Use access groups to control where a user can work and roles to control what they can do. Follow the prerequisites below, then manage access from Admin > Users.
How access groups, roles, and permissions work
- Access groups define which part of your network a user can access, such as a specific CPO contract.
- Roles define what a user can do within that group.
- Permissions define the specific actions allowed by a role, such as creating a location or updating a Charge Station.
The example below shows a user with two access groups. Each group can have one or more roles.

Each role, such as Smart Charging Manager, includes permissions that apply to the assets in its assigned group, such as a CPO contract.
The second example shows the two access-group entries for the user. Review the group and role on each entry before changing access.

Before you assign or change access
Make sure both conditions are met for each access group:
- Your own assigned role includes a permission to manage users: Create User, Read User, Update User, or Delete User.
- The group and role you want to assign or change are already assigned to your own account.
If either condition is not met, you cannot assign or change that group or role for another user.
Where to manage user access
Go to Admin > Users to manage access:
- Select Add New to create a user, then assign an Access Group and Role before saving or sending the invitation.
- Select Edit for an existing user, then open the Groups tab to view or change their access groups and roles.
