Cooperation Permission Restrictions
When you share a plant or portfolio with a partner organization, the level you share at becomes a ceiling: the partner can never grant their own members more access than you gave them. This keeps cross-organization sharing safe and predictable — you stay in control of how far your resources travel.
Concept
A cooperation lets two organizations share parks and portfolios across the organization boundary. Each shared resource is shared at a specific job role, and that role caps everything the receiving side can do with it.
Three rules make this work:
- Visibility is broader than access. An Admin or Moderator on the receiving side can see what a cooperation shares — which plants and portfolios, at which job role, from whom, and for how long. Running a partner relationship is organizational governance, so the manager tier, Member and External see none of it.
- Access stays with the Admin. Seeing the list is not the same as opening the data. Only an organization Admin on the receiving side automatically gains access to the shared resources themselves; everybody else needs an explicit grant from that admin.
- Capped delegation. The receiving admin can hand a shared resource to their own members only at a role no higher than the one it was shared at, and only within an allowed set (see below).
Info
Visibility without access is deliberate. The people who run a partner relationship need to know which resources it covers, while the decision to actually open plant data to a person stays with a single accountable admin on each side.
Who sees what
On the receiving side, seeing that a resource was shared and being able to open it are two separate things:
| Role on the receiving side | Sees the sharing arrangement | Automatic access to the data |
|---|---|---|
| Admin | Yes | Yes |
| Moderator | Yes | No |
| Asset Manager (Technical) | No | No |
| Asset Manager (Commercial) | No | No |
| Member | No | No |
| External | No | No |
This is not a dead end. The admin decides who should work on the shared plants and delegates the resource to them — typically the Asset Manager (Technical) — and from that moment those people manage exactly the plants they were given. What delegation never hands over is the cooperation overview itself; that stays with Admin and Moderator.
Permission Hierarchy
Job roles on a resource run from highest to lowest authority. Technical Manager and Asset Manager sit at the same level: they are two parallel tracks for different purposes, not steps in a ladder. Cooperation sharing picks one of these — or the separate Security Officer lane described below — as the shared level:
Technical Manager covers the technical operation of the plant. Asset Manager covers the same plant scope and additionally the commercial side (accounting data). Choose the one that matches why the partner needs the resource — neither outranks the other.
The Operator role is reserved for resources an organization owns directly. You can never share or re-grant a resource at the Operator level through a cooperation — that authority does not cross the organization boundary.
Security Officer is not on this ladder at all — it is a separate lane. It reaches the network segments of the plant it was granted (network infrastructure, cameras, security systems) over remote access, plus that plant's access log, and it reaches no production, performance or commercial data. That makes it the level to share with an alarm, CCTV or perimeter contractor: they get to the equipment they maintain, and to nothing else on the plant. Which networks a security officer actually reaches is decided by the segment tags — see Network Segmentation.
You share at this level exactly like any other: pick the plant or the portfolio, and set Security Officer as the shared role. Sharing a portfolio hands the role every plant inside it. What the partner then sees is the plant by name, its network devices in the granted segments, remote access (VPN and browser proxy) to those devices, tickets and the plant's access log — and no dashboard, production graphs, components, reports or commercial figures at all.
A Viewer is not a smaller Security Officer
The two are different lanes, not two rungs of one ladder. A Viewer sees the plant's production, performance and events, but reaches no network device and gets no remote access. A Security Officer is the mirror image: remote access to its granted segments, and no production data whatsoever. Neither contains the other — which is why a Security Officer share is delegated on its own terms.
How Capped Delegation Works
When Organization A shares a resource with Organization B at a given level, Organization B's admins can:
- Access the resource automatically at the shared level (admins only).
- Delegate to their own members — but only within the allowed set for that shared level.
The allowed set for a cooperation-shared resource is Viewer plus the shared role itself. A receiving admin chooses between giving a member read-only access (Viewer) or the full shared level — nothing in between, and never higher.
The one exception is Security Officer, because Viewer does not sit below it. Offering Viewer there would let the receiving admin turn a segment-only share into a production grant you never made, so a Security Officer share can only be delegated as Security Officer.
| Shared at | Receiving admin may grant members | Never allowed |
|---|---|---|
| Technical Manager | Viewer, Technical Manager | Operator, anything higher |
| Asset Manager (commercial authority) | Viewer, Asset Manager | Operator, anything higher |
| Security Officer (network segments) | Security Officer | Viewer, Operator, everything else |
| Viewer (read-only) | Viewer | every higher role |
Example Scenario
Warning
A member who receives a cooperation-shared resource sees exactly what their granted level allows — no more than the organization that owns the plant chose to share. If the sharing organization later lowers the shared level or removes the cooperation, the receiving members' access is reduced or revoked accordingly.
Managing Cooperation Permissions
You manage what your organization shares, and what it re-grants, from the cooperation and member-permission areas of the platform:
- What you share out — only the resource-owning organization can set the level at which a park or portfolio is shared through a cooperation, and can set an optional expiration on that share.
- What you delegate in — a receiving admin grants the shared resource to their own members within the allowed set above, optionally with an expiration date.
These surfaces are also available through the public REST API (see the live /docs). The same caps are enforced no matter how a grant is made, so the API can never be used to exceed the shared level.
Related Features
- Permission System — organization roles, job roles, and how they map to resource access
- Cooperations — how to create, pause, and expire cross-organization sharing
- Invitations — inviting members and partner organizations
- Audit Log — who accessed shared plant infrastructure and when