Skip to main content

Idea

Operator accounts allow you to grant your employees restricted access to your dashboard. This is useful if you want to prevent them to accidentally remove product or an access token, while still allow them to perform necessary changes to licenses, etc. All operations performed by the user will be logged in the Object log.
You can also provision operators through Company SSO and SCIM. Enabling SCIM replaces existing local operator permissions and removes company access for operators absent from provisioning. Review the SCIM preparation steps before switching; manage directory users and their permissions through your identity provider.

Getting started

Adding an operator

To invite an employee to sign up for an operator account, you can share the link on the operators page. New operators have no dashboard resource permissions by default. Grant permissions afterward if they need to manage products, customers, or other dashboard resources. If the employee already has an operator account, ask them to sign in with that account and accept your company’s invitation. Their account should then appear on your Operators page. When using JIT or SCIM user provisioning, complete this before their first JIT sign-in or before SCIM first provisions them. Otherwise, a separate account can be created; signing in does not merge it with the original account. In JIT mode, manual invitations are available only while SSO is optional; complete invitations before enabling SCIM. See reusing an existing operator account for the steps.

Employees who only need to view licenses

An operator can accept a customer association link and view the licenses assigned to that customer in the customer portal. This is useful for employees using internally licensed software. No additional operator permissions are needed for this workflow; leave them unset if the employee only needs to view those licenses. Follow the employee license-access steps.

Modifying permissions

Once an employee has signed up, you will be able to grant them permission by clicking on Modify on operators page. For employees who need to manage licenses and customers, we generally recommend two permissions: edit permission for products and owner permission for customers. Set Resource Id to 0 for access to all resources of that type, or to a specific product or customer ID to restrict access to that resource. Employees who only view licenses through customer associations do not need these permissions.

Permissions

In this section we describe what your employees can do with different permission levels.

Access Type

There are three different access types that you can assign to a user. Note, extra permission is given to users depending on the resource they have permission to, which is covered in Resources.

View

The user can only view the object.

Edit

The user can edit the object but not remove it.

Owner

The user can add new and remove existing objects.

Resources

In this section we cover extra permission given to users depending on the resource.

Product

In addition to the permission granted based on the access types described earlier, users will get extra permission to other objects depending on the access type. View Users will get read-only access to see all license keys, machine code and data objects (associated with the product, a license key or machine code). Edit & Owner Users will be able to add and modifying the aforementioned objects. Moreover, they will also be able to create new customers when creating a new license key (although they won’t see existing customers if they don’t have a separate permission to view customers).

Customer

No special permission is granted beyond what is defined under Access Type.

Analytics

No special permission is granted beyond what is defined under Access Type. For now, the analytics portal only supports read-only mode, so edit or owner permissions don’t give any extra access.

Billing

Allows users to manage billing information, access invoices, etc. View permission allows only viewing what is stored whereas Edit allows to change the pricing tier, the attached card, etc.

Resource Id

When this is set to zero, the user will have access to all products of that type. If you set it to be an id of an object (eg. product id), the user will only be granted the specified permission for that object.