Documentation

Roles and permissions

The three roles, the eight permissions, and why an administrator of one measurement server cannot create a second one.

There are three roles and eight permissions. The distinction that explains everything: some permissions are answered on a measurement server, others on the account.

The three roles

Owner belongs to the account, and therefore to whoever pays. This role is not handed out.

Administrator does everything there is to do with a measurement server.

Reader looks on without changing anything — useful for someone who only wants to see the figures.

A role on the account and a role on a single measurement server count on the same scale, and the stronger of the two wins.

What each role may do

On a measurement server:

Permission Reader Administrator Owner
View traffic yes yes yes
View usage yes yes yes
Manage the measurement server no yes yes
Manage its members no yes yes

On the account:

Permission Reader Administrator Owner
Create or delete a measurement server no yes yes
Manage account members no yes yes
Plan, price and invoices no no yes
Delete the account no no yes

Why that split exists

Someone invited to a single measurement server has no role on the account. That means they cannot create a measurement server either — and that is not an arbitrary restriction.

Creating a measurement server costs money and hangs under a subscription. Someone with access to one server has no account to hang it under. If they could, an agency would be able to run up costs on its client’s account without the client seeing it.

It is the same arrangement that means you front nothing as an agency. See Working for clients.

A role that is not recognised

If the database holds a role this code does not know, it ranks below every real role — not above. A value that is not understood can therefore only ever grant less, never more.