Skip to content

Understanding SOC Manager User Types

Overview

SOC ManagerĀ® provides four User types that determine what a User can do and the portion of the system they are permitted to manage.

The four User types are:

  • Global Admin User
  • User
  • Tenant Admin User
  • Tenant User

SOC Manager also uses Sites to control the scope of a User's access.

An Easy Way to Remember

User Type controls what a User can do.

Site assignments control where the User can do it.

Global Admin Users

A Global Admin User has unrestricted access to all SOC Manager functions.

Global Admin Users are responsible for overall system administration and can create:

  • Users
  • Tenants
  • Tenant Admin Users
  • Tenant Users

Global Admin Users can also determine which Sites are available to a Tenant.

Because Global Admin Users have unrestricted access to SOC Manager, this User Type should only be assigned to individuals who require full administrative control.

Users

A User performs normal SOC Manager access management functions.

Users can be assigned to one or more Sites. These Site assignments determine which portions of the locking system are available to the User.

Depending on their Site assignments, Users can perform functions such as:

  • Issue Phone Keys and key fobs
  • Add and manage Persons
  • Revoke credentials
  • Blacklist keys
  • Request audit information
  • Work with Access Rights available to them

For example, a User responsible for a single location may be assigned to one Site, while a regional User may be assigned to several Sites.

Tenant Administration

A Tenant allows an organization to delegate access management to another organization.

This is useful when an organization wants to give another company access to selected Sites but does not want to be responsible for managing that company's employees and credentials.

Example: Tower Company and Subcontractors

Consider a tower company that uses multiple subcontractors.

The tower company needs to control which tower Sites each subcontractor can access, but does not want to manage every subcontractor employee.

A Global Admin User can create a separate Tenant for the subcontractor and assign the appropriate Sites to that Tenant.

Once the Tenant is established, the subcontractor becomes responsible for managing its own employees and their access.

The Tenant can:

  1. Create its own Tenant Users.
  2. Add its employees as Persons.
  3. Create the Access Rights needed by its employees.
  4. Issue and manage credentials for its employees.

Tenant Access Is Limited

A Tenant can only manage access to Sites that have been assigned to the Tenant by a Global Admin User.

The Tenant cannot give itself access to additional Sites.

This allows the primary organization to retain control over where the Tenant can operate, while allowing the Tenant to control who within its organization receives access.

Tenant Admin Users

A Tenant Admin User is responsible for administering SOC ManagerĀ® within their Tenant.

Tenant Admin Users can create and manage:

  • Other Tenant Admin Users within their own Tenant
  • Tenant Users within their own Tenant
  • Persons within their own Tenant

Tenant Admin Users can also manage Access Rights and credentials within the Sites that have been made available to their Tenant.

For example, a subcontractor's Tenant Admin User can create additional Tenant Admin Users for their organization, create Tenant Users, add employees as Persons, establish the appropriate Access Rights, and issue credentials as required.

Tenant Administration Is Restricted to the Tenant

A Tenant Admin User can only administer Users, Persons, Access Rights, and other resources within their own Tenant.

Tenant Admin Users cannot administer another Tenant or expand the Sites available to their Tenant.

Tenant Users

A Tenant User performs normal SOC Manager functions within their Tenant.

Tenant Users operate within the Sites and access structure established for their Tenant.

Unlike Tenant Admin Users, Tenant Users cannot create or administer other Tenant Users.

Their access is limited to the resources available through their Tenant and their applicable Site assignments.

Comparing User Types

User Type Scope Primary Purpose
Global Admin User Entire SOC Manager system Unrestricted system administration. Creates Users and Tenants and establishes Tenant access.
User Assigned Sites Day-to-day access management
Tenant Admin User Own Tenant and permitted Sites Administers the Tenant. Can create other Tenant Admin Users and Tenant Users within their Tenant.
Tenant User Own Tenant and assigned Sites Day-to-day access management within the Tenant

User Types and Persons

SOC Manager Users and Persons serve different purposes.

A User is an individual who can log in to SOC Manager and perform management functions.

A Person is an individual who can receive an iLOQ credential, such as a Phone Key or key fob.

An individual may be both a User and a Person, but the records serve different purposes.

For more information, see Understanding Persons and Users.

  • Understanding Persons and Users
  • Managing Users
  • Managing Tenants
  • Mapping Users to Sites
  • Managing Persons
  • Managing Access Rights