Dashboard
Recent Activity
Activity Log
Devices
Loading devices...
Device
| Name | PID | CPU % | CPU Time | Memory |
|---|
| Name | Display Name | Status | Startup | Actions |
|---|
| Time | Level | Source | ID | Message |
|---|
| Name | Type | Data |
|---|
Device Groups
Loading groups...
Pending Requests
Organization
Pending Invitations
Deploy
Audit Logs
Geo Access
Pending Requests
Active Allowlists
Each allowed IP can stay active up to 30 days. Revoke any time.
Account
Account Details
Change Password
Two-Factor Authentication (MFA)
Add an extra layer of security to your account with an authenticator app.
Scan this QR code with your authenticator app:
Save these recovery codes now! They won't be shown again.
Each code can be used once to sign in if you lose your authenticator app.
MFA is enabled
Two-factor authentication is required for all accounts and cannot be disabled.
Platform Administration
Platform Overview
All Organizations
All Devices
Platform Users
About: Roles & Permissions
How access works
Every account has up to three layers of access. They are independent of each other:
- Platform role: for ShomerIT staff. It applies across every customer organization. Most accounts are plain User (no platform access).
- Organization role: Owner, Admin, Manager, Member or Restricted. It applies only inside that person's own organization.
- Per-service level: None, View or Manage for each service (Internet Control, DNS Filter, EDR). It's a ceiling on top of the organization role and never adds access the role doesn't already allow.
Platform roles (ShomerIT staff)
| Role | Stored as | Can | Cannot |
|---|---|---|---|
| SuperAdmin | Admin | Everything on the platform: every org, user, device, group, audit log and geo request. Only SuperAdmins can create or delete users, change platform roles, delete orgs, see enrollment tokens, fully control or delete any device, and approve, deny or revoke geo access. Geo request emails go only to SuperAdmins. | Demote the last remaining SuperAdmin. That's blocked so the platform always has one. |
| Support | Support | Read-only view of every org, user, device and group, the audit log (including the geo-block summary), and geo requests and allowlists. | Change anything. Can't see enrollment tokens, run RMM tools, approve devices or geo requests, or manage users. |
| Billing | Billing | View all orgs and platform stats. Change an org's plan and maximum devices. | Rename or delete orgs, see users, devices, groups, the audit log or geo requests, or touch any device. |
| Engineer | Engineer | View all orgs, devices and groups, and the audit log. Run RMM diagnostics on any device (terminal, processes, services, registry, files). Approve unclaimed devices and assign them to an org. | Manage users or roles, change customer settings on a device (blocking toggle, timers, schedules, groups), clear local passwords or delete devices, see enrollment tokens, or view or approve geo requests. |
| User | User | Nothing at the platform level. They have only what their organization role allows. | See the Admin section, Audit, or other organizations. |
Why "Admin"? SuperAdmin is saved in the database as the old value Admin, so existing platform admins became SuperAdmins with no data change. On the Platform Users list, Make Admin and Revoke Admin mean grant or remove SuperAdmin. A Platform Admin (SuperAdmin) isn't the same as an Org Admin (an organization role, below).
Role changes take effect the next time that person signs in or their session refreshes.
Platform permission matrix
| Permission | What it allows | SuperAdmin | Support | Billing | Engineer |
|---|---|---|---|---|---|
| OrgsView | List and view all orgs and platform stats (opens this Admin section) | ✓ | ✓ | ✓ | ✓ |
| OrgSecretsView | See org enrollment tokens | ✓ | |||
| OrgsBillingEdit | Change an org's plan and maximum devices | ✓ | ✓ | ||
| OrgsEdit | Change an org's name or description | ✓ | |||
| OrgsDelete | Delete an org | ✓ | |||
| UsersView | List all users | ✓ | ✓ | ||
| UsersManage | Create or delete users, change platform roles | ✓ | |||
| DevicesView | See every device, including unclaimed ones (read-only) | ✓ | ✓ | ✓ | |
| DevicesDiagnostics | RMM tools on any device (terminal, processes, registry, files) | ✓ | ✓ | ||
| DevicesApprove | Approve unclaimed devices or assign them to an org | ✓ | ✓ | ||
| DevicesControl | Full control of any device (blocking, timers, schedules, groups) | ✓ | |||
| DevicesAdminister | Clear local password or delete any device | ✓ | |||
| GroupsView | See all device groups | ✓ | ✓ | ✓ | |
| GroupsManage | Create, edit or delete groups in any org | ✓ | |||
| AuditView | Audit log, CSV export and geo-block summary | ✓ | ✓ | ✓ | |
| GeoView | See geo access requests and allowlists | ✓ | ✓ | ||
| GeoManage | Approve, deny or revoke geo access | ✓ | |||
| ServicePermissionsManage | Set per-service levels for members of any org | ✓ |
Organization roles (inside a customer's org)
| What | Owner | Admin | Manager | Member | Restricted |
|---|---|---|---|---|---|
| See devices | All | All | All | Assigned only | Assigned only |
| Control devices (blocking, timers, schedules) | All | All | Assigned with control | Assigned with control | No, must send a request |
| RMM tools (terminal, processes, registry, files) | ✓ | ✓ | Only with an RMM grant | Only with an RMM grant | |
| Delete a device | ✓ | ✓ | ✓ | ||
| Clear a device's local password | ✓ | ✓ | |||
| Approve access requests | ✓ | ✓ | ✓ | ||
| Grant device or group access to members | ✓ | ✓ | |||
| Create, edit or delete groups | ✓ | ✓ | |||
| Invite members | Any role except Owner | As Member only | |||
| Remove members | Anyone but the Owner | Managers, Members, Restricted | |||
| Change member roles / transfer ownership | ✓ | ||||
| Set per-service levels for members | ✓ | ✓ | |||
| Deploy tab (view enrollment token) | ✓ | ✓ | |||
| Regenerate enrollment token | ✓ | ||||
| Edit org name or description | ✓ | ✓ | |||
| Approve geo requests routed to the org | ✓ | ✓ | |||
| Manage billing / subscription | ✓ | ||||
| Leave the org | Transfer ownership first | ✓ | ✓ | ✓ | ✓ |
"Assigned" means the member was given a device directly or through a group. Each grant says whether they may control the device and whether they may use RMM tools. The most generous grant wins. Only a SuperAdmin can delete an organization. A user with no organization has full control of their own devices.
Per-service permissions
Each organization member has a level for each service:
- None: the service is hidden. For Internet Control, the member sees no org devices at all.
- View: they can see what their role allows, but can't control, run RMM or delete.
- Manage: normal access for their role, which is the same as before Phase 0.
| Org role | Internet Control default / max | DNS Filter default / max | EDR default / max |
|---|---|---|---|
| Owner | Manage (fixed) | Manage (fixed) | Manage (fixed) |
| Admin | Manage (fixed) | Manage (fixed) | Manage (fixed) |
| Manager | Manage / Manage | Manage / Manage | View / View |
| Member | Manage / Manage | View / Manage | None / View |
| Restricted | View / View | View / View | None / None |
- The default applies when nobody has set an override. Defaults match how things worked before, so nobody's access changed.
- An org Owner or Admin (or a SuperAdmin) can set an override under Organization → member card → Services. It can't go above the role's max. Resetting it returns the member to the default. Every change is written to the audit log as
ServicePermissionChanged. - Overrides for an org are deleted automatically when the member leaves that org.
- Only Internet Control is enforced today. DNS Filter and EDR levels are saved and shown but don't restrict anything until those services ship.
Good to know
- Geo-block audit rollup: repeated geo-blocked visits are counted per day (by country and IP) instead of one audit row each. Use Audit → Geo-block summary to see the counts, or tick "Show individual geo-block events". Nothing is deleted. Anyone with AuditView (SuperAdmin, Support, Engineer) can see it.
- Not built yet: a reseller/MSP tier and users who belong to more than one organization. A membership table is already kept in sync for that later phase, but nothing uses it for access yet.