Platform DocumentationPlatform Documentation

Roles & Permissions

Overview of the role system in CORE — Admins, Moderators, and Members — and their respective permissions.

CORE uses a role-based access control system to manage what users can see and do within the platform. There are three built-in roles, each with different levels of access:

RolePlatform AccessDevice AccessUser AccessTemplate Editing
AdminAll functionsAll devices (all accounts)All usersFull access
ModeratorSupport functionsShared devices + own devicesAll usersNo access
MemberDevice functionsOwn devices onlyOwn profileNo access

Admin

Admins have full control over the entire platform. They can:

  • View and manage all devices across all accounts
  • View and manage all users across all accounts
  • Create, edit, and delete device templates
  • Configure platform settings and brand customization
  • Manage workflows, lookup tables, and automations
  • Reassign devices between users and accounts

Info

Admins should be trusted platform operators only. With full access comes full responsibility — accidental changes to device templates or platform settings can affect all connected devices.

Moderator

Moderators are designed for support staff who need visibility into customer devices but should not be able to make structural changes. They can:

  • View all devices that have been explicitly shared with them by Members
  • View all users across all accounts
  • Access the support workflow to troubleshoot device issues
  • Cannot edit or delete device templates
  • Cannot modify platform settings or brand customization

How Moderators See Devices

Moderators do not have automatic access to all devices. They can only see devices that Members have explicitly shared:

  1. The Member goes to their device settings
  2. Clicks Share on the device
  3. Toggles Share with Moderators

Once shared, the device becomes visible to all Moderators. This ensures Members retain control over which devices support staff can access.

Admin vs. Moderator

CapabilityAdminModerator
View all devices (own + shared)YesOnly shared devices
View all usersYesYes
Edit device templatesYesNo
Modify platform settingsYesNo
Manage workflowsYesNo
Support troubleshootingYesYes

Tip

The Moderator role gives platform operators the ability to hire support staff who can work directly with customers without risking accidental changes to device templates. Moderators are support-focused — they can see and diagnose issues, but cannot administratively alter the platform.

Member

Members are end users who interact with their own devices. They can:

  • View and manage their own devices only
  • Share devices with Moderators for support access
  • Configure device-specific settings and datastream mappings
  • View their own device dashboards
  • Cannot access other users' devices
  • Cannot edit device templates
  • Cannot view other users

Sharing Devices with Moderators

When a Member needs support, they can grant temporary access to Moderators:

  1. Navigate to the device settings
  2. Click the Share button
  3. Toggle Share with Moderators

Once enabled, all Moderators can see and access this device for troubleshooting. The Member can revoke access at any time by toggling the switch back off.

Support Workflow Example

Here's a typical support scenario:

  1. Customer calls — A Member (customer) reports an issue with their machine
  2. Moderator responds — Support staff (Moderator) receives the request
  3. Device sharing — The Moderator asks the Member to share the affected device by toggling "Share with Moderators" in the device settings
  4. Troubleshooting — Once shared, the Moderator can see the device, review its datastreams, and help diagnose the issue
  5. Resolution — The Moderator guides the Member through the fix or escalates to an Admin if template changes are needed
  6. Access revoked — After support is complete, the Member can revoke Moderator access by toggling the share switch off

Note

Admins are not affected by sharing settings — they always have full access to all devices and users, regardless of sharing configuration.

On this page