Member Roles
Every member has one baseline organisation membership level. Assign the lowest level that lets someone do their work, then use additional IAM roles and groups for narrower product-specific responsibilities.
Role Summary
| Role | Use for |
|---|---|
| Owner | Trusted people responsible for organisation settings, access administration, and assigning or removing Owner access. |
| Admin | People who manage members, invitations, IAM configuration, and day-to-day organisation administration. |
| Member | People who need baseline read access to organisation resources but should not manage organisation-wide settings or access. |
Change a Membership Level
- Open Access > Members.
- Select Manage access beside the member.
- In Membership level, choose the new level.
- Select Save membership level.
Admins and owners can change eligible membership levels. Only owners can assign the Owner level or remove Owner access from another member.
Owner Access
Keep at least one active owner in every organisation. Owner access should be limited to trusted people who are responsible for organisation administration.
Before assigning Owner access, confirm the person should be able to manage high-impact organisation settings and owner-level access.
Groups and Role Assignments
Membership levels are the simplest way to control baseline organisation administration. They are separate from additional IAM roles. A member can have one membership level and any number of compatible direct or group-inherited roles.
Use Access > Groups to create reusable groups. Use Access > Roles to review available organisation-scoped IAM roles.
Infuse provides shared role templates for common IoT responsibilities:
| Role | Intended access |
|---|---|
| IoT Viewer | View IoT applications, boards, devices, networks, and telemetry. |
| Device Operator | IoT Viewer access plus device updates. |
| Command Operator | IoT Viewer access plus command execution. |
| IoT Admin | Organisation-level IoT administration through granular IoT permissions. |
Shared templates are read-only. Clone one from Access > Roles when your organisation needs a customised version.
To verify the combined result, open Access > Members, select Manage access or View access, and review Effective permissions.
For more detail, see Users, Groups, and Roles.