Skip to main content

Users and Roles

Invite your team into ioX-Pulse, assign roles, and control who can do what across your workspace and its sub-accounts.

note

Where to find it: Sidebar -> Members (partner-wide) or any sub-account -> Members.

The role system at a glance

ioX-Pulse has five roles you can assign. Two apply at the partner level (across your whole workspace), three apply at the sub-account level (scoped to one customer or project).

RoleScopeTypical use
Partner AdministratorPartner-wideOwns the workspace. Manages branding, billing, sub-accounts, members, and platform settings.
Partner SupportPartner-wide, read-onlyInternal support staff who need to see everything but change nothing.
AdministratorOne sub-accountCustomer-side administrator. Manages devices, dashboards, workflows, and the account's own members.
OperatorOne sub-accountDay-to-day operator. Can use the platform, including sending downlinks to devices, but can't change configuration.
ViewerOne sub-accountRead-only. Sees the sections it's allowed, can't change anything or send downlinks.
note

The sub-account roles are named Administrator, Operator, and Viewer, with no "sub-account" prefix, so they read naturally inside a customer's own workspace. The scope column above is for your reference; a customer only ever sees their own account and the plain role name.

tip

You can give one person multiple memberships. A consultant might be an Administrator in two of your customer sub-accounts and a Viewer in a third. Each membership is a separate row with its own role.

What each role can do

Each role carries two kinds of setting:

  • Visibility controls which sections a role can see in the sidebar: Dashboards, Fleet, Workflows, Notifications, and Analytics. By default every role sees every section it's entitled to; you can hide sections per role to create, for example, a Dashboards-only login.
  • Permissions control what a role can do: manage devices, dashboards, members, send downlinks, and so on.

The defaults below match a fresh ioX-Pulse install. You can fine-tune both the visibility and the permissions per partner or per sub-account in Account Settings -> Security -> Role permissions (see Role permissions below).

PermissionPartner AdministratorPartner SupportAdministratorOperatorViewer
Manage workspace branding
Manage sub-accounts
Manage members (invite, remove)✓ (own account)
Manage devices (register, assign, edit)
Manage gateways
Manage sites and networks
Manage dashboards (create, edit)
Manage workflows and notifications
Manage analytics
Send device downlinks
View everything in scope

Reading the table:

  • A blank cell means "no, by default". You can promote a permission for a specific role in the Role permissions editor (e.g. let an Operator manage their own dashboards, or let a Viewer invite members).
  • Sub-account roles only act within their assigned sub-account. An Administrator in sub-account A cannot see or touch devices in sub-account B.
  • Permissions that depend on the subscription tier (analytics, sites, networks, downlinks) are shown but locked, marked Not in this tier, on an account whose tier doesn't include them, so a grant can't promise something the tier won't deliver.

Inviting a user

The invitation flow is the same whether you're adding a partner-wide member or a sub-account member; only the scope differs.

Partner-wide member

  1. Sidebar -> Members (top-level, not inside a sub-account).
  2. Click Invite Member.
  3. Fill in:
    • Email of the person you're inviting.
    • Role (Partner Administrator or Partner Support).
    • Default landing page (optional). Where this member lands after signing in. Leave it blank for the default, Fleet: Overview. They can change it themselves later. See Default landing page for the options.
  4. Click Send invitation.

Sub-account member

  1. Switch into the target sub-account from the sub-account selector at the top of the sidebar.
  2. Members in the left nav.
  3. Click Invite Member.
  4. Fill in:
    • Email.
    • Role (Administrator / Operator / Viewer). You only see the roles you're allowed to assign; you can't grant a role higher than your own.
    • Default landing page (optional), as above.
  5. Click Send invitation.

Permission required: the Manage members permission. Partner Administrators and Administrators have it by default. You can also grant it to an Operator or Viewer so they can invite teammates without being a full admin (see Role permissions). Whoever invites can only assign a role at or below their own.

Editing a member's profile later

Open the ... menu on a member's row in the Members list and choose Edit profile. The drawer lets you change, on the member's behalf:

  • Name, phone, and email: the contact fields on their account. Changing the email changes how they sign in and signs their other sessions out.
  • Default landing page: where they land after signing in. Leave it blank to reset them to the default (Fleet: Overview).
  • Notification toggles: the member's in-app, email, and SMS channel switches for this workspace, the same ones they see on their own profile. See Notifications in the end-user guide for what each toggle does. SMS only appears when the account's tier includes text messages.
  • Site access (Operators and Viewers, when your tier has multi-site): see Sites.

The member can still change their landing page and notification toggles themselves on their own profile.

What happens behind the scenes

  • If the email is new to your workspace, ioX-Pulse creates a user record and sends them an invitation email with an activation link.
  • If the email already has an account in your workspace (for example, you're adding an existing member to another sub-account), the new membership is created and accepted immediately and they get a courtesy "you've been added" email, with no second password to set.
  • Accounts are scoped to your workspace. If the same email address is used in a different workspace, that is a separate account with its own password; in your workspace it is treated as brand-new and gets its own activation link.
  • Invitation links expire after 7 days. If a user doesn't activate in time, re-send the invitation from the Members list.
  • When you invite or resend, the invitation link also appears on screen with a Copy button. You can share it directly (email, chat, text) if the automated message is slow to arrive or lands in spam.
caution

Email sending is optional. If email hasn't been configured for your workspace, invitation emails won't actually go out. New users won't get a link, but the membership is still created in the database. You can still onboard them with the on-screen invitation link above. If invites are arriving but landing in spam, see Email deliverability.

Activating an invitation (user-side)

The recipient receives an email with an "Activate your account" button. Clicking it takes them to your branded ioX-Pulse workspace where they:

  1. Choose a password (at least 12 characters, mixing letters and numbers).
  2. Optionally set up multi-factor authentication. If your workspace mandates MFA (see below), this step is required.
  3. Land on the dashboard they have access to.

See Getting Started for the user-side onboarding walkthrough.

Multi-factor authentication (MFA)

ioX-Pulse supports TOTP-based MFA using any standard authenticator app (Google Authenticator, Authy, 1Password, Microsoft Authenticator).

How users enable it

  1. The user clicks their avatar in the top-right -> Account security.
  2. Click Enable MFA.
  3. Scan the QR code with their authenticator app, enter the six-digit code to verify, and save.

After enabling, every sign-in requires both the password and a fresh six-digit code.

Mandating MFA for your workspace

As Partner Admin, you can require MFA for everyone in your workspace.

  1. Settings -> Security in the left nav.
  2. Toggle Require multi-factor authentication to On.
  3. Set a grace period if you want existing users some time to enroll before MFA is enforced.

When the grace period expires, users without MFA can sign in once, but they're immediately forced to enroll before they can do anything else.

caution

No recovery codes. ioX-Pulse doesn't currently generate backup codes. If a user loses their phone, they can't recover their account themselves. A Partner Admin must reset their access via the "Force password reset" action on the Members list, which clears their MFA so they can re-enroll on next sign-in. If a Partner Admin themselves loses access, contact ioX-Connect support.

Sub-account MFA mandate

Some sub-accounts have stricter security requirements than others. An Administrator can mandate MFA just for their own account independently of the partner setting.

  • Members -> Settings tab (inside the sub-account) -> Require MFA.
  • The stricter of the two policies wins. If either the partner or the sub-account requires MFA, the user must enroll.

Removing or suspending a member

Suspend (temporarily disable a member)

A suspended member can't sign in but keeps their membership intact. Use this when someone is on extended leave or you're investigating a security issue.

  1. Members -> find the member -> three-dot menu -> Suspend.
  2. They're signed out immediately and can't sign back in.
  3. Reverse with the same menu -> Reactivate.

Remove (permanently revoke access)

  1. Members -> find the member -> three-dot menu -> Remove.
  2. Their membership is soft-deleted. Their user record persists in case they belong to other sub-accounts in your workspace, but they lose access to the scope you removed them from.

Reset a member's password

Use this when a member is locked out (see below) or has forgotten their password.

  1. Members -> three-dot menu -> Send password reset.
  2. They receive an email with a reset link (1-hour expiry).
  3. They set a new password and can sign in again.

Force password reset (immediate kick-out)

A stronger version that also kills active sessions, useful if you suspect compromised credentials.

  1. Members -> three-dot menu -> Force password reset.
  2. Their password is cleared immediately. Any active sessions are invalidated. They receive a reset email and must complete it before signing in again.

Permission required: the Manage members permission for suspend, remove, and role changes (limited to members at or below your own role). Password resets stay admin-only: a Partner Administrator, or an Administrator for members of their own account.

caution

You can't demote or remove the workspace owner. The owner of a partner workspace can't be downgraded by other Partner Admins. This prevents accidental lockout. To transfer ownership, contact ioX-Connect support.

Account lockout

ioX-Pulse locks an account after three consecutive failed sign-in attempts. The lock is immediate and there's no time-based auto-unlock.

To unlock a locked member:

  • Send them a password reset (see above). Completing the reset clears the lockout.
  • Force a password reset if the user can't access the email tied to the account.

Lockout protects against brute-force attacks. If you find a user frequently getting locked out, double-check their password manager has the right entry and consider mandating MFA for that sub-account.

Managing multi-membership users

Some users (consultants, integrators, your own internal support staff) have access to multiple sub-accounts. They see a sub-account switcher at the top of the sidebar, with each accessible sub-account in a dropdown. Switching changes what they see across the whole app.

In the Members list:

  • Partner-wide view shows everyone with a partner-level membership.
  • Sub-account view (when scoped to a sub-account) shows only members of that sub-account.

A user with both a partner-level membership and a sub-account membership appears in both lists.

Role permissions: what each role sees and does

By default, roles follow the visibility and permissions in the table above. You can override both, per partner or per sub-account, in Account Settings -> Security -> Role permissions. Each role splits into Visibility (which sidebar sections it sees) and Permissions (what it can do), and any capability your tier doesn't include is shown locked and marked Not in this tier.

For the step-by-step editor walkthrough and recipes like a Dashboards-only login or a "front desk" login that can only invite teammates, see Controlling what each role can see and do in the end-user guide. Two things are specific to you as a partner:

  • Partner-level overrides (from your partner-wide scope) apply to every sub-account in your workspace.
  • Sub-account-level overrides (switch into the target sub-account first) apply to that one sub-account only. Use sparingly to avoid confusion across your team.
note

Overrides combine in this order: role default -> partner override -> sub-account override. The most specific override wins.

Frequently asked

A user disappeared from the members list.

Most likely they were removed (soft-deleted), or you're scoped into the wrong sub-account. Try switching to partner-wide scope from the top of the sidebar to confirm.

A user's invite expired before they activated.

Re-send the invitation from the Members list. The new email contains a fresh 7-day link. The user's pending account stays in place; nothing is lost.

Can I bulk-invite users?

Not today. Invitations are one-at-a-time. Bulk invite is on the roadmap for a future release.

How do I add a user to a second sub-account?

Switch into the second sub-account, go to Members, and invite them again with the same email. As long as that email already belongs to a member of your workspace, ioX-Pulse recognizes the existing user and creates a second membership for them, with no new activation email needed. Once they have access to more than one sub-account, they get a workspace switcher at the top of the sidebar to move between them.

Someone is a member of my workspace and another partner's workspace with the same email. Is that one account?

No. Accounts are scoped to a workspace, so that is two separate accounts that happen to share an email address, each with its own password. Anything you do in your workspace (role, suspension, password reset) only affects the account in your workspace.

Can a read-only user also manage members?

For a sub-account, yes. Grant the Manage members permission to a Viewer or Operator in Account Settings -> Security -> Role permissions to create a "read-only plus invite" login. They can invite, change, suspend, and remove only members at or below their own role, so a Viewer with the permission manages only other Viewers. Partner Support (partner-wide) stays strictly read-only and can't be granted member management at the partner level today.

A user can't sign in but isn't locked out.

Common causes: (1) MFA was mandated and they haven't enrolled yet, (2) their membership was suspended, (3) their email isn't actually receiving the invitation. Check Members -> three-dot menu -> View activity to see their last sign-in attempt.