification , and Function Configuration. Roles and permissions must be created manually for these resources in the Multitenant Access Control module; these can then be assigned to users or user groups.
By default, resources are automatically registered for the Area facility level. Lines and stations inherit the information from the higher-level area. |
Example

Two resources are registered in the Multitenant Access Control module:
-
Rules for area Fe2.1 (including sub-facilities)
-
Rules for area Fe2.2 (including sub-facilities)
The other facilities (lines and stations) are not registered as a resource. |
Resources for Facilities
When a facility (area) is added, a resource is automatically assigned to each of the access rights in the Health Monitoring , Rules Management , Deviation Notification and Function Configuration of the device in the Multitenant Access Control module.
Example
Facility level | Name | Authorizations | Description |
---|---|---|---|
Area A |
|
Read |
Access the rules of devices associated with area A or its subordinate facilities |
Create role for facilities
Prerequisite
Administrator
or Rule Service Administrator
role
Procedure
-
Create facility.
The permissions for the created facility are created automatically.
-
Create role and assign permissions.
-
Assigning a Role to a User
A role has been created for a facility.
Examples: Role for facilities
The following three examples show how an ACL-‑based authorization can be implemented in Condition Monitoring , Rules Management , Deviation Notification and Function Configuration. The organizational roles shown must be created manually:
User area A
-
Application role: Read
Rule Service User
: -
Authorizations:
Area A — Rule
: Read -
Rights of User area A :
-
Sees the Efficiency Analysis menu in the portal > Rules management
-
Can see, edit, add and delete rules of devices associated with area A or its subordinate facilities
-
Can see, edit, add and delete rules of device types whose devices are associated with area A or their subordinate facilities
-
User area A admin
-
Application role: Read
Rule Service User
: -
Authorizations:
Area A — Rule
: create, read, modify, delete -
Rights of User area A admin :
-
Sees the Efficiency Analysis menu in the portal > Rules management
-
Can see, edit, add and delete rules of devices associated with area A or its subordinate facilities
-
Can see, edit, add and delete rules of device types whose devices are associated with area A or its subordinate facilities
-
User area A ‑ C Admin
-
Application role: Read
Rule Service User
: -
Authorizations:
Area A — Rule
: create, read, modify, delete -
Authorizations:
Area B — Rule
: create, read, modify, delete -
Authorizations:
Area C — Rule
: create, read, modify, delete -
Rights of User Area A - C Admin :
-
Sees the Efficiency Analysis menu in the portal > Rules management
-
Can see, edit, add and delete rules of devices associated with areas A ‑ -C or their subordinate facilities
-
Can see, edit, add and delete rules of device types whose devices are associated with areas A ‑ -C or their subordinate facilities
-