Roles and Permissions for Access Control
Learn about roles that define a user’s access control permissions in Verkada Command
As of November 14, 2024, access control permissions have changed. Users with legacy access control roles will maintain their permissions until they are updated to the current roles detailed in this article. See Legacy Access Control Roles for more information.
This article describes the set of roles and associated permissions for Verkada Access Control. For more information on roles and permissions for other Verkada product lines, see Roles and Permissions for Command.
Permissions considerations
Subsites inherit permissions from all parent sites, including the ultimate parent.
Users can belong to multiple groups. When roles conflict, the user receives the highest role granted directly or through any group.
Group-assigned roles can be manually upgraded but not downgraded. Remove the user from the group with the higher role to downgrade their access.
Permissions for access control are set at both the organizational level and the site level. There are two org-level roles and one site-level role that define a user’s permissions to view and manage access control permissions and devices:
Access control roles are granted to users independently of one another.
Organization-level roles
Access System roles grant permissions to manage organization-wide access control settings for all sites.
Create and edit door schedules, door exceptions, and access exceptions
✅
✅
Create and edit badge templates
✅
Receive access Site Admin privileges over all sites
✅
Manage organization-wide access control settings
✅
Create and edit buildings and floors
✅
Grant Access System roles to other users
✅
Role overview
User management roles
Access User Management roles grant permissions to manage access users, credentials, and access groups.
Manage user credentials and print user badges
✅
✅
✅
Suspend user access
✅
✅
✅
Create and edit users
✅
✅
Edit access group membership
✅
✅
Create access groups
✅
Grant Access User roles to other users
✅
Create and edit Badge Templates
✅
Role overview
Site roles
Access Site roles grant permissions to manage access control settings, devices, and door access. Site-level roles can be assigned to individual users or groups and apply only to a specific site. Subsites inherit permissions from parent sites above them in the hierarchy.
View site's doors, inputs/outputs, and events
✅
✅
✅
✅
Remote unlock site's doors
Only doors where granted access
✅
✅
Manage visits for site
✅
✅
✅
Apply door schedules, door exceptions, and overrides to site's doors
✅
✅
Create and edit access levels and access exceptions for site
✅
✅
Create and edit visit access templates for site
✅
✅
Create and edit roll call templates for site
✅
✅
View areas and clear anti-passback violations for site
✅
✅
Manage lockdowns for site
✅
Manage area settings for site
✅
Manage doors, inputs/outputs, and access controllers for site
✅
Manage site's access control settings
✅
Grant Access Site roles to other users
✅
Role overview
Set permissions
You can set site permissions for existing users and groups by managing user roles or groups.
Common access control permission configurations
Scenario
Role Configuration
User needs total control over all access control system settings, devices, and users. For example, a Security Director.
User needs to be able to create and edit door schedules or exceptions applied to doors in one or more sites.
For example, a security team member.
User is responsible for onboarding new users by printing badges and adding them to access groups. For example, an HR staff member.
User is only responsible for adding credential info and printing badges for new users, such as SCIM-synced users. For example, an HR staff member.
User needs to manage all site-specific access control settings but should not be able to edit user or access group settings (granted by User Management Roles). For example, an office General Manager.
User needs to manage which access groups have access to doors for a particular site but should not be able to edit other access control settings for the site. For example, an office facilities staff member.
User needs to provide temporary access for visitors. For example, a front desk receptionist.
User only needs to view and unlock certain doors for a particular site. For example, a front desk receptionist.
Last updated
Was this helpful?

