FEATURES · ROLES AND ACCESS

Give the right access. And nothing more.

In Overseer, people see and do only what their role allows. A role is a set of capabilities you choose, a person can be limited to particular clients, and every change to who can do what is written to the audit log.

Built from capabilities

A capability is one named decision, such as deploying software to a computer. Roles hold capabilities; people hold roles.

Limited by client

Give a person every client or only the ones they look after. The rest stay out of view.

New roles start empty

A role you create holds nothing until you grant it, so nobody receives access by accident.

Every change recorded

A new account, a changed role, a granted capability: each one goes into the audit log.

The People screen in Overseer, which lists the people Overseer knows about.
People is where each person is given the role they work under.
THE PROBLEM

Shared access hides who can do what.

  • Everyone is an administratorIt is quicker to give full access than to work out what each person needs.
  • Roles copied from other rolesA copied role carries capabilities nobody chose to give, and they stay unnoticed.
  • Every client in viewSomeone who looks after two clients can open the computers of all of them.
  • Changes with no recordAccess is widened for one job and never narrowed. Later, nobody can say who widened it.
WITH OVERSEER

Each role holds only what you grant.

  • Capabilities, named plainlyEach capability covers one decision that matters. A refusal names the capability that was needed.
  • One client or allActing on a client’s computers and writing one deployment for every client are separate capabilities, granted separately.
  • Guards against lockoutYou cannot change your own role, delete your own account, or remove the last administrator.
  • Read-only where it fitsA viewer role opens reports, sessions and history without any capability to change a computer.
SETTING UP ACCESS

Three decisions. Each made on purpose.

1

Define the role

Create a role, describe who it is for, and grant the capabilities it needs.

RoleDescriptionCapabilities
2

Choose the clients

Decide whether the person works across every client or only particular ones.

Every clientParticular clients
3

Assign the person

Put the person on the role in People. It applies from their next action and is recorded.

PeopleRoleAudit log
ROLES

Two roles built in. The rest are yours.

RoleWhere it comes fromSeesCan do
AdministratorBuilt inEvery clientHolds every capability, always. This role cannot be narrowed or deleted.
TechnicianBuilt inThe clients you give themDay-to-day work on computers, within the capabilities you leave it.
Read-only viewerYou define itThe clients you give themOpens reports, sessions and history. Changes nothing.
Any other roleYou define itThe clients you give themOnly the capabilities you grant. It starts empty.

In development. Launch inquiries welcome.

Overseer is still being built and is not available yet. If you would like to hear when it launches, get in touch.

Ask about launch