Overview

Admin is the platform-wide control surface for managing identity, access, and organizational structure across Lens, Weave, and Maskbits. It groups four management areas — User, Roles, Group, and Organization — under a single Admin tab in the Main Navigation Bar.

Admin is accessed from Admin in the Main Navigation Bar and is restricted to users holding the Account Admin role. The four management areas are interdependent: roles defined in Roles Management are consumed by User Management and Group Management; users created in User Management populate group membership; organizations defined in Organization Management scope the visibility of every other Admin object.

When to use it

  • A new user must be onboarded with the correct access to Lens, Weave, or Maskbits.
  • A team’s access pattern is changing and roles or group memberships need to be updated.
  • A new department, division, or team is being modeled in the platform.
  • A custom role is required to express access combinations the system roles don’t cover.

Management areas

User ManagementCreate, edit, and deactivate user accounts; assign roles directly to users.Users, direct role assignments
Roles ManagementDefine custom roles bundling menu access, data source visibility, dataset and field restrictions, report access, and security tags.Roles
Group ManagementOrganize users into groups (and subgroups) for team-level role and permission management.Groups, subgroups, group-to-role assignments
Organization ManagementConfigure organizational structure and platform-wide parameters that scope all other Admin objects.Organizations, platform parameters

Common page pattern

All four Admin sub-tabs follow a consistent layout. Recognizing the pattern shortens the learning curve for new Account Admins.

List viewEach sub-tab opens to a list of existing objects (users, roles, groups, or organizations) with paginated browsing.
Search barFilters the list by name. Behavior is consistent across sub-tabs.
Add iconBottom-right of the screen. Opens a creation pop-up specific to the sub-tab.
Settings columnPer-row actions for edit and delete. Roles Management adds a Security action for tag assignment.

Key behaviors

Account Admin gating. The Admin tab is exposed only to users with the Account Admin system role. Designer and Viewer roles cannot reach Admin surfaces, regardless of any custom role configuration.

Cross-area dependencies. Admin objects depend on each other in a fixed order: organizations scope users, groups, and roles; roles must exist before they can be assigned in User Management or Group Management; users must exist before they can be added to groups. When bootstrapping a new tenant, configure organizations first, then roles, then users, then groups.

Additive permission model. Every permission assignment in Admin is additive. A user’s effective access is the union of direct role assignments (User Management), roles inherited from group membership (Group Management), and any roles inherited from parent groups. Removing a permission from one source does not revoke it for users who hold it through another.

Security tags are not configured under Admin. Security tags are created in Lens by Lens Designers and assigned directly to roles in Roles Management to scope role-level data visibility. The Admin tab does not contain a tag configuration surface; the work is split deliberately so tag definitions live with the product where Reports — the primary objects tags govern — are designed.