Role-based access control (RBAC)
What RBAC does
Section titled “What RBAC does”Role-based access control lets you decide which of your identity provider’s roles can Add, Edit, or Delete devices in the SiteSync Field App — and at which sites. Every user can always view (Read) devices; RBAC controls whether they can also change or remove them.
| Privilege | What it allows |
|---|---|
| Read | View devices and their data. Every authenticated user has this by default — it is the baseline everyone gets, whether or not RBAC is turned on. |
| Add | Create new devices at a site (for example, via QR sync or manual entry). |
| Edit | Modify an existing device — its configuration, location, tags, and similar settings. |
| Delete | Remove a device from a site. |
How access is determined
Section titled “How access is determined”RBAC does not maintain its own list of users. Instead, it reads the role names your identity provider (IdP) already assigns to each person when they log in, and checks those role names against the permissions you configure on the admin screen.
This works with any identity provider Ignition supports — Azure AD / Entra ID, Okta, Auth0, ADFS, a generic SAML or OIDC provider, or Ignition’s own built-in accounts. For an OIDC-based provider like Azure AD / Entra ID with roles configured as App Roles, Ignition typically picks up the standard roles claim automatically — no extra mapping step needed once the App Role is assigned to a user in Azure. If your identity provider uses SAML, or sends role/group information under a non-standard claim or attribute name, your Gateway’s Identity Provider configuration may need an explicit attribute mapping so that information lands in Ignition’s session roles. Your SiteSync contact can confirm what, if anything, is needed for your specific provider.
Reference documentation from Inductive Automation:
- Configuring Identity Providers
- User Attribute Mapping — only needed for non-standard claim names, e.g. SAML
Default behavior and safety
Section titled “Default behavior and safety”Off by default. Until you explicitly turn RBAC on, every authenticated user retains full Add, Edit, and Delete access — identical to how the Field App has always worked. Upgrading to a version with RBAC changes nothing on its own.
Fails safe. If the underlying configuration is ever unreadable or invalid for any reason, the app does not break or lock anyone out — it falls back to Read-only access for everyone until the issue is resolved.
Scoped to the Field App only. RBAC has no effect on the Enterprise Management app or Site dashboards.