Team members and roles
Your account is a workspace that you (the Owner) can share with colleagues. Each invited person signs in with their own login but works inside your workspace — your devices, gateways, and dashboards — with access limited by the role you give them and, if you choose, by which devices they can see (see Device access below).
Roles
A role is a set of permissions (e.g. "edit devices", "change parameters", "add gateways", "edit dashboards"). We ship four built-in roles:
| Role | Can do |
|---|---|
| Owner | Everything, including billing and managing the team. There is exactly one Owner — you. |
| Admin | Everything except changing the plan or paying — manage devices, gateways, dashboards, rules, macros, data forwarding, the team, and save and schedule reports. Can see the plan, orders and invoices. |
| Operator | Run the fleet: edit devices, change parameters, send commands, edit dashboards/rules/macros, build, run and export reports. Cannot add or remove gateways, flash gateway firmware, change data forwarding, save or schedule reports, manage the team, or see billing. |
| Viewer | Read-only. See devices, dashboards, data, data-forwarding destinations (without their credentials) and billing, and run reports on screen, but change or export nothing. |
Need something in between? Build your own — see Custom roles.
Workspaces: switching between teams
When you sign in, Synacl opens the workspace you used last. The first time, it opens the team you joined most recently — unless you have devices or gateways of your own, in which case you start in My account and switch to the team when you need it. The name of the team you're working in shows in the top bar.
If you belong to more than one workspace (your own account plus one or more teams), open your profile menu (top right) and use the workspace switcher to move between My account and each team. Switching keeps you signed in. If you belong to only one workspace there's nothing to switch, so the switcher isn't shown.
On the mobile app you land in your team the same way, but the app has no switcher yet: pick the workspace on the web, then sign in again on the phone and it opens the one you chose last.
Nobody can hand out more than they hold
Managing the team never lets anyone reach above their own role:
- Whoever invites or manages members can only put someone into a role whose permissions they hold themselves. Roles above your own aren't offered in the picker.
- Nobody can change their own role — another admin or the Owner has to do it.
- You can't change or remove a member whose role includes a permission yours doesn't.
- Custom roles follow the same line: you create, edit and delete them only within your own permissions, and editing the role you hold yourself can only narrow it — see Custom roles.
The Owner is never limited by any of this.
Device access: limit a member to some devices
By default every member sees the whole fleet. Device access narrows a member to the gateways and devices they actually work with — a contractor who looks after one site, or a technician who should only see their own machines.
Device access is being switched on account by account. If your account has it, you'll see Device access when you open a member on the Team page.
Set it
- Go to Team and open the member.
- Under Device access, choose:
- All devices (the default) — the member sees everything their role allows, across the whole account.
- Selected — pick the gateways and/or individual devices they may see. Picking a gateway includes its sub-gateways and every device on them.
- Save. The change takes effect immediately — the member's live view reconnects on its own.
You need to be the Owner, or hold Manage members, to change someone's device access. The Owner is never restricted.
What a restricted member sees
Everything is filtered to their devices: the device and gateway lists, device pages and charts, live data, events and alarms, rules, macros, jobs, fleet views, uptime, and push notifications. In Reports they build reports over their devices only, and see only the saved reports and schedules they created themselves. Anything outside their access simply isn't there — no greyed-out rows, no "access denied".
Their role still applies on top: a restricted Operator can edit and command the devices in their access; a restricted Viewer can only look at them. A device or gateway a restricted member creates is added to their own access automatically.
What a restricted member can't do
- Invite people, or change anyone's role or device access.
- Change account-wide settings: data-forwarding destinations and saved actions.
Agent access: tokens and AI apps your members hold
Members can create API tokens and connect AI assistants that act with their own permissions — never more. Anyone with Manage members can see every token and connected AI app held by anyone in the workspace under Team → Agent access, and revoke any of them. Removing a member revokes their tokens and connected apps in your workspace automatically; anything they hold for their own account is untouched.
What permission gating looks like
Members only see the buttons and pages they're allowed to use. A Viewer opening a dashboard sees it read-only with no Edit toggle; an Operator can edit it. A role with no permission at all in an area can't open that area — without View rules, the Rules page isn't available. If a member tries an action outside their role, the app shows "You don't have permission for this action" — it never signs them out.
Any permission in an area includes viewing that area: Edit devices includes View devices, Manage data forwarding includes View data forwarding, and so on. A custom role that grants "edit" without "view" keeps working.
Two permissions are new in 1.27.0: View data forwarding and Manage data forwarding. Before, any member could change where your data is forwarded; now changing destinations needs Manage data forwarding. Admins have both, Viewers can view (credentials hidden), Operators have neither.
Plan and seats
Team members are a paid-plan feature. On the Free plan your workspace is just you (one seat). Paid plans add seats; the Team page shows how many you've used (used / limit). When you reach the limit, upgrade your plan to invite more. A plan with unlimited seats shows no count.
Limits follow the team's plan: a member's rule and macro limits are those of your plan, not of their own account.
Alerts and notifications
Members see the same events feed and alerts as you — a member with limited device access sees only the events, alarms and push notifications for their devices. Those who use the mobile app also receive the workspace's push notifications on their own phone, with their own notification settings (on/off, minimum severity, quiet hours). Removing a member stops their notifications along with their access; if they were signed in, their session leaves your workspace within minutes.
To get started, see Inviting team members.