Skip to main content

Access Control

IGNOS uses Azure AD to authenticate users. This means that all users and their access on ignos.io is handled by the customers active directory. There is no need to create new users in IGNOS, nor do we handle any passwords.

Role descriptions

Measurement Forms

RoleNameDescription
MeasurementForms.OperatorMeasurement Forms OperatorOperators have the ability to read form instances and log measurements.
MeasurementForms.AdminMeasurement Forms AdminGives access to everything in the measurement forms app.
MeasurementForms.InstanceAdminMeasurement Forms Instance AdminInstance admins have the ability to override the instance element list (disable balloons).
Supplier.AdminSupplier AdminLets the user administrate suppliers.
QC.AdminQC AdminThis is a combination of MeasurementForms.Admin and MeasuringTools.Admin.

Measuring Tools

All users are allowed to read measuring tools data as long as the app is enabled.

RoleNameDescription
MeasuringTools.AdminMeasuring Tools AdminManage measuring tools, calibrations, tool types, whitelists, import etc.
QC.AdminQC AdminThis is a combination of MeasurementForms.Admin and MeasuringTools.Admin.

Utilization

RoleNameDescription
Apps.UtilizationDetailsUtilization DetailsRequired for users to be able to see utilization details and configure alert rules.

Alarms

RoleNameDescription
Alarms.ReadAlarms readerReaders have the ability to browse machine alarms.

Keep

RoleNameDescription
Keep.OperatorKeep OperatorOperators can do everything except managing machines and communication settings.
Keep.AdminKeep AdminAdmins can manage machines and communication settings.

Engage

RoleNameDescription
Mes.OperatorMES OperatorManufacturing execution system access for operators.
Mes.ReaderMES ReaderManufacturing execution system access for readers only.
Mes.CrossCompanyMES Cross CompanyUsers with this role are allowed to switch between companies in Engage.

Workspace

RoleNameDescription
Workspace.AdminWorkspace AdminAllows customer wide workspace administration.

Sustainability

RoleNameDescription
Iot.AdminIOT AdminConfigure LogBoxes (power consumption tracking).

MRB

RoleNameDescription
Mrb.TraceMrb TraceUsers with this role are allowed to trace work orders.
Mrb.DocumentControllerMrb Document ControllerDocument controllers can maintain MRB templates and create MRB's
Mrb.DataManagerMrb Data ManagerUsers with this role can maintain document types

Other

RoleNameDescription
ErpErp data accessEnables the user to write ERP data.
IntegrationIntegrationIntended for applications and integrations.
AdminAdminAdmin users implicitly has all of the roles above (full access).
Operations.MonitorOperations MonitorUsers that need to see service/operations data for machines. Gives access to the health dashboard.
Machines.Groups.WriteManage Machine GroupsWriters have the ability to create, update and delete machine groups.
ExternalServiceCredentials.ReadExternal service credentials readerGives applications acces to read credentials for external services.

Role assignments

The IGNOS enterprise application defines a set of roles which can be assigned to users or groups within your organization, depending on what capabilities you want your users to have.

  1. Sign in to the Azure Portal as an admin.
  2. Search for and select Azure Active Directory.
  3. Under Manage, select Enterprise applications and click on Ignos.
  4. Under Manage, select Users and groups > Add user/group. users and groups
  5. Select the user(s) or group(s) you want to assign role(s) to select users or groups
  6. Click on the role(s) you want to be assigned to the selected user(s) or group(s) select roles
  7. Click Assign

The new roles should be effective within an hour or after the next login.