Roles & Permissions
Overview of the role system in CORE — Admins, Moderators, and Members — and their respective permissions.
CORE uses a role-based access control system to manage what users can see and do within the platform. There are three built-in roles, each with different levels of access:
| Role | Platform Access | Device Access | User Access | Template Editing |
|---|---|---|---|---|
| Admin | All functions | All devices (all accounts) | All users | Full access |
| Moderator | Support functions | Shared devices + own devices | All users | No access |
| Member | Device functions | Own devices only | Own profile | No access |
Admin
Admins have full control over the entire platform. They can:
- View and manage all devices across all accounts
- View and manage all users across all accounts
- Create, edit, and delete device templates
- Configure platform settings and brand customization
- Manage workflows, lookup tables, and automations
- Reassign devices between users and accounts
Info
Admins should be trusted platform operators only. With full access comes full responsibility — accidental changes to device templates or platform settings can affect all connected devices.
Moderator
Moderators are designed for support staff who need visibility into customer devices but should not be able to make structural changes. They can:
- View all devices that have been explicitly shared with them by Members
- View all users across all accounts
- Access the support workflow to troubleshoot device issues
- Cannot edit or delete device templates
- Cannot modify platform settings or brand customization
How Moderators See Devices
Moderators do not have automatic access to all devices. They can only see devices that Members have explicitly shared:
- The Member goes to their device settings
- Clicks Share on the device
- Toggles Share with Moderators
Once shared, the device becomes visible to all Moderators. This ensures Members retain control over which devices support staff can access.
Admin vs. Moderator
| Capability | Admin | Moderator |
|---|---|---|
| View all devices (own + shared) | Yes | Only shared devices |
| View all users | Yes | Yes |
| Edit device templates | Yes | No |
| Modify platform settings | Yes | No |
| Manage workflows | Yes | No |
| Support troubleshooting | Yes | Yes |
Tip
The Moderator role gives platform operators the ability to hire support staff who can work directly with customers without risking accidental changes to device templates. Moderators are support-focused — they can see and diagnose issues, but cannot administratively alter the platform.
Member
Members are end users who interact with their own devices. They can:
- View and manage their own devices only
- Share devices with Moderators for support access
- Configure device-specific settings and datastream mappings
- View their own device dashboards
- Cannot access other users' devices
- Cannot edit device templates
- Cannot view other users
Sharing Devices with Moderators
When a Member needs support, they can grant temporary access to Moderators:
- Navigate to the device settings
- Click the Share button
- Toggle Share with Moderators
Once enabled, all Moderators can see and access this device for troubleshooting. The Member can revoke access at any time by toggling the switch back off.
Support Workflow Example
Here's a typical support scenario:
- Customer calls — A Member (customer) reports an issue with their machine
- Moderator responds — Support staff (Moderator) receives the request
- Device sharing — The Moderator asks the Member to share the affected device by toggling "Share with Moderators" in the device settings
- Troubleshooting — Once shared, the Moderator can see the device, review its datastreams, and help diagnose the issue
- Resolution — The Moderator guides the Member through the fix or escalates to an Admin if template changes are needed
- Access revoked — After support is complete, the Member can revoke Moderator access by toggling the share switch off
Note
Admins are not affected by sharing settings — they always have full access to all devices and users, regardless of sharing configuration.