Skip to main content

Users and roles

Question and objective

Who should use analyses, and who should be allowed to change their configuration? The objective is to enable everyday use while deliberately controlling changes to production data flows.

Implementation in Bytefabrik

The StreamPipes foundation distinguishes global administration from module-specific roles, for example for connectivity, pipelines, dashboards, data exploration, and assets. Resources also have their own permissions. Bytefabrik modules may require additional privileges; the actual selection depends on the installation.

Operational activities such as machine operation or process engineering are not automatically predefined role names. Derive the permissions they need from their specific tasks.

Best practices

  1. Describe which views a user group needs and what it should be able to change.
  2. Assign the required module privileges and check access to the relevant resources.
  3. Test the result with a representative account rather than only as an administrator.
  4. Recheck permissions when resources are shared, teams change, or additional modules are activated.

Example: A team needs a dashboard for shift meetings but does not need to change the underlying pipeline. Treat these as separate tasks when assigning permissions.

What to consider

Access to an overview page does not automatically mean access to every resource. Conversely, hidden navigation is not a substitute for properly managed permissions.

Keep administrative accounts separate from everyday use and document responsibility for production changes. This reduces unintended configuration changes without making daily analysis unnecessarily difficult.