Skip to main content

Roles and presets

By default every Station user is an admin who sees and can change everything. Presets restrict that: a preset is a bundle of pages and actions matching a job, and each preset comes in three levels, Administrator, Supervisor and Operator. Use them to give a control-room operator the live view without the ability to edit watchlists, or an analyst the history without the camera configuration. Roles are enforced in Station only; the APIs on ports 8098 and 8097 are protected separately (see Authentication).

Presets​

The Security preset is for live operation. Its start page is http://localhost:8000/security.

Security AdminSecurity SupervisorSecurity Operator
Live monitoring (camera preview and feed settings, event detail)yesyesyes
History and event detailyesyesno
Watchlistsyesyesno
Settings: Station tabyesyesyes
Camerasyesnono
Settings: platform tabyesnono

The Investigation preset is for analysts working with stored data. Its start page is http://localhost:8000/investigation/.

Investigation AdminInvestigation SupervisorInvestigation Operator
Live monitoringnonono
History and event detailyesyesyes
Watchlistsyesyesno
Settings: Station tabyesyesyes
Camerasnonono
Settings: platform tabyesnono

Force one role for everybody​

The simplest deployment gives all users the same role. In .env.station, uncomment FORCED_ROLE_NAME_0 and set it to the role key:

FORCED_ROLE_NAME_0=/security_operator

Then apply the change:

docker compose up -d station

The role keys are the values of the ROLE_KEY_* settings in the same file: /admin, /security_admin, /security_supervisor, /security_operator, /investigation_admin, /investigation_supervisor and /investigation_operator. Leave any other commented keys in that block as they are.

Roles per user​

With an identity provider in front of Station, roles come from the user's token instead. ROLES_CLAIM_NAME names the claim that carries the user's groups (the group mapper name in Keycloak, cognito:groups in Cognito), and each ROLE_KEY_* setting maps a Station role to the group value expected in that claim:

ROLES_CLAIM_NAME=sf_roles
ROLE_KEY_ADMIN=/admin
ROLE_KEY_SECURITY_ADMIN=/security_admin
ROLE_KEY_SECURITY_SUPERVISOR=/security_supervisor
ROLE_KEY_SECURITY_OPERATOR=/security_operator
ROLE_KEY_INVESTIGATION_ADMIN=/investigation_admin
ROLE_KEY_INVESTIGATION_SUPERVISOR=/investigation_supervisor
ROLE_KEY_INVESTIGATION_OPERATOR=/investigation_operator

Create matching groups in the identity provider, assign users to them, and do not set FORCED_ROLE_NAME_0. Setting up Keycloak or Auth0 with Station is described in the authentication guide; the related .env.station keys are listed in Configuration.