> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.emnify.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.emnify.com/_mcp/server.

> Review the emnify account permissions for various roles

The [emnify Portal](https://portal.emnify.com/) is a powerful application to control the connectivity of devices of a production system.

Users across your Workspace may use the Portal, from operations and finance to development and product.
That's why emnify offers four levels of access (referred to as **Roles**) to use and manage Portal features:

* **SuperAdmin** (provided for organizations with [multiple Workspaces](/portal/workspaces))
* **Administrator** (has access to all services and user management)
* **User** (has access to all services)
* **Observer** (has access to limited services)

Administrators can view and edit these roles in **Workspace settings** > [**Users**](https://portal.emnify.com/organisation-settings/users).

The following tables describe the permissions for different roles.

## Device management

| Action                                                           | SuperAdmin | Administrator | User | Observer |
| ---------------------------------------------------------------- | :--------: | :-----------: | :--: | :------: |
| Retrieve a device by ID                                          |     Yes    |      Yes      |  Yes |    Yes   |
| Update or delete a device by ID                                  |     Yes    |      Yes      |  Yes |    No    |
| Retrieve the blocked networks for a device                       |     Yes    |      Yes      |  Yes |    Yes   |
| Add or remove networks from the device blocklist by ID           |     Yes    |      Yes      |  Yes |    No    |
| List all devices                                                 |     Yes    |      Yes      |  Yes |    Yes   |
| Create a new device                                              |     Yes    |      Yes      |  Yes |    No    |
| Retrieve connectivity information for a device                   |     Yes    |      Yes      |  Yes |    Yes   |
| Reset device connectivity                                        |     Yes    |      Yes      |  Yes |    No    |
| Create devices in factory test mode (FTM) from the SIM inventory |     Yes    |      Yes      |  Yes |    No    |

## Tag management

| Action                                 | SuperAdmin | Administrator | User | Observer |
| -------------------------------------- | :--------: | :-----------: | :--: | :------: |
| View tags                              |     Yes    |      Yes      |  Yes |    Yes   |
| Add tags to devices                    |     Yes    |      Yes      |  Yes |    No    |
| Edit tag details                       |     Yes    |      Yes      |  Yes |    No    |
| Delete unused tags                     |     Yes    |      Yes      |  Yes |    No    |
| Delete tags in use (with confirmation) |     Yes    |      Yes      |  Yes |    No    |
| Bulk add tags                          |     Yes    |      Yes      |  Yes |    No    |
| Bulk remove tags                       |     Yes    |      Yes      |  Yes |    No    |
| Filter by tags                         |     Yes    |      Yes      |  Yes |    Yes   |

## SIM management

| Action                       | SuperAdmin | Administrator | User | Observer |
| ---------------------------- | :--------: | :-----------: | :--: | :------: |
| List available SIMs          |     Yes    |      Yes      |  Yes |    Yes   |
| List available SIM statuses  |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve SIMs by ID          |     Yes    |      Yes      |  Yes |    Yes   |
| Update or delete SIMs by ID  |     Yes    |      Yes      |  Yes |    No    |
| Order SIMs from the SIM Shop |     Yes    |      Yes      |  Yes |    No    |

## Service policy

| Action                                            | SuperAdmin | Administrator | User | Observer |
| ------------------------------------------------- | :--------: | :-----------: | :--: | :------: |
| Retrieve a list of available countries            |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve a list of available currencies           |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve single currency details by ID            |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve a list of available services             |     Yes    |      Yes      |  Yes |    Yes   |
| List available traffic limits for a service by ID |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve service policies                         |     Yes    |      Yes      |  Yes |    Yes   |
| Create service policies                           |     Yes    |      Yes      |  Yes |    No    |
| Retrieve service policies by ID                   |     Yes    |      Yes      |  Yes |    Yes   |
| Update or delete service policies by ID           |     Yes    |      Yes      |  Yes |    No    |
| Add or delete services from service policies      |     Yes    |      Yes      |  Yes |    No    |
| Add or delete traffic limit from a service        |     Yes    |      Yes      |  Yes |    No    |
| Retrieve the SMS interface types                  |     Yes    |      Yes      |  Yes |    No    |
| Set or change a custom DNS                        |     Yes    |      Yes      |  Yes |    No    |
| Set or change data and SMS quotas                 |     Yes    |      Yes      |  Yes |    No    |

## Coverage policy

| Action                                      | SuperAdmin | Administrator | User | Observer |
| ------------------------------------------- | :--------: | :-----------: | :--: | :------: |
| List of available coverage area statuses    |     Yes    |      Yes      |  Yes |    Yes   |
| List of available data plan statuses        |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve data plan details by ID            |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve data plans                         |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve list of data plan statuses         |     Yes    |      Yes      |  Yes |    Yes   |
| Create coverage policies                    |     Yes    |      Yes      |  Yes |    No    |
| List coverage policies                      |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve coverage area of a coverage policy |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve country details by ID              |     Yes    |      Yes      |  Yes |    Yes   |
| List networks                               |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve my currently active data plan      |     Yes    |      Yes      |  Yes |    Yes   |
| Block networks                              |     Yes    |      Yes      |  Yes |    No    |
| Block radio access technologies (RATs)      |     Yes    |      Yes      |  Yes |    No    |

## IP address space management

| Action                           | SuperAdmin | Administrator | User | Observer |
| -------------------------------- | :--------: | :-----------: | :--: | :------: |
| View allocated IP address spaces |     Yes    |      Yes      |  Yes |    Yes   |
| Add IP address spaces            |     Yes    |      Yes      |  No  |    No    |
| Remove IP address spaces         |     Yes    |      Yes      |  No  |    No    |

## User management

<table sticky>
  <colgroup />

  <colgroup />

  <colgroup span="3" />

  <thead>
    <tr>
      Action

      All Workspaces

      Per Workspace
    </tr>

    <tr>
      <th scope="col">
        SuperAdmin
      </th>

      <th scope="col">
        Administrator
      </th>

      <th scope="col">
        User
      </th>

      <th scope="col">
        Observer
      </th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td scope="row">
        View the Users tab in Workspace settings (requires the 

        **Administrator**

         role in at least one Workspace)
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        Create or list Workspace users
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        Update or delete Workspace users
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        Reassign or delete a SuperAdmin
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        Retrieve your user role
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>
    </tr>

    <tr>
      <td scope="row">
        Modify your user role
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        Add or delete per Workspace roles from a user
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        Update your password
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>
    </tr>

    <tr>
      <td scope="row">
        Delete or list trusted devices for a user
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        Create or retrieve an application token
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        Edit an application token
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        Create a support token to assume user permissions by ID
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>

      <td>
        No
      </td>
    </tr>

    <tr>
      <td scope="row">
        View reports
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>

      <td>
        Yes
      </td>
    </tr>
  </tbody>
</table>

> **Note**
>
> A user can have different roles in different Workspaces, even if they're linked.
> **SuperAdmin** is the only role that is consistent across linked Workspaces by default.
> However, a user can be a SuperAdmin in one main organization but hold another role (for example, **Observer**) in an unrelated Workspace with a different main organization.
>
> User management covers every Workspace you administer, so the **Users** tab is available if you have the **Administrator** role in at least one Workspace.
> It's limited to those Workspaces, even when your role in the Workspace you're currently in is different.
>
> For more information, see [Multiple Workspaces](/portal/workspaces) and [Users](/portal/workspaces/users).

## Workspace management

| Action                                                                     | SuperAdmin | Administrator | User | Observer |
| -------------------------------------------------------------------------- | :--------: | :-----------: | :--: | :------: |
| Automatically access Workspaces linked to your main organization by emnify |     Yes    |       No      |  No  |    No    |
| Send a request to create a new Workspace                                   |     Yes    |      Yes      |  No  |    No    |
| Send a request to link existing Workspaces                                 |     Yes    |      Yes      |  No  |    No    |
| Switch between Workspaces you have access to                               |     Yes    |      Yes      |  Yes |    Yes   |
| Transfer SIMs between Workspaces                                           |     Yes    |      Yes      |  No  |    No    |
| View centralized reports with data from multiple Workspaces                |     Yes    |      Yes      |  Yes |    Yes   |

## Automations and events

| Action                                                  | SuperAdmin | Administrator | User | Observer |
| ------------------------------------------------------- | :--------: | :-----------: | :--: | :------: |
| Retrieve organization or device alerts                  |     Yes    |      Yes      |  Yes |    Yes   |
| Retrieve user events by ID                              |     Yes    |      Yes      |  No  |    No    |
| Retrieve IMSI and SIM events                            |     Yes    |      Yes      |  Yes |    Yes   |
| View the Rules list                                     |     Yes    |      Yes      |  Yes |    No    |
| Add a Rule                                              |     Yes    |      Yes      |  Yes |    No    |
| Edit a Rule                                             |     Yes    |      Yes      |  Yes |    No    |
| Duplicate a Rule                                        |     Yes    |      Yes      |  Yes |    No    |
| Pause a Rule                                            |     Yes    |      Yes      |  Yes |    No    |
| Delete a Rule                                           |     Yes    |      Yes      |  Yes |    No    |
| Remove users from email notification recipients list    |     Yes    |      Yes      |  Yes |    No    |
| View email notification recipients' verification status |     Yes    |      Yes      |  Yes |    No    |
| Resend verification email after token expired           |     Yes    |      Yes      |  Yes |    No    |

## Flow Logs Beta \[#flow-logs]

| Action                                    | SuperAdmin | Administrator | User | Observer |
| ----------------------------------------- | :--------: | :-----------: | :--: | :------: |
| Retrieve organization or device Flow Logs |     Yes    |      Yes      |  No  |    No    |
| Retrieve Flow Log details by ID           |     Yes    |      Yes      |  Yes |    No    |
| Export organization or device Flow Logs   |     Yes    |      Yes      |  Yes |    No    |

## Data streams

| Action                         | SuperAdmin | Administrator | User | Observer |
| ------------------------------ | :--------: | :-----------: | :--: | :------: |
| Add new data streams           |     Yes    |      Yes      |  Yes |    No    |
| Delete existing data streams   |     Yes    |      Yes      |  Yes |    No    |
| Update an existing data stream |     Yes    |      Yes      |  Yes |    No    |
| Retry an expired data stream   |     Yes    |      Yes      |  Yes |    No    |
| Turn a data stream on or off   |     Yes    |      Yes      |  Yes |    No    |

## Secure connection

> **Note**
>
> The following actions are available in the Portal for AWS Transit Gateway and IPsec.
> OpenVPN isn't shown in the [**Secure Connection**](https://portal.emnify.com/integrations#secure-connection) list.
> For more information, see [OpenVPN](/services/openvpn).

| Action                             | SuperAdmin | Administrator | User | Observer |
| ---------------------------------- | :--------: | :-----------: | :--: | :------: |
| Create secure connections          |     Yes    |      Yes      |  Yes |    No    |
| Delete existing secure connections |     Yes    |      Yes      |  No  |    No    |
| Retry an expired secure connection |     Yes    |      Yes      |  Yes |    No    |

## MFA keys

| Action                                           | SuperAdmin | Administrator | User | Observer |
| ------------------------------------------------ | :--------: | :-----------: | :--: | :------: |
| Generate user shared secret key for MFA          |     Yes    |      Yes      |  Yes |    Yes   |
| Activate user shared secret key for MFA          |     Yes    |      Yes      |  Yes |    Yes   |
| List available MFA key statuses                  |     Yes    |      Yes      |  Yes |    Yes   |
| Delete shared secret key for MFA of a user by ID |     Yes    |      Yes      |  No  |    No    |
| List your trusted devices                        |     Yes    |      Yes      |  Yes |    Yes   |
| Delete a trusted device from your list by ID     |     Yes    |      Yes      |  Yes |    Yes   |
| List available MFA key types                     |     Yes    |      Yes      |  Yes |    Yes   |
| Delete my shared secret for MFA                  |     Yes    |      Yes      |  Yes |    Yes   |

## Single sign-on

| Action                                                | SuperAdmin | Administrator | User | Observer |
| ----------------------------------------------------- | :--------: | :-----------: | :--: | :------: |
| View the **Single Sign-On** tab in Workspace settings |     Yes    |      Yes      |  No  |    No    |
| Set up SSO with specific providers                    |     Yes    |      Yes      |  No  |    No    |
| Verify and troubleshoot SSO integrations              |     Yes    |      Yes      |  No  |    No    |
| Delete SSO integrations                               |     Yes    |      Yes      |  No  |    No    |