Permissions
Permissions are the individual capabilities MontBlancAI defines — each one a specific action on a specific part of the product. The catalog is maintained by MontBlancAI and is the same for every organization; you decide who holds which permissions by bundling them into roles.
Permissions follow a consistent *action + area* pattern (view, add, edit, delete, share, run, use, manage), and any write permission automatically includes the matching view permission — someone who can edit dashboards can always see them.
The catalog covers these areas:
Area | Examples |
Asset hierarchy | View / add / edit / delete / share sites, areas, lines, equipment (equipment permissions also govern its signals) |
Configuration | View / edit configuration and the digital twin |
Dashboards & visualization | Dashboards, cockpit, production timeline, signals, saved views |
Anomalies | View anomalies, rate anomalies, view ratings |
Thresholds | View / add / edit / delete thresholds |
Incidents | Manage incidents, use the Alpinist incident investigator |
Comments | Manage comments and comment categories |
Alpinist AI | Use Alpinist chat, scheduled prompts, knowledge-base documents, integrations |
Edge | Manage edge connections and data sources |
Batch tracing | Run batch tracing |
Resource groups | View resource groups (baseline); manage resource group access (opt-in) |
Administration | User management, role management, team management |
Support | Contact Intercom support |
Roles
A Role is a named bundle of permissions, defined per organization. Roles are how you translate job functions ("maintenance engineer", "quality viewer") into access. You assign roles to teams — either as team default roles (everyone in the team) or to individual users within a team.
Default Role with the View Resource Groups permission:
Roles your organization starts with
Every organization is set up with a practical starting set:
Default Role — attached to the Default team, so every member has it. It grants the standard product permissions but deliberately excludes the administrative ones: user management, role management, team management, and resource group access management.
Machine Admins — full permissions on the asset hierarchy and product features.
Users — day-to-day operations: read access to the asset hierarchy and configuration, full access to operational features like dashboards, thresholds, and incidents.
Read Only — view permissions only; the default pairing for teams synced from Microsoft Entra ID.
Account Management — the administrative permissions (user, role, and team management) for delegated administrators.
These are ordinary roles in your organization — you can adjust them or build your own from scratch.
Editing roles takes effect immediately
Roles stay live: when you add or remove permissions on a role, everyone holding that role gets the change immediately. Removing a role from a team or user immediately revokes the permissions that came from it (they keep anything still granted by other roles or teams).
Who can manage roles
Action | Who |
Browse the permission catalog | Any member |
View the organization's roles | Owners, admins, or holders of the role management permission |
Create, edit, delete roles | Owners, admins, or holders of the role management permission |
Assign roles to teams or users | Owners, admins, or holders of the team management permission |
Remember that owners and admins are not limited by roles — they always have full access.



