Most access problems are not broken permissions. They are a role granted at a different level than the one someone is trying to use, or the wrong project open. Work through these in order, because each step rules out a more common cause than the one after it.
1. Confirm the account
Check which account is signed in. People with more than one address, or who have been invited under a work address different from the one they normally use, can end up signed in as an account that was never granted anything.
2. Confirm the project
Check the project selector. Nothing crosses between projects, so a device, dashboard, or alert that has apparently vanished is very often present in a project other than the one currently open.
This costs seconds to rule out and explains a large share of reports.
3. Confirm project membership
Being a member of a team is not the same as being a member of a project. Confirm the person has been added to the specific project, not only to the team or organization above it.
4. Confirm the level the role was granted at
This is the step that resolves the reports that survive the first three.
If someone can see something but not change it, they most likely hold a role on the parent rather than on the thing itself. Editor on a project does not carry into the dashboards and alerts inside it — those are granted separately. Check the role on the specific dashboard or alert, not just on the project.
| Symptom | Usually means |
|---|---|
| Cannot see the project at all | Not a member of the project |
| Can open a dashboard, cannot edit it | Viewer on that dashboard, whatever the project role says |
| Can edit some dashboards, not others | Editor on some, viewer on others; they are separate grants |
| Cannot delete a dashboard they can edit | Editor, and someone else created it |
| Cannot add or remove users | Editor or viewer; user management requires admin |
| A whole sidebar area is missing | Role does not include that area, or wrong project |
5. Check who can make the change
Project membership, dashboard sharing, and alert sharing are managed by an admin at that level. Team membership and team roles are handled by BDI Cloud Support.
An admin cannot grant access above their own level. A project admin can add someone to their project but cannot add them to the team.
If it still looks wrong
Contact BDI Cloud Support with the affected account, the project name, the specific thing they were trying to do, what happened instead, and the role you believe they hold and at which level.
That last detail matters more than it appears. "They should be an editor" and "they are an editor on the project but not on the dashboard" describe the same grant and only one of them explains the behaviour.
Comments
0 comments
Article is closed for comments.