By default, anyone who can use Monitoring can see every machine in your company, and anyone allowed to use Remote Access can reach any of them. Machine Access narrows that down person by person, for example so a contractor only sees the machines at the site they support.
You'll find it under Admin → Machine Access, described as "Control which users can monitor and remote into which machines. Assign in bulk by location or selection." You need the Assets → manage permission to use it.
What a restriction does
When a person is restricted:
- In Monitoring, they see only the machines assigned to them.
- In Remote Access, where it's enabled for your organization, they can only reach the machines assigned to them.
- A machine they aren't assigned behaves as if it doesn't exist for them. They get "not found" rather than "forbidden", so the restriction doesn't reveal which other machines exist.
When a person is not restricted, they keep access to all company machines. That's the default for everyone.
Administrators are never restricted. They always have access to every machine, whatever this page shows.
Machine Access decides which machines someone can reach. Whether they can use Monitoring or Remote Access at all comes from their roles, so a person needs both.
Reading the page
The Users list on the left shows everyone in your organization except disabled accounts, each with one of two badges:
| Badge | Meaning |
|---|---|
| full · all machines | Not restricted: they can reach every company machine |
| restricted · N assigned | Restricted to the N machines assigned to them |
Select a person to see their machines on the right. Each machine shows its name, whether it's online or offline, its location, and its type. A checkmark means it's assigned to that person.
Restrict someone to specific machines
Every change applies immediately
There's no Save button. Ticking a box, using a bulk button, or turning on the restriction takes effect the moment you do it. If you turn on the restriction before assigning any machines, the person can't reach any machine until you do. Assign first, then restrict.
Select the person
In the Users list, select them. If they're not restricted yet, you'll see "This user currently has access to all company machines."
Narrow the machine list
Use the Location dropdown, set to All locations by default, and the Search name / serial box to show just the machines you want to assign.
Assign the machines
Tick individual machines, or select Grant all matching (N) to assign every machine that matches your current filter. The number shows how many that is.
Turn on the restriction
Tick Restrict to assigned machines only. The person is now limited to the machines you assigned, and their badge changes to restricted.
Check the result
Confirm their badge shows restricted and the number of machines you expect.
Change or remove access
- Add machines: tick more machines, or filter and select Grant all matching (N).
- Remove machines: untick them, or filter and select Revoke all matching. A restricted person loses access to those machines right away.
- Lift the restriction entirely: untick Restrict to assigned machines only. The person goes back to seeing all company machines, and their list of assigned machines is kept in case you restrict them again.
Bulk changes across many machines
The machine list shows up to 500 machines at a time. When more machines match your filter, you'll see "Showing … of …. Use 'Grant/Revoke all matching' to cover every machine in this filter." The bulk buttons always act on every machine matching your filter, not just the ones on screen, so check the Location and search you've set before you use them.
A reliable pattern for sites:
- Set Location to the site.
- Leave the search box empty.
- Select Grant all matching (N), then turn on the restriction.
Common questions
The person still sees every machine. Check that Restrict to assigned machines only is ticked for them, and that they aren't an Administrator. Administrators are never restricted.
The person sees no machines at all. They're restricted and have no machines assigned, or none that match what they're looking at. Assign machines, or lift the restriction.
Do API keys follow these restrictions? No. API keys belong to your organization rather than a person, so machine access doesn't apply to them. See Platform overview.
