In Overseer, people see and do only what their role allows. A role is a set of capabilities you choose, a person can be limited to particular clients, and every change to who can do what is written to the audit log.
A capability is one named decision, such as deploying software to a computer. Roles hold capabilities; people hold roles.
Give a person every client or only the ones they look after. The rest stay out of view.
A role you create holds nothing until you grant it, so nobody receives access by accident.
A new account, a changed role, a granted capability: each one goes into the audit log.
Create a role, describe who it is for, and grant the capabilities it needs.
Decide whether the person works across every client or only particular ones.
Put the person on the role in People. It applies from their next action and is recorded.
| Role | Where it comes from | Sees | Can do |
|---|---|---|---|
| Administrator | Built in | Every client | Holds every capability, always. This role cannot be narrowed or deleted. |
| Technician | Built in | The clients you give them | Day-to-day work on computers, within the capabilities you leave it. |
| Read-only viewer | You define it | The clients you give them | Opens reports, sessions and history. Changes nothing. |
| Any other role | You define it | The clients you give them | Only the capabilities you grant. It starts empty. |
When a client asks who can reach their computers, the answer is in People, and every change to that answer is in the audit log.
Overseer is still being built and is not available yet. If you would like to hear when it launches, get in touch.