Skip to main content

Defining Permissions

You need to set up Permissions to define which types of resources your Targets will be allowed or denied access to.

The resources available to grant permission depend on the Target you select, and the rules available depend on the resource selected. For more information, see Defining Targets.

Permissions editor showing Targets and Permissions

Adding resources and how rules are applied​

You can add as many resources as needed. An OR operation is applied between permissions: as you add more permissions, more resources will be included in the verification process.

warning

Denial permissions will override any permissions granting access to the same resource.

AI​

The AI resource controls the AI Chat in TagoRUN for Run user Targets. It has no individual resources to match, so its permission always applies to the whole feature. Its rules are:

RuleWhat it grants
AccessThe user sees and can use the AI chat. Required for every other rule.
Read device dataThe assistant can list devices and read their data on the user's behalf.
Read entity dataThe assistant can read entity schemas and data on the user's behalf.
Read dashboardsThe assistant can list dashboards on the user's behalf.
Read usersThe assistant can list TagoRUN users on the user's behalf.

The read rules say what kind of resource the assistant may read. Which resources it may read is decided by the AI access rule on the resource permission itself.

AI access on resources​

Device, Entity, Dashboard, Run User, and SQL Query permissions for Run user Targets have an AI access rule next to their existing rules. It marks the matched resources as readable by the assistant for the targeted users, and matches by ID, tag, or Any like any other rule.

AI access is separate from the rules the portal uses. Dashboard access on a device lets the user see it in dashboards and says nothing about the assistant. Grant both when the user should have both.

A complete grant to read device data therefore needs two permissions: AI with Access and Read device data, and Device with AI access on the devices in question. A grant missing either half reads nothing.

SQL Queries​

The SQL Query resource grants actions on TagoSQL stored queries. Run user Targets can be granted Access (list and view queries), Execute (run them), and AI access (let the AI chat discover and run them on the user's behalf); analysis Targets can additionally be granted Create, Edit, and Delete.

warning

Granting execution of a query grants its full result set. The policy decides which queries a caller may run, never which rows or columns come back.

To scope what each Run user sees within a single query, see Session Context. The same scoping applies when the AI chat runs the query; see Restrict AI results with a saved TagoSQL query.