Choosing a role
Choosing a role
| The person | Role |
|---|---|
| Works the barrier at a gate | Tpa gatekeeper — and set their Gate on the user form |
| Fits OBUs to vehicles in the field | Tpa installer |
| Reconciles UWA records and clears exceptions | Tpa reconciler |
| Runs the park operation and reads reports | Tpa management |
| Issues, dispatches and chases badges and OBUs | Tpa management for the day-to-day; Tpa admin for triage, repairs and thresholds |
| Manages TotalEnergies' own staff and their work cards | Tpa admin (personnel:* plus card:*) |
| Works for the wildlife authority | Tpa uwa |
| Needs to look and change nothing | Tpa viewer |
| Works for an external contractor | Tpa contractor |
| Administers TotalEnergies' park access | Tpa admin |
| Administers accounts, roles and the stock thresholds | System admin |
| Posts captures from a lane device | Tpa line controller |
| Is a service, not a person | one of the five machine roles |
The three custom roles need a decision before use. Contractor can create
and delete organisations and approve its own submissions; Organisation
Contractor holds no organisation:* permission despite its name; and Park
Auditor can create, update and delete gates and devices, which is not what an
auditor should be able to do. Prefer a built-in role unless one of these has
been reviewed and deliberately chosen.
Give the narrowest role that lets the person do their job. It is far easier to add a role later than to explain why somebody could see something they should not have.
What the sidebar does and does not tell you
- The name under the sidebar avatar is the person's TPAS role, read from the authorisation service. If it is not the role you expect, check their account under Administration → Users & Roles → Users.
- An account holding several roles shows only one name there, and not necessarily the important one. The sidebar chip is not a summary of what somebody can do; the Users page is.
- A visible menu entry proves they hold that entry's permission — not that every row behind it belongs to their own organisation. Row-level scoping is the backend's job, and it is applied per endpoint.
- A missing entry is not always a missing permission. The viewer holds
visitor:readand still has no Visitors entry, because that entry lives in the Management group and the viewer is shown Registry (Two sidebars, one set of pages).
To find out what somebody can actually do, look them up in Administration → Users & Roles → Users and read their assigned roles, then read those roles in The role catalogue.