Role-Based Access Control (RBAC) Implementation Guide

Last updated – June 8, 2026

This guide, as of NetSpeek platform version 1.5, describes the permissions of the platform-provided default roles in the table at the bottom of the page. There are 6 roles, defined as Owner, Administrator, Manager, Operator, Analyst, and Limited Access*.

*The Limited Access role was originally named Viewer and is in the process of being renamed in the NetSpeek platform interface. The documentation below for Limited Access addresses either role name you may see in your tenant.

Groups Configuration (Optional)

The intention of the Groups feature in Tenant Settings is to make RBAC administration more scalable by enabling managing role assignments for multiple users in bulk.

To configure Groups, navigate to Tenant Management –> Groups:

Groups are initially given a name and description – roles and members are assigned afterward.


Member assignment of NetSpeek Users to a group

Role assignment – defining what permissions the group members will have

An example of 2 groups – members of the first group have Administrator permissions, and the second have Analyst permissons

Permissions By Role

The table below describes the permissions allotted to each role – roles can be assigned to Groups as described above, or to individual users.

PermissionDescriptionOwnerAdministratorManagerOperatorAnalystLimited Access
Identity and Access Management
Users:ReadSelfView own profile and settings
Users:WriteSelfUpdate own profile and settings
Users:ReadView other users
Users:WriteCreate / Update other users
Roles:ReadView roles and assigned permissions
Roles:WriteUpdate role permissions and delete roles
Roles:AssignAssign or revoke users from roles
Permissions:ReadView permissions
Tenants and Context
Customers:ReadSelfView current tenant details
Customers:WriteSelfUpdate current tenant details
Customers:ReadView child tenants
Customers:WriteManage child tenants
Context:SwitchSwitch tenant context
Location Management
Locations:ReadView location entities
Locations:WriteManage location entities
Endpoints
Endpoints:ReadView endpoints
Endpoints:WriteManage endpoints
Endpoints:ActionDispatch actions to devices
Integrations
Integrations:ReadView integrations
Integrations:WriteManage integrations
Lena and Reports
Lena:ChatChat with Lena
Reports:ReadView reports (Room Check results)
Room Checks
RoomChecks:TargetState:ReadView Room Check target states
RoomChecks:TargetState:WriteManage Room Check target states
RoomChecks:Schedule:ReadView Room Check schedules
RoomChecks:Schedule:WriteManage Room Check schedules

Notes:

As of platform version 1.5, there are no exposed differences between Owner and Administrator. Future plans for the RBAC featureset will provide separation between these roles – discuss these plans with your NetSpeek representative if of interest.