Granular User Roles
Split API and DOM Service access across roles matching real responsibility levels.
Overview
The DOM Service application is increasingly used on site, and can be handed to people with very different levels of responsibility — from an installer commissioning devices to a facility operator performing day-to-day openings. The API now defines roles reflecting these levels, instead of the coarser permission set used previously.
Roles work together with Microsoft Entra ID authentication, which supplies the identity, and with the audit trail, which records what each identity did.
Available since: Version 26.02 (June 2026 · API v34)
How to Use
Assign a role to each API user according to what that user must be able to do on site. Access to the audit data is itself governed by the role, so an installer account can be granted device operations without being able to read the audit trail.
Refer to the Middleware API Specification shipped with the release for the exact role names and the operations each one covers.
Updates
26.02 — June 2026
Initial Release
- New API roles reflecting the responsibility levels encountered on site
- Role assignment governs DOM Service capabilities and access to the audit data