How does roles and permissions (to access EV Portal) work?
Core principles:
Access to EV Portal is managed through role-based access control.
- Access groups: Define where the user has power (e.g. a specific CPO contract like UK-ABC)
- Roles: Define what the user can do within that group (e.g. CPO Manager)
- Permissions: Define what specific actions are allowed for role (e.g. Create location or U

Concrete example for a certain user with two Access Groups (2 entry records below), each with its role(s):

Each of these roles (e.g. Smart Charging Manager) has a set of associated permissions, which will allow the user to perform the respective actions over the assets that belong to Group (e.g. CPO Contract: GreenFlux Netherlands)
Key principle when assigning/updating/removing Groups and Roles. A certain EV Portal user (USER A) can only add/update/remove Groups and Roles to another user (USER B) provided the following two conditions are verified, within each access group:
- USER A has a role assigned to it which contains a permission with ability to manage Users (Create User, Read User, Update User, Delete User).
- The group and permissions that the USER A is trying to change in regard to USER B is a group and role that user A has assigned to himself.
Please refer to this article to see how to manage users: How to Create and Manage Users
