Help Center

Access Control - Help

Access Control

Managing permissions and access rights

Access Control

Access Control in Command Center is where admins review membership requests, sponsorship flows, and grant assignments that decide who can perform sensitive actions in REACTOR. It complements User Management: users may exist, but grants and approvals still gate what they can do in pilot workflows.

Purpose

Pilot safety workflows depend on the right people being able to approve permits, triage observations, investigate incidents, and assign actions. Access Control provides the approval queues and grant tooling to manage those permissions deliberately — rather than giving everyone broad admin rights.

Who uses this

  • Tenant Owner / Tenant Admin — reviews pending access requests and manages grants
  • HSE lead — confirms approvers and specialists receive the right workflow permissions
  • Cerb.works — assists with bootstrap grants and troubleshooting effective access

End users do not manage grants here. Operators who need help should contact their Tenant Admin. Personal support tickets belong in Control Panel → Support, not Access Control.

What the admin configures

  • Membership requests — approve or reject people joining the organization
  • Sponsorship requests — review sponsored access flows when enabled
  • Grant assignments — assign catalog grants that unlock specific module permissions
  • Grant manager — create, filter, and revoke assignments for users
  • Grant history — audit trail of assignment changes
  • Effective access review — inspect combined role + grant outcome on user detail pages

Typical setup workflow

  1. After User Management provisioning, list who must approve PTW, triage observations, and manage incidents.
  2. Open Access Control and clear any pending Membership requests for pilot participants.
  3. Assign grants so supervisors and HSE specialists can perform module actions (for example PTW approve/issue where required).
  4. Use the Grant assignments queue for high-risk grants that need explicit approval.
  5. From a user's Command Center profile, open Effective access to verify the result matches intent.
  6. During the pilot, review grant history after role changes or when someone reports "access denied" in a module.

Roles and responsibilities

  • Tenant Admin — keeps approval queues current and assigns grants according to the pilot role model.
  • Process owner — defines which job functions map to PTW approver, HSE reviewer, and incident investigator.
  • Grant approver — acts on pending high-risk grant assignments promptly.
  • Cerb.works — supports bootstrap grants and explains effective access when module behaviour does not match expectations.

Access / permission implications

Effective access is layered:

  1. Tenant membership — user belongs to the organization.
  2. Tenant role — baseline admin vs operational vs viewer behaviour.
  3. Module access — modules visible in the shell (configured in User Management).
  4. Grants — fine-grained permissions inside modules (for example SHARD PTW approve).

A user can be an Operator in User Management yet still receive a grant that allows a specific approval action. Conversely, a Supervisor without the right grant may see a module but cannot complete approval steps.

Pilot-safe caveats

  • Keep the pilot role model small — avoid granting broad admin or platform roles to field users.
  • Do not assume enterprise SSO, automated group sync, or custom audit exports are active unless agreed for your tenant.
  • Some queues (for example company claims) are platform-operator concerns; tenant admins typically focus on membership and grant assignments.
  • When access fails, check active status → tenant role → module access → grants before re-provisioning the user.
  • Document who holds approver grants locally so holiday cover and shift handover stay workable.

Where to open it in REACTOR