Users – login, roles and permissions
Configure project accounts, understand role permissions and test allowed and blocked actions with a practice account.
1. Account, role and user display
An account identifies who signs in. The username is used for login; the display name appears in the application and as a note author. A role contains permitted functions. Changing a role affects all accounts assigned to it.
Accounts are project-specific. The user object displays session status and provides login/logout; it does not create accounts itself or require a PLC address. Original screenshots show the German interface.
2. Insert the user object
Select Documents → Users. The example uses X = 20, Y = 130, width = 300 and height = 72. Assign area can place the object in a tab, collapsible area or scroll area.
“Benutzeranzeige / Name und Rolle” is the editor preview. “Keine Benutzer eingerichtet” in test mode means no project accounts exist yet. Open project settings to create them.
3. Create the first account
- Open Settings → Manage users.
- Click New. Enter username rainer and display name Rainer.
- Use the management role, Administrator in this example, and keep the account enabled.
- Set your own password of at least 10 characters.
- Click Save. The account must then appear in the list on the left.
The first account must be active and able to manage users and roles. Rainer is already signed in after creation in this example. Close management, apply settings and save the project.
An empty password field on an existing account preserves its current password. A new account requires a password. Merely filling out the form does not save an account.
4. Sign in and out
- Start test mode with F5.
- Click Log out if necessary; the object shows that nobody is signed in.
- Click Log in, select the active account and enter its password.
- Confirm the login.
The display changes to Rainer / Administrator: display name above, role below. Without configured accounts, existing operating behavior is retained. This differs from being a signed-out guest after account setup.
5. View and edit roles
As an authorized user, open Settings → Manage roles. Select an existing role on the left to see its name and selected permissions. An empty name with unchecked boxes is the new-role form, not the Administrator permission set.
The screenshots show Beobachter (5), Bediener (15), Wartung (19), Projektierer (33) and Administrator (35 permissions). These counts describe this project state; actual checked permissions determine access, not the role name alone.
To edit, select a role, change its name or permissions and save. Click New first when adding another role. Scroll the permission list to see all entries.
6. Understand individual permissions
This reference explains all 35 permissions shown. Permissions are independent: editing recipes does not automatically permit transfer; creating notes does not permit marking them read. A workflow may require several permissions, such as editor access plus saving projects.
| Permission label in the screenshots | Meaning |
|---|---|
| Playmodus öffnen | Start the runtime view. |
| Seiten und Detailfenster öffnen | Navigate between process pages and open detail views. |
| Prozess bedienen und Werte schreiben | Operate controls and write process values. |
| Alarmmeldungen quittieren | Acknowledge alarm messages; this does not remove their cause. |
| PID-Regler bedienen | Operate PID setpoints and manual mode. |
| PID-Regler parametrieren | Configure controller parameters such as Kp, Ti and Td. |
| Notizen anlegen | Save a new shift note. |
| Notizen gelesen/offen setzen | Toggle the read status of existing notes. |
| Rezepte an die SPS übertragen | Write recipe setpoints to their configured destination. |
| Rezepte anlegen und bearbeiten | Edit recipe definitions and parameters. |
| Wartung öffnen und pflegen | Open and maintain maintenance functions. |
| CIP-Bibliothek öffnen und bearbeiten | Edit the cleaning-in-place (CIP) library. |
| Logbuch anzeigen und exportieren | Read and export recorded logbook events. |
| Trenddaten als CSV exportieren | Export recorded trend values to CSV. |
| Prozessprotokolle ansehen | View existing process reports. |
| Prozessprotokolle starten | Start recording a process report. |
| Prozessprotokolle beenden | Finish an ongoing process report. |
| Prozessprotokolle als PDF öffnen | Open a process report as PDF. |
| Lokale PDF-Dateien auswählen | Choose a PDF file on the computer. |
| Prozessprotokoll-Vorlagen bearbeiten | Configure process-report template layout and content. |
| Editor verwenden | Work in the design editor. |
| Projekte öffnen und neu anlegen | Load or create a project. |
| Projekte speichern | Save project changes. |
| Projekteinstellungen ändern | Change project-wide options. |
| SPS-Tabelle bearbeiten | Edit communication symbols and their connection/address data. |
| Lager und Bestände ansehen | View warehouse locations and stock quantities. |
| Lagerbestand ein-, aus- und umlagern | Book stock receipts, withdrawals and relocations. |
| RBG-Fahrauftrag mit verfügbarer Menge senden | Submit a storage/retrieval-machine movement order with available quantity. |
| RBG-Fahrauftrag abbrechen und Havarie klären | Cancel such an order and handle recovery incidents. |
| Chargendaten und MHD korrigieren | Correct batch data and best-before dates. |
| Lager-Materialstamm bearbeiten | Edit warehouse material master data. |
| Lager-Datenbankstruktur bearbeiten | Edit the warehouse database structure. |
| Lager-Vorgangshistorie einsehen | Review past warehouse operations. |
| Benutzerkonten verwalten | Create and edit accounts, assign roles and change passwords. |
| Rollen und Berechtigungen verwalten | Create and edit roles and grant individual permissions. |
7. Create the Schichtbeobachter role
Click New, name the role Schichtbeobachter and select only:
- Open Play mode
- Open pages and detail windows
- Create notes
Save. The list now shows three permissions. This role can write notes but cannot change process values or mark notes as read.
8. Assign a second account
Open Manage users → New. Enter username beobachter, display name Schichtbeobachter, role Schichtbeobachter, enabled account and your own password of at least 10 characters. Save the account and project as an authorized user.
Sign Rainer out in test mode and sign in as beobachter. Display name and role name happen to match here, but are separate fields.
9. Test permissions
Starting with version 2.61.509, both note buttons visibly reflect permissions. Their appearance updates when users sign in or out.
| Session | New note | Read / open | Process operation |
|---|---|---|---|
| Signed out | blocked | blocked | blocked |
| Schichtbeobachter | allowed | blocked | blocked |
The first image shows the signed-out state. Sign in as beobachter and create the note “Test der Rolle Schichtbeobachter”. Its author is filled from the signed-in account. After saving, the open count is 1. New note remains enabled; Read / open and the process enable control remain disabled. The screenshots demonstrate this behavior.
Missing operation permission is not a communication fault. Process values may still be displayed. An administrator with the relevant permissions can operate the corresponding controls for comparison.
10. Edit accounts, change passwords and disable accounts
- With account-management permission, open Manage users and select the existing account.
- Change its username, display name or role. Usernames must remain unique.
- To change its password, enter a new one of at least 10 characters; otherwise leave that field empty.
- Uncheck Account enabled to disable it, or check it again to reactivate it.
- Save and save the project changes.
Disabling retains the account but prevents login. Delete removes the selected account. The currently signed-in account cannot be disabled or deleted. At least one active account must retain permission to manage users and roles.
These management procedures are described from the implementation. The screenshot sequence tests login and role permissions, not password changes, disabling or deletion.
11. Change role permissions or delete roles
Edit and save a role when its responsibilities change. All assigned accounts are affected. If only one person needs different access, create a suitable additional role and assign it to that account.
A role cannot be deleted while an account uses it; reassign affected accounts first. At least one role must remain. The program also protects the remaining active user/role management account from losing the permissions needed to administer access.
12. Automatic logout and saving
In Settings → Automatic logout, 0 disables the feature. Values 1 through 1440 specify minutes without registered user activity before logout in test mode. The example uses 0; automatic timeout was not demonstrated.
Save project changes with an authorized account. The practice role cannot save projects or use the editor. Sign in as Rainer again to continue editing.
Related guides: notepad and keyboard shortcuts.
13. Manage accounts and roles during runtime
Management is also available directly in Play mode, without switching to the editor. Access depends on Manage user accounts and Manage roles and permissions, not merely the role name Administrator.
- Sign in as Rainer or another account with the required management permissions.
- Open Benutzer / Rollen (Users / Roles) in the header. If the project already has a dedicated management button, use that button; the extra header button is then hidden.
- With account-management permission, this opens user management. Use Manage roles to access roles when permitted. If the account only has role-management permission, the entry opens role management directly.
- Select an account or role, make the change and click Save.
- Check the status message about saving the project file.
Permissions and affected controls update in the running application. Role changes affect all assigned accounts. Runtime management attempts to persist changes directly to the project file. A message that the change was applied but the file could not be saved means the current change is effective but has not been saved permanently.
Protection rules still apply: the signed-in account cannot be disabled or deleted, and at least one active account must retain user and role management access. The image shows the runtime entry while an administrator is signed in. Editing within runtime management is described from the implementation.