Skip to content
Try for free

ThingsBoard Cloud

Choose your data region

Your data stays in the region you choose, for residency and compliance. No credit card required.

Rather run it yourself? Install on your own servers

Isolate Device Access by Group

Give each user group exclusive read/write access to their own device group, with no cross-access between groups. This uses Group roles — each role applies strictly to a specific entity group.

Prerequisites: Basic familiarity with Roles and RBAC.

User groups

  • Building A Admins (includes Alice)
  • Building B Admins (includes Bob)

Device groups

  • Building A (contains Device A1)
  • Building B (contains Device B1)

Objective

  • Alice: read/write access to devices in Building A only.
  • Bob: read/write access to devices in Building B only.
  1. Navigate to Customers & users ⇾ Roles.
  2. Click + Add role.
  3. Name: Building Device Access — Role type: Group.
  4. Under Permissions, add: Operations Read, Write.
  5. Click Add.

Step 2. Assign to the “Building A” device group

Section titled “Step 2. Assign to the “Building A” device group”
  1. Navigate to Devices & assets ⇾ Devices ⇾ Groups.
  2. Open Building A device group details ⇾ Permissions tab.
  3. Click Add.
  4. Select: Role Building Device Access, Owner Tenant, User group Building A Admins.
  5. Click Add.

Step 3. Assign to the “Building B” device group

Section titled “Step 3. Assign to the “Building B” device group”
  1. Open Building B device group details ⇾ Permissions tab.
  2. Click Add.
  3. Select: Role Building Device Access, Owner Tenant, User group Building B Admins.
  4. Click Add.
  • Alice sees only device group Building A and Device A1.
  • Bob sees only device group Building B and Device B1.
  • Neither can access devices outside their assigned group.