hi human interface®
English

Access Control

Access Control

Overview

Access Control defines who can sign in, which product functions each user can access, and which Ports are visible to them. Effective access combines roles with Tag-based visibility rules.

Access control in hi combines the following mechanisms:

  • Role-based feature access - roles define which product functions a user can access.

  • Tag-based resource visibility - assigned Tags grant resource visibility, while Limit Access narrows the Tags available to the user.

  • External identity integration - Microsoft Entra ID (formerly Azure Active Directory) support allows user access to be linked to an existing identity provider where configured.

User Access Model

Authentication

The hi web interface requires an authenticated session. Local authentication is available by default. Microsoft Entra ID authentication can be enabled for installations that use external identity management.

hi supports two authentication methods:

  • Local authentication - a username and password managed by the hi installation.

  • Entra ID - an external identity provider used for enterprise sign-in and group-based access where licensed and configured.

For identity-administration entitlement, see Licensing - Select by Capability. hiCore includes this capability; existing hiBase installations use their hiAccess entitlement.

For sign-in behavior and identity-provider configuration, see Sign In to hi and Manage System Settings.

User and Group Assignments

For Entra ID users, group membership adds the group's configured roles and Tags to the user's assignments. Each resulting set contains unique assignments.

User and Group Assignments

The combined roles determine feature access. Tag assignments contribute to resource visibility, with Limit Access applied separately.

User Roles

The user editor groups roles under Administrative Roles, Feature Access Roles, and Operation Roles. Feature-specific roles can appear when those features are enabled.

Administrative Roles

Role

Access provided

System administrator

System-wide administrative access.

User admin

Manage user accounts and assign their roles.

Node admin

Add, remove, and configure Nodes, including device-specific settings.

Tag admin

Define and manage Tags and categories.

Tally admin

Define and manage Tallies.

Shutdown admin

Shut down or restart the system.

Logging access

Access system logs and create or download log collections.

Licensing admin

View and manage licensing information.

Widget admin

Create, configure, and delete Widgets.

Feature Access Roles

Role

Access provided

Control Panel access

Access the Control Panel, subject to the user's Tag-based visibility, and Monitor Walls whose Tags the user can access.

Simplified Control Panel access

Open a simplified Control Panel with delegated Presets and no main navigation.

Monitor Wall admin

Create and manage Monitor Walls, displays, and Multiviewer Head layouts.

Simplified Power Widget access

Access assigned Power Widgets through the simplified interface.

Wiring Diagram access

Access wiring diagrams.

Port Container admin

Create, edit, and delete Port Containers.

Joystick Override admin

Configure Joystick Override settings and Shader Groups.

Rule admin

Define and administer Rules, including their triggers and actions.

Operation Roles

Role

Access provided

Preset admin

Manage Presets and delegate them to users or Hardware Panels.

Unlock admin

Unlock locks on authorized Destinations.

Port Container Assignment

Modify Port assignments in Port Containers on the Control Panel.

Backup admin

Create, update, delete, and restore Backups.

Snapshot admin

Create, update, delete, and recall Snapshots.

Most roles can be combined.

The Simplified Control Panel access and Simplified Power Widget access profiles are exclusive. Saving either one removes the user's other roles, and while a user has one of these profiles, the role editor disables the other roles. The System administrator role automatically includes all roles.

For the role-assignment workflow, see Manage Users.

Defining Access to Ports in the System

While roles define feature access, Tagging controls which Ports and related resources a user can see and operate.

Two Tag-based access mechanisms are available:

  • Assign Tags - grants access to resources carrying the assigned Tags.

  • Limit Access - applies a pre-filter that narrows which Tags remain available to the user or group.

Tag assignments and pre-filters can also come from Entra ID groups. The Account Information view shows the resulting effective configuration.

Example: Access for a Studio Operator

A Studio Operations group is imported from Microsoft Entra ID. Its configured assignments include Control Panel access and the Main Studio Tag.

An operator belonging to that group inherits those assignments. The role provides Control Panel access; the Tag provides access to the tagged resources.

Setting

Purpose in This Example

Observable Result

Control Panel access role

Provide access to the routing workspace.

The operator can open the Control Panel.

Main Studio Tag assignment

Provide access to resources carrying that Tag.

Aggregated Tags includes Main Studio; the operator can view the accessible tagged Ports.

Limit Access pre-filter

Restrict the available Tag view separately from Tag assignment.

Account Information shows the pre-filter; the operator sees the permitted Tag filters.

Use Inspect Account Information to review Aggregated Roles, Aggregated Tags, and the pre-filter together.

Then verify the Control Panel with the operator's account. Tag assignment does not replace a required role, and a pre-filter does not grant additional access.

Operational Implications

Feature access, resource access, and the available Tag view are separate parts of the configuration. Review all three when a user cannot find a workspace or Port.

Entra ID group workflows apply only to Entra ID users. Local users receive their assignments directly; they do not use imported Entra ID groups.

License Implications

Authentication and authorization do not define session entitlement. See Licensing - User License Model for the canonical session-counting rules.