Onboard uses role-based access control to manage what users can see and do within your account. This guide explains the roles available, how the hierarchy works, and how access is scoped.
Onboard has two roles: Admin and User.
Admin is the highest level of access. Admins have full control over the account, including managing users, configuring buildings and deployments, and accessing all data. Every account must have at least one Admin.
User can view and interact with the buildings and data they have been granted access to, but cannot manage deployments, publish data or invite other users.
| Capability | Admin | User |
|---|---|---|
| Access buildings and data | ✅ | ✅ |
| API Access | ✅ | ✅ |
| Use Data Export Tool | ✅ | ✅ |
| Create Data Alerts | ✅ | ✅ |
| Manage Buildings & Deployments | ✅ | ❌ |
| Model & Publish Building Data | ✅ | ❌ |
| Invite & manage users | ✅ | ❌ |
| Manage account settings | ✅ | ✅ |
| Access to Onboard Community | ✅ | ✅ |
By default, users are granted access at the account level, meaning they can view all buildings associated with the account. If you need to restrict a user's access to specific buildings only, Onboard supports per-building roles. To configure per-building access, contact support@onboarddata.io.