Skip to content

How RBAC stores its configuration

Applies to Enterprise ManagementField App Introduced in 1.0.0 Role: Administrator

Install-time settings (rbac/settings/code.py)

Section titled “Install-time settings (rbac/settings/code.py)”

When RBAC is first deployed, three per-install values must be set in rbac/settings/code.py. This is the one place in the package that ties RBAC to your specific projects and tags, and it’s done by whoever installs the module — not through the admin screen.

FIELD_APP_PROJECT_NAME = "SiteSync-FieldApp" # confirm via system.util.getProjectName()
ERROR_POPUP_VIEWPATH = "Popups/error"
CONFIG_TAG_PATH = "[SiteSync]_Config/RBAC"
ValueWhat it is
FIELD_APP_PROJECT_NAMEThe exact name of the Field App project RBAC enforces against. Confirm it with system.util.getProjectName() from within that project — it must match exactly.
ERROR_POPUP_VIEWPATHThe view path shown when a user attempts an action they don’t have permission for.
CONFIG_TAG_PATHThe tag that stores the RBAC configuration (see below). Must match the tag your deployment actually uses.

Everything RBAC knows lives in a single tag:

Tag pathType
[SiteSync]_Config/RBACString (memory tag)

The tag’s value is stored as a JSON-encoded string. Parsed, it represents the same information the admin screen edits:

  • enabled — the master on/off switch; same as the RBAC Enabled toggle on the admin screen.
  • roleMappings — one entry per privilege: add, edit, and delete. Read isn’t listed here because every authenticated user always has it.
  • Each grant is a { role, tenantIDs } pair. role must match your identity provider’s role name exactly, including case. tenantIDs is either "*" (all sites) or a list of specific site IDs.
{
"enabled": true,
"roleMappings": {
"add": [
{ "role": "FieldTech", "tenantIDs": [2] },
{ "role": "Administrator", "tenantIDs": [3, 8] },
{ "role": "EnterpriseOwner","tenantIDs": "*" }
],
"edit": [
{ "role": "FieldTech", "tenantIDs": [2] },
{ "role": "Administrator", "tenantIDs": "*" }
],
"delete": [
{ "role": "FieldTech", "tenantIDs": [2] },
{ "role": "Administrator", "tenantIDs": "*" }
]
}
}

If you ever need to inspect this directly — for example, while troubleshooting with your SiteSync contact — you can view or export it from the Designer’s Tag Browser at the path above, the same way you would any other tag.

Was this page helpful? Report incorrect documentation Last reviewed 2026-08-25