Scope a User to Their Customer's Data
Restrict a customer user to see and manage only the entities belonging to their own customer, with no visibility into other customers. No entity groups are required — scope is controlled by where the Generic role is assigned.
Prerequisites: Basic familiarity with Roles and RBAC.
Step 1. Create the role
Section titled “Step 1. Create the role”- Navigate to Security ⇾ Roles.
- Click + Add role.
- Name: Customer Full Access — Role type: Generic.
- Add one permission entry: Resource All, Operations All.
- Click Add.
Step 2. Assign the role at Customer level
Section titled “Step 2. Assign the role at Customer level”- Navigate to Customers ⇾ click Manage customer users for the target customer.
- Open Groups ⇾ open the target user group ⇾ Roles tab.
- Click Add — select Role type Generic, Role Customer Full Access.
- Click Add.
Result
Section titled “Result”The user sees and can manage every entity belonging to their customer — and nothing outside it. Repeat Step 2 for each customer that needs this access pattern.