Permissions
Permissions are the individual capabilities MontBlancAI defines — each one a specific action on a specific part of the product. The catalog is maintained by MontBlancAI and is the same for every organization; you decide who holds which permissions by bundling them into roles.
Permissions follow a consistent *action + area* pattern (view, add, edit, delete, share, run, use, manage), and any write permission automatically includes the matching view permission — someone who can edit dashboards can always see them.
The catalog covers these areas:
Area | Examples |
Asset hierarchy | View / add / edit / delete / share sites, areas, lines, equipment (equipment permissions also govern its signals) |
Configuration | View / edit configuration and the digital twin |
Dashboards & visualization | Dashboards, cockpit, production timeline, signals, saved views |
Anomalies | View anomalies, rate anomalies, view ratings |
Thresholds | View / add / edit / delete thresholds |
Incidents | Manage incidents, use the Alpinist incident investigator |
Comments | Manage comments and comment categories |
Alpinist AI | Use Alpinist chat, scheduled prompts, knowledge-base documents, integrations |
Edge | Manage edge connections and data sources |
Batch tracing | Run batch tracing |
Resource groups | View resource groups (baseline); manage resource group access (opt-in) |
Administration | User management, role management, team management |
Support | Contact Intercom support |
Roles
A Role is a named bundle of permissions, defined per organization. Roles are how you translate job functions ("maintenance engineer", "quality viewer") into access. You assign roles to teams — either as team default roles (everyone in the team) or to individual users within a team.
Default Role with the View Resource Groups permission:
Roles your organization starts with
New organizations are set up with one team and one role, so you can start working right away:
Default Role — attached to the Default team, so every member has it. It grants the full set of permissions, including the administrative ones: user management, role management, team management, and resource group access management.
Because every member of a new organization holds every permission, anyone you invite can manage users, roles, and teams. If you want to separate access, create narrower roles and teams and move people into them before you invite more colleagues.
When you connect Microsoft Entra ID, one more role is added:
Read Only — view permissions only, with no administrative access; the default role for teams synced from Microsoft Entra ID.
Editing roles takes effect immediately
Roles stay live: when you add or remove permissions on a role, everyone holding that role gets the change immediately. Removing a role from a team or user immediately revokes the permissions that came from it (they keep anything still granted by other roles or teams).
Who can manage roles
Action | Who |
Browse the permission catalog | Any member |
View the organization's roles | Owners, admins, or holders of the role management permission |
Create, edit, delete roles | Owners, admins, or holders of the role management permission |
Assign roles to teams or users | Owners, admins, or holders of the team management permission |
Remember that owners and admins are not limited by roles — they always have full access.



