Start with no access

Viewer and Operator assignments should not imply global visibility.

Scope explicitly

Assign groups, sites, devices or all-resources deliberately.

Enforce server-side

UI hiding is useful but backend authorization remains authoritative.

Audit changes

Treat role and scope changes as administrative security events.

Need deployment help?

AL Group can design, deploy, integrate and support the production implementation.

Talk to engineering →