Documentation

Platform · Guides

Machine access

Limit specific people to specific machines for monitoring and remote access — one at a time or in bulk by location — without cutting off their access by mistake.

By default, anyone who can use Monitoring can see every machine in your company, and anyone allowed to use Remote Access can reach any of them. Machine Access narrows that down person by person, for example so a contractor only sees the machines at the site they support.

You'll find it under Admin → Machine Access, described as "Control which users can monitor and remote into which machines. Assign in bulk by location or selection." You need the Assets → manage permission to use it.

What a restriction does

When a person is restricted:

  • In Monitoring, they see only the machines assigned to them.
  • In Remote Access, where it's enabled for your organization, they can only reach the machines assigned to them.
  • A machine they aren't assigned behaves as if it doesn't exist for them. They get "not found" rather than "forbidden", so the restriction doesn't reveal which other machines exist.

When a person is not restricted, they keep access to all company machines. That's the default for everyone.

Administrators are never restricted. They always have access to every machine, whatever this page shows.

Machine Access decides which machines someone can reach. Whether they can use Monitoring or Remote Access at all comes from their roles, so a person needs both.

Reading the page

The Users list on the left shows everyone in your organization except disabled accounts, each with one of two badges:

BadgeMeaning
full · all machinesNot restricted: they can reach every company machine
restricted · N assignedRestricted to the N machines assigned to them

Select a person to see their machines on the right. Each machine shows its name, whether it's online or offline, its location, and its type. A checkmark means it's assigned to that person.

Restrict someone to specific machines

Every change applies immediately

There's no Save button. Ticking a box, using a bulk button, or turning on the restriction takes effect the moment you do it. If you turn on the restriction before assigning any machines, the person can't reach any machine until you do. Assign first, then restrict.

Select the person

In the Users list, select them. If they're not restricted yet, you'll see "This user currently has access to all company machines."

Narrow the machine list

Use the Location dropdown, set to All locations by default, and the Search name / serial box to show just the machines you want to assign.

Assign the machines

Tick individual machines, or select Grant all matching (N) to assign every machine that matches your current filter. The number shows how many that is.

Turn on the restriction

Tick Restrict to assigned machines only. The person is now limited to the machines you assigned, and their badge changes to restricted.

Check the result

Confirm their badge shows restricted and the number of machines you expect.

Change or remove access

  • Add machines: tick more machines, or filter and select Grant all matching (N).
  • Remove machines: untick them, or filter and select Revoke all matching. A restricted person loses access to those machines right away.
  • Lift the restriction entirely: untick Restrict to assigned machines only. The person goes back to seeing all company machines, and their list of assigned machines is kept in case you restrict them again.

Bulk changes across many machines

The machine list shows up to 500 machines at a time. When more machines match your filter, you'll see "Showing … of …. Use 'Grant/Revoke all matching' to cover every machine in this filter." The bulk buttons always act on every machine matching your filter, not just the ones on screen, so check the Location and search you've set before you use them.

A reliable pattern for sites:

  1. Set Location to the site.
  2. Leave the search box empty.
  3. Select Grant all matching (N), then turn on the restriction.

Common questions

The person still sees every machine. Check that Restrict to assigned machines only is ticked for them, and that they aren't an Administrator. Administrators are never restricted.

The person sees no machines at all. They're restricted and have no machines assigned, or none that match what they're looking at. Assign machines, or lift the restriction.

Do API keys follow these restrictions? No. API keys belong to your organization rather than a person, so machine access doesn't apply to them. See Platform overview.

Need a hand with Platform?Talk to our team →