Roles and presets
By default every Station user is an admin who sees and can change everything. Presets restrict that: a preset is a bundle of pages and actions matching a job, and each preset comes in three levels, Administrator, Supervisor and Operator. Use them to give a control-room operator the live view without the ability to edit watchlists, or an analyst the history without the camera configuration. Roles are enforced in Station only; the APIs on ports 8098 and 8097 are protected separately (see Authentication).
Presets
The Security preset is for live operation. Its start page is http://localhost:8000/security.
| Security Admin | Security Supervisor | Security Operator | |
|---|---|---|---|
| Live monitoring (camera preview and feed settings, event detail) | yes | yes | yes |
| History and event detail | yes | yes | no |
| Watchlists | yes | yes | no |
| Settings: Station tab | yes | yes | yes |
| Cameras | yes | no | no |
| Settings: platform tab | yes | no | no |
The Investigation preset is for analysts working with stored data. Its start page is http://localhost:8000/investigation/.
| Investigation Admin | Investigation Supervisor | Investigation Operator | |
|---|---|---|---|
| Live monitoring | no | no | no |
| History and event detail | yes | yes | yes |
| Watchlists | yes | yes | no |
| Settings: Station tab | yes | yes | yes |
| Cameras | no | no | no |
| Settings: platform tab | yes | no | no |
Force one role for everybody
The simplest deployment gives all users the same role. In .env.station, uncomment FORCED_ROLE_NAME_0 and set it to the role key:
FORCED_ROLE_NAME_0=/security_operator
Then apply the change:
docker compose up -d station
The role keys are the values of the ROLE_KEY_* settings in the same file: /admin, /security_admin, /security_supervisor, /security_operator, /investigation_admin, /investigation_supervisor and /investigation_operator. Leave any other commented keys in that block as they are.
Roles per user
With an identity provider in front of Station, roles come from the user's token instead. ROLES_CLAIM_NAME names the claim that carries the user's groups (the group mapper name in Keycloak, cognito:groups in Cognito), and each ROLE_KEY_* setting maps a Station role to the group value expected in that claim:
ROLES_CLAIM_NAME=sf_roles
ROLE_KEY_ADMIN=/admin
ROLE_KEY_SECURITY_ADMIN=/security_admin
ROLE_KEY_SECURITY_SUPERVISOR=/security_supervisor
ROLE_KEY_SECURITY_OPERATOR=/security_operator
ROLE_KEY_INVESTIGATION_ADMIN=/investigation_admin
ROLE_KEY_INVESTIGATION_SUPERVISOR=/investigation_supervisor
ROLE_KEY_INVESTIGATION_OPERATOR=/investigation_operator
Create matching groups in the identity provider, assign users to them, and do not set FORCED_ROLE_NAME_0. Setting up Keycloak or Auth0 with Station is described in the authentication guide; the related .env.station keys are listed in Configuration.