Administration

Members & roles

Who can see and change what, and how access follows the tenant tree.

Access is granted per tenant. A person is a user on the platform, and a member of each tenant they can work in — with a role that decides what they may do there.

The same person can be a member of several tenants with a different role in each.

Roles

RoleCan
OwnerEverything in the tenant, including managing members.
AdminEverything operational — projects, devices, integrations, routing, rules.
MemberDay-to-day work; not tenant administration.
ViewerRead only. Nothing they do can change the pipeline.

Give Viewer freely — to colleagues who need to check whether data is flowing, to support staff, to anyone diagnosing a problem. It is the role that costs you nothing.

Keep Owner narrow. It is the role that can hand out access.

Access follows the tree

Tenants nest, and so does visibility. A member of a parent tenant can work in the tenants beneath it; a member of a child sees only that child and its own descendants.

So an operator's support team can be granted access once at the top rather than being added to every customer individually — and a customer's own staff, added at their tenant, can never see a sibling.

Add people at the narrowest tenant that works
Membership high in the tree is inherited all the way down. Adding someone at the operator tenant because it was convenient gives them every customer beneath it.

Adding someone

IAM → Members → Add. The person must already exist as a platform user; creating the login itself is a separate, platform-level action under IAM → Users.

Two steps, deliberately: creating a login and granting access to a tenant are different decisions, often made by different people.

Changing and removing

Changing a role takes effect on that person's next request. Existing sessions are not forcibly signed out, so a role change is not an instant lockout — if you are removing access urgently, remove the membership rather than downgrading it.

Removing a membership revokes access to that tenant only. The platform user remains, along with their access to any other tenant.

The active tenant

Anyone in more than one tenant picks an active tenant in the sidebar, and everything they see and create belongs to it.

When someone reports that a device "disappeared", the active tenant is the first thing to check — far more often than not, they are simply looking at the wrong one.

What to tell a new member

Three things save the most support time:

  1. Check the active tenant first, every time.
  2. Analytics answers "is data flowing?" faster than anything else.
  3. Dead letters is where failed deliveries wait — they are parked, not lost.

Next

Provider credentials
API credentials, their scopes, and rotating them.
Tenants & projects
How the hierarchy decides what people see.
Copyright © 2026