Start with no access
Viewer and Operator assignments should not imply global visibility.
Scope explicitly
Assign groups, sites, devices or all-resources deliberately.
Enforce server-side
UI hiding is useful but backend authorization remains authoritative.
Audit changes
Treat role and scope changes as administrative security events.
AL Group can design, deploy, integrate and support the production implementation.
Talk to engineering →