The Admin app manages who can use SAGRIS ODC and what they can do. It is restricted to users with the user-administration permission.
Three separate concepts, one per panel:
| Panel | Grants | Answers |
|---|---|---|
| Groups | Permissions | What may a user do? |
| Companies | App entitlements | Which apps may a customer use? |
| Users | Accounts | Who is this person, and which groups/companies/plan apply? |
Key rule: Membership in the administrators group grants access to the Manager control plane. Grant it sparingly.
To onboard a new customer user: make sure a company exists with the right apps, confirm the groups that carry the permissions they need, then on the Users panel set their plan, groups, and companies.
A group is a named set of users that carries a set of permissions. A user's effective permissions are the union over all the groups they belong to.
The top card lists every permission and what it grants. Use it as the reference when deciding which permissions a group should carry.
administrators: membership in this group grants access to the Manager control plane. Treat it as the most privileged group.
Open a group from the list to change its permissions or description. Changes take effect on the user's next permission check.
Tip: Build groups around roles (e.g. "analyst", "operator") rather than individuals — then onboarding a person is just adding them to the right groups on the Users panel.
A company is a contract-bound customer account. Its applications are the SAGRIS ODC apps the contract covers, and users inherit app access from the companies they belong to.
These are deliberately separate:
| Grants | Example | |
|---|---|---|
| Groups | Permissions — what a user may do | "may administer users" |
| Companies | App entitlements — which apps a customer may use | "Mapper + Farmer" |
A user typically needs both: a group for permissions and a company for app access.
Add users to a company from the Users panel — they then gain access to that company's apps.
Tip: Use the description field to record the contract reference or renewal date so entitlements stay traceable.
Every account that has signed in at least once appears here. The table is where you set each person's plan, access, groups, and companies.
| Column | Meaning |
|---|---|
| The account identity (from Auth0 sign-in). | |
| plan | Data-API quota tier — controls the user's API rate/feature limits. |
| active | Master on/off switch for all access. |
| groups (permissions) | The user's groups → their permissions. administrators ⇒ Manager access. |
| companies (apps) | The user's companies → which apps they can use. |
Note: A user only appears after their first successful sign-in. If someone is missing, have them log in once, then refresh.