Exosphere Documentation

User Permissions & Roles

Permission matrix, role hierarchy, and access control in Exosphere


User Roles Overview

Role Hierarchy

RoleDescription
(Workspace) OwnerFull access
AdministratorAdministrative access
EditorDevice operations and content management
Viewer (with Loxone Config)Read-only access + Loxone Config file management
ViewerRead-only access

Role Descriptions

RolePermissions and Access
OwnerFull control - can do everything. All permissions including deletion. Cannot be removed by other users. Full system administration access.
AdministratorAdministrative access to workspace. User and device management. Content creation and management.
EditorDevice operations and content management. Cannot manage users or workspace settings.
Viewer (with Loxone Config)Read-only access to content. Can additionally upload and manage Loxone Config program files.
ViewerRead-only access to content. View dashboards, charts, and reports. Cannot modify any content or settings.

Role Selection

Give users the minimum permissions they need.


Permission Inheritance

Hierarchical Structure

Permission inheritance flows from higher to lower privilege levels:

  1. Owner inherits all permissions
  2. Administrator inherits Editor + Viewer permissions
  3. Editor inherits Viewer permissions
  4. Viewer (with Loxone Config) has Viewer permissions + program file management
  5. Viewer has base read permissions
RoleInherits FromAdditional Permissions
OwnerAll rolesBilling, deletion, system admin
AdministratorEditor, ViewerUser management, workspace settings
EditorViewerDevice operations, content management
Viewer (with Loxone Config)ViewerProgram file upload and management
ViewerNoneRead-only access

Detailed Permission Matrix

Workspace Management

PermissionOwnerAdministratorEditorViewer
Create Workspace
Delete Workspace
Modify Workspace Settings
View Workspace Settings

User Management

PermissionOwnerAdministratorEditorViewer
Invite Users
Remove Users
Change User Roles
View User List

Device Management

PermissionOwnerAdministratorEditorViewer
Add Devices
Remove Devices
Edit Device Settings
View Device Details
Device Operations
Bulk Operations
Device Backup
Device Update
Device Reboot

Content Management

PermissionOwnerAdministratorEditorViewer
Create Dashboards
Edit Dashboards
Delete Dashboards
Share Dashboards
View Dashboards
Create Charts
Edit Charts
Delete Charts
View Charts

Data Management

PermissionOwnerAdministratorEditorViewer
Create Value History
Edit Value History
Delete Value History
Schedule Reports
View Value History
Export Data
Import Data
Manage Databases

System Administration

PermissionOwnerAdministratorEditorViewer
System Settings
License Management
Backup Management
Update Management

Notifications

PermissionOwnerAdministratorEditorViewer
Manage Notifications
Configure Alerts
View Notifications
Email Notifications
SMS Notifications

Permission Audits

Check user permissions regularly.

Hierarchical Permissions in ENTERPRISE Workspaces

Workspaces with ENTERPRISE licenses feature structure-aware permissions that align with the workspace hierarchy. Key points to understand:

  • Hierarchical Restrictions: When a role is assigned to a structure element, child elements can only inherit equal or more restrictive permissions (never less restrictive).
  • Example: If a floor is assigned Editor permissions, rooms within that floor cannot have Administrator or Owner roles; they can only have Editor, Viewer (with Loxone Config), or Viewer.
  • Consistency and Integrity: This rule ensures a consistent permission hierarchy across the workspace. It also applies when revoking permissions, maintaining strict access control throughout the structure.

For further information on workspace hierarchy, refer to Structure Panel & Sidebar.

Hierarchical Permissions in Enterprise Workspaces

Troubleshooting

See Permission Issues for detailed troubleshooting guide.