Skip to main content

11. Roles & Permissions

Permissions as basic capability definition and Roles as Permission bundles that enable quick assignment through teams to multiple users

Permissions

Permissions are the individual capabilities MontBlancAI defines — each one a specific action on a specific part of the product. The catalog is maintained by MontBlancAI and is the same for every organization; you decide who holds which permissions by bundling them into roles.


Permissions follow a consistent *action + area* pattern (view, add, edit, delete, share, run, use, manage), and any write permission automatically includes the matching view permission — someone who can edit dashboards can always see them.


The catalog covers these areas:

Area

Examples

Asset hierarchy

View / add / edit / delete / share sites, areas, lines, equipment (equipment permissions also govern its signals)

Configuration

View / edit configuration and the digital twin

Dashboards & visualization

Dashboards, cockpit, production timeline, signals, saved views

Anomalies

View anomalies, rate anomalies, view ratings

Thresholds

View / add / edit / delete thresholds

Incidents

Manage incidents, use the Alpinist incident investigator

Comments

Manage comments and comment categories

Alpinist AI

Use Alpinist chat, scheduled prompts, knowledge-base documents, integrations

Edge

Manage edge connections and data sources

Batch tracing

Run batch tracing

Resource groups

View resource groups (baseline); manage resource group access (opt-in)

Administration

User management, role management, team management

Support

Contact Intercom support

Roles

A Role is a named bundle of permissions, defined per organization. Roles are how you translate job functions ("maintenance engineer", "quality viewer") into access. You assign roles to teams — either as team default roles (everyone in the team) or to individual users within a team.

Default Role with the View Resource Groups permission:


Roles your organization starts with

Every organization is set up with a practical starting set:

  • Default Role — attached to the Default team, so every member has it. It grants the standard product permissions but deliberately excludes the administrative ones: user management, role management, team management, and resource group access management.

  • Machine Admins — full permissions on the asset hierarchy and product features.

  • Users — day-to-day operations: read access to the asset hierarchy and configuration, full access to operational features like dashboards, thresholds, and incidents.

  • Read Only — view permissions only; the default pairing for teams synced from Microsoft Entra ID.

  • Account Management — the administrative permissions (user, role, and team management) for delegated administrators.

These are ordinary roles in your organization — you can adjust them or build your own from scratch.


Editing roles takes effect immediately

Roles stay live: when you add or remove permissions on a role, everyone holding that role gets the change immediately. Removing a role from a team or user immediately revokes the permissions that came from it (they keep anything still granted by other roles or teams).


Who can manage roles

Action

Who

Browse the permission catalog

Any member

View the organization's roles

Owners, admins, or holders of the role management permission

Create, edit, delete roles

Owners, admins, or holders of the role management permission

Assign roles to teams or users

Owners, admins, or holders of the team management permission

Remember that owners and admins are not limited by roles — they always have full access.

Did this answer your question?