Skip to main content

Choosing a role

Choosing a role​

The personRole
Works the barrier at a gateTpa gatekeeper — and set their Gate on the user form
Fits OBUs to vehicles in the fieldTpa installer
Reconciles UWA records and clears exceptionsTpa reconciler
Runs the park operation and reads reportsTpa management
Issues, dispatches and chases badges and OBUsTpa management for the day-to-day; Tpa admin for triage, repairs and thresholds
Manages TotalEnergies' own staff and their work cardsTpa admin (personnel:* plus card:*)
Works for the wildlife authorityTpa uwa
Needs to look and change nothingTpa viewer
Works for an external contractorTpa contractor
Administers TotalEnergies' park accessTpa admin
Administers accounts, roles and the stock thresholdsSystem admin
Posts captures from a lane deviceTpa line controller
Is a service, not a personone of the five machine roles

The three custom roles need a decision before use. Contractor can create and delete organisations and approve its own submissions; Organisation Contractor holds no organisation:* permission despite its name; and Park Auditor can create, update and delete gates and devices, which is not what an auditor should be able to do. Prefer a built-in role unless one of these has been reviewed and deliberately chosen.

Give the narrowest role that lets the person do their job. It is far easier to add a role later than to explain why somebody could see something they should not have.

What the sidebar does and does not tell you​

  • The name under the sidebar avatar is the person's TPAS role, read from the authorisation service. If it is not the role you expect, check their account under Administration → Users & Roles → Users.
  • An account holding several roles shows only one name there, and not necessarily the important one. The sidebar chip is not a summary of what somebody can do; the Users page is.
  • A visible menu entry proves they hold that entry's permission — not that every row behind it belongs to their own organisation. Row-level scoping is the backend's job, and it is applied per endpoint.
  • A missing entry is not always a missing permission. The viewer holds visitor:read and still has no Visitors entry, because that entry lives in the Management group and the viewer is shown Registry (Two sidebars, one set of pages).

To find out what somebody can actually do, look them up in Administration → Users & Roles → Users and read their assigned roles, then read those roles in The role catalogue.