Skip to main content

Roles and permissions

The emnify Portal is a powerful application to control the connectivity of devices of a production system.

Users across your Workspace may use the Portal, from operations and finance to development and product. That's why emnify offers four levels of access (referred to as Roles) to use and manage Portal features:

  • SuperAdmin (provided for organizations with multiple Workspaces)
  • Administrator (has access to all services and user management)
  • User (has access to all services)
  • Observer (has access to limited services)

To view and edit these roles, go to Workspace settings > Users.

The following tables describe the permissions for different roles.

Device management

ActionSuperAdminAdministratorUserObserver
Retrieve a device by IDyesyesyesyes
Update or delete a device by IDyesyesyesno
Retrieve the blocked networks for a deviceyesyesyesyes
Add or remove networks from the device blocklist by IDyesyesyesno
List all devicesyesyesyesyes
Create a new deviceyesyesyesno
Retrieve connectivity information for a deviceyesyesyesyes
Reset device connectivityyesyesyesno
Create devices in factory test mode (FTM) from the SIM inventoryyesyesyesno

SIM management

ActionSuperAdminAdministratorUserObserver
List available SIMsyesyesyesyes
List available SIM statusesyesyesyesyes
Retrieve SIMs by IDyesyesyesyes
Update or delete SIMs by IDyesyesyesno
Order SIMs from the SIM Shopyesyesyesno

Service policy

ActionSuperAdminAdministratorUserObserver
Retrieve a list of available countriesyesyesyesyes
Retrieve a list of available currenciesyesyesyesyes
Retrieve single currency details by IDyesyesyesyes
Retrieve a list of available servicesyesyesyesyes
List available traffic limits for a service by IDyesyesyesyes
Retrieve service policiesyesyesyesyes
Create service policiesyesyesyesno
Retrieve service policies by IDyesyesyesyes
Update or delete service policies by IDyesyesyesno
Add or delete services from service policiesyesyesyesno
Add or delete traffic limit from a serviceyesyesyesno
Retrieve the SMS interface typesyesyesyesno
Set or change a custom DNSyesyesyesno
Set or change data and SMS quotasyesyesyesno

Coverage policy

ActionSuperAdminAdministratorUserObserver
List of available coverage area statusesyesyesyesyes
List of available data plan statusesyesyesyesyes
Retrieve data plan details by IDyesyesyesyes
Retrieve data plansyesyesyesyes
Retrieve list of data plan statusesyesyesyesyes
Create coverage policiesyesyesyesno
List coverage policiesyesyesyesyes
Retrieve coverage area of a coverage policyyesyesyesyes
Retrieve country details by IDyesyesyesyes
List networksyesyesyesyes
Retrieve my currently active data planyesyesyesyes
Block networksyesyesyesno
Block radio access technologies (RATs)yesyesyesno

IP address space management

ActionSuperAdminAdministratorUserObserver
View allocated IP address spacesyesyesyesyes
Add IP address spacesyesyesnono
Remove IP address spacesyesyesnono

User management

ActionAll WorkspacesPer Workspace
SuperAdminAdministratorUserObserver
Create or list Workspace usersyesyesnono
Update or delete Workspace usersyesyesnono
Reassign or delete a SuperAdminnononono
Retrieve your user roleyesyesyesyes
Modify your user rolenononono
Add or delete per Workspace roles from a useryesyesnono
Update your passwordyesyesyesyes
Delete or list trusted devices for a useryesyesnono
Create or retrieve an application tokenyesyesnono
Edit an application tokenyesyesnono
Create a support token to assume user permissions by IDnononono
View reportsyesyesyesyes
info

A user can have different roles in different Workspaces, even if they're linked. SuperAdmin is the only role that is consistent across linked Workspaces by default. However, a user can be a SuperAdmin in one main organization but hold another role (for example, Observer) in an unrelated Workspace with a different main organization.

For more information, see Multiple Workspaces.

Workspace management

ActionSuperAdminAdministratorUserObserver
Automatically access Workspaces linked to your main organization by emnifyyesnonono
Send a request to create a new Workspaceyesyesnono
Send a request to link existing Workspacesyesyesnono
Switch between Workspaces you have access toyesyesyesyes
Transfer SIMs between Workspacesyesyesnono
View centralized reports with data from multiple Workspacesyesyesyesyes

Alerts

ActionSuperAdminAdministratorUserObserver
Retrieve organization or device alertsyesyesyesyes
Retrieve user events by IDyesyesnono
Retrieve IMSI and SIM eventsyesyesyesyes

Data streams

ActionSuperAdminAdministratorUserObserver
Add new data streamsyesyesyesno
Delete existing data streamsyesyesyesno
Update an existing data streamyesyesyesno
Retry an expired data streamyesyesyesno
Turn a data stream on or offyesyesyesno

Secure connection

info

The following actions are available in the Portal for AWS Transit Gateway and IPsec. OpenVPN isn't shown in the Secure Connection list. For more information, see OpenVPN.

ActionSuperAdminAdministratorUserObserver
Create secure connectionsyesyesyesno
Delete existing secure connectionsyesyesnono
Retry an expired secure connectionyesyesyesno

MFA keys

ActionSuperAdminAdministratorUserObserver
Generate user shared secret key for MFAyesyesyesyes
Activate user shared secret key for MFAyesyesyesyes
List available MFA key statusesyesyesyesyes
Delete shared secret key for MFA of a user by IDyesyesnono
List your trusted devicesyesyesyesyes
Delete a trusted device from your list by IDyesyesyesyes
List available MFA key typesyesyesyesyes
Delete my shared secret for MFAyesyesyesyes