Exosphere Documentation

User Permissions & Roles

Permission matrix, role hierarchy, and access control in Exosphere


User Roles Overview

Role Hierarchy

RoleDescription
(Workspace) OwnerFull access
AdministratorAdministrative access
EditorDevice operations and content management
Viewer (with Loxone Config)Read-only access + Loxone Config file management
ViewerRead-only access

Role Descriptions

RolePermissions and Access
OwnerFull control - can do everything. All permissions including deletion. Cannot be removed by other users. Full system administration access.
AdministratorAdministrative access to workspace. User and device management. Content creation and management.
EditorDevice operations and content management. Cannot manage users or workspace settings.
Viewer (with Loxone Config)Read-only access to content. Can additionally upload and manage Loxone Config program files.
ViewerRead-only access to content. View dashboards, charts, and reports. Cannot modify any content or settings.

Role Selection

Give users the minimum permissions they need.


Permission Inheritance

Hierarchical Structure

Permission inheritance flows from higher to lower privilege levels:

  1. Owner inherits all permissions
  2. Administrator inherits Editor + Viewer permissions
  3. Editor inherits Viewer permissions
  4. Viewer (with Loxone Config) has Viewer permissions + program file management
  5. Viewer has base read permissions
RoleInherits FromAdditional Permissions
OwnerAll rolesBilling, deletion, system admin
AdministratorEditor, ViewerUser management, workspace settings
EditorViewerDevice operations, content management
Viewer (with Loxone Config)ViewerProgram file upload and management
ViewerNoneRead-only access

Detailed Permission Matrix

Workspace Management

PermissionOwnerAdministratorEditorViewer
Create Workspace✅✅✅✅
Delete Workspace✅❌❌❌
Modify Workspace Settings✅✅❌❌
View Workspace Settings✅✅✅❌

User Management

PermissionOwnerAdministratorEditorViewer
Invite Users✅✅❌❌
Remove Users✅✅❌❌
Change User Roles✅✅❌❌
View User List✅✅❌❌

Device Management

PermissionOwnerAdministratorEditorViewer
Add Devices✅✅✅❌
Remove Devices✅✅✅❌
Edit Device Settings✅✅✅❌
View Device Details✅✅✅✅
Device Operations✅✅✅❌
Bulk Operations✅✅✅❌
Device Backup✅✅✅❌
Device Update✅✅✅❌
Device Reboot✅✅✅❌

Content Management

PermissionOwnerAdministratorEditorViewer
Create Dashboards✅✅✅❌
Edit Dashboards✅✅✅❌
Delete Dashboards✅✅✅❌
Share Dashboards✅✅✅❌
View Dashboards✅✅✅✅
Create Charts✅✅✅❌
Edit Charts✅✅✅❌
Delete Charts✅✅✅❌
View Charts✅✅✅✅

Data Management

PermissionOwnerAdministratorEditorViewer
Create Value History✅✅✅❌
Edit Value History✅✅✅❌
Delete Value History✅✅✅❌
Schedule Reports✅✅✅❌
View Value History✅✅✅✅
Export Data✅✅✅❌
Import Data✅✅✅❌
Manage Databases✅✅✅❌

System Administration

PermissionOwnerAdministratorEditorViewer
System Settings✅✅❌❌
License Management✅✅❌❌
Backup Management✅✅✅❌
Update Management✅✅✅❌

Notifications

PermissionOwnerAdministratorEditorViewer
Manage Notifications✅✅✅❌
Configure Alerts✅✅✅❌
View Notifications✅✅✅✅
Email Notifications✅✅✅✅
SMS Notifications✅✅✅❌

Permission Audits

Check user permissions regularly.

Hierarchical Permissions in ENTERPRISE Workspaces

Workspaces with ENTERPRISE licenses feature structure-aware permissions that align with the workspace hierarchy. Key points to understand:

  • Hierarchical Restrictions: When a role is assigned to a structure element, child elements can only inherit equal or more restrictive permissions (never less restrictive).
  • Example: If a floor is assigned Editor permissions, rooms within that floor cannot have Administrator or Owner roles; they can only have Editor, Viewer (with Loxone Config), or Viewer.
  • Consistency and Integrity: This rule ensures a consistent permission hierarchy across the workspace. It also applies when revoking permissions, maintaining strict access control throughout the structure.

For further information on workspace hierarchy, refer to Structure Panel & Sidebar.

Hierarchical Permissions in Enterprise Workspaces

Troubleshooting

See Permission Issues for detailed troubleshooting guide.