- Home
- Blog
- EDGEBIC How-To
- How to Create a Role in EDGEBIC
To create a role in EDGEBIC by User Solutions you open the Roles and Permissions tab, click New role, name it, tick the permissions it should grant in the tree, and save. A role is the unit of access in EDGEBIC: you never hand rights to a person directly, you build a role and attach it. Getting the tick list right is the whole job.
This is the narrow task of building one role. For how users, roles, and permissions relate, read users and roles explained, and for the end-to-end setup see how to set up users and roles.
Before You Start
- You are signed in with an administrator account, or one whose role includes the security permissions. Only such a user sees the Security tab.
- You have decided what this role is for, in one sentence: "Planner who schedules but does no admin," or "Supervisor who logs actuals but cannot reschedule." That sentence drives every tick.
- You know the least-privilege principle: start from nothing and add permissions only where the job genuinely needs them. Clawing back access later is harder than granting it when someone hits a wall.
Creating the Role
-
Open the Settings tab and click the 🔒 Security tab, then the Roles & Permissions sub-tab.
-
Click New role. The role dialog opens.
-
Enter a Role name, such as
Shop Floor Supervisor, and a short Description so the next administrator knows what it is for. -
Work through the Permissions tree. Permissions are grouped by area, then by module:
Area What it covers Sales Quotes, customers Production Manufacturing orders, scheduling, actuals, routings Master Data Products, work centers, shifts, holidays, departments Insights Reports and dashboards Data Import masks and runs Settings Configuration, and the destructive Clear Data tool Security User and role management -
Tick the individual permissions this role should grant. Each group has its own Select all and Clear buttons, and there are Select all and Clear all buttons at the top for the whole tree. For a Planner, that typically means the Production and Master Data permissions plus Insights, but nothing under Security and no Clear Data under Settings.
-
Click the save button. The role now exists.
-
Assign it: switch to the Users sub-tab, Edit a user, and tick the new role in their Roles group.
What Changes When You Save
Saving writes the role and its permission set. Because rights are the union of a user's roles, the moment you attach the role, its permissions are in play.
| Surface | Effect |
|---|---|
| Roles & Permissions grid | The role appears with its permission count |
| Users you assign it to | Gain its permissions at their next sign-in |
| Users already holding it, later edits | Permission edits reach them; those signed in on the same machine pick up changes immediately, others at next sign-in |
| Buttons and tabs | Anything a user's roles do not permit stays hidden or is refused |
| Security audit trail | A permanent role-change entry lands in the database |
Permissions in EDGEBIC are granted through roles only. There is no per-user grant-or-deny override screen, so if one person needs a slightly different set, the answer is a narrower role, not an exception on their account.
How to Check It Worked
Assign the role to a test user, sign in as that user, and walk the tabs. Every capability you ticked should be reachable, and every one you left unticked should be hidden or refused. A Supervisor role, for instance, should show the schedule and the Log Actuals screen but offer no way to run the scheduler. If something you granted is missing, confirm the exact permission is ticked on the role and that the test user actually holds the role, then sign in again to reload rights.
Common Mistakes
Granting more than the job needs. A role that includes Settings or Security "just in case" hands out destructive tools by accident. Grant the least that does the work, and add permissions when someone genuinely needs them. More of these traps are collected in user and permission mistakes.
Expecting custom roles to inherit new permissions on upgrade. Only the Administrator role auto-receives new permissions. Review and update your custom roles after every version upgrade, or planners quietly lose access to new features.
Trying to deny one permission to one person. There is no per-user override. If a planner should not have delete rights, create a "Planner, no delete" role and assign that, rather than looking for an exception switch that does not exist.
Leaving Clear Data in a planner role. The Clear Data permission wipes tables permanently. Keep it in administrator-only roles, never in Planner or Supervisor.
Two Worked Roles
The two roles most plants build first are Planner and Supervisor, and they show how the tick list encodes intent.
A Planner role is for people who build and run the plan but do no administration. Grant the Production permissions (manufacturing orders, scheduling, drag-reschedule, actuals, and the routing designer), the Master Data permissions (products, work centers, shifts, holidays), the Sales permissions (quotes and customers), and the Insights permissions (reports and dashboards). Add the Data permissions if planners also run imports. Grant nothing under Security, and under Settings grant only the view permission, never Clear Data or the data-source configuration. The result is full operational reach without the destructive admin tools.
A Supervisor role is narrower. Grant schedule-view and the two actuals permissions (log actuals and edit actuals), plus manufacturing-order view and report or dashboard view for context. Deliberately leave schedule-generate and drag-reschedule unticked, along with the routing-edit and all Settings permissions. Now a supervisor can watch the plan and record real hours against it but cannot regenerate or alter it. The same schedule-view-and-log-actuals combination is what the shop-floor kiosk relies on, so a Supervisor role doubles as the floor-logging role.
Least Privilege in Practice
The safest way to build any role is to start from an empty tick list and add permissions only when someone genuinely hits a wall. It feels slower than granting broadly and trimming later, but trimming is the hard direction: once people rely on an access they should not have, taking it back breaks their habits and invites pushback. Granting on demand, by contrast, is a quick edit the moment a real need appears. Start narrow, and let the roles grow toward what the jobs actually require rather than toward what might one day be convenient.
Next Steps
Once the role exists, how to add a user is the companion task, where you attach the role to real people. For the full task library, see the EDGEBIC how-to hub, and for where access control sits in the wider platform, EDGEBIC.
Expert Q&A: Deep Dive
Q: After a version upgrade our planners lost access to a new report the admin can see. Did the upgrade break their role?
A: No, this is by design. When an update adds new permissions, only the built-in Administrator role receives them automatically, which is a security-first default. Your custom Planner role does not gain the new permission until you grant it. Open Roles and Permissions, edit the Planner role, tick the new permission where it appears in the tree, and save. Tell the planners to sign in again to load the change. Reviewing custom roles after every upgrade avoids this surprise.
Q: I want supervisors to log actuals but never regenerate the plan. Which permissions do I tick?
A: Create a Supervisor role and grant the schedule-view and actuals-logging permissions in the Production area, plus manufacturing-order view and report or dashboard view for context. Deliberately leave the schedule-generate and drag-reschedule permissions unticked, and grant nothing under Settings or Security. The result is a role that can see the plan and record real hours against it but cannot alter or rerun it. Assign it to the supervisors on the Users tab.
Frequently Asked Questions
Ready to Transform Your Production Scheduling?
User Solutions has been helping manufacturers optimize their production schedules for over 35 years. One-time license, 5-day implementation.

User Solutions Team
Manufacturing Software Experts
User Solutions has been developing production planning and scheduling software for manufacturers since 1991. Our team combines 35+ years of manufacturing software expertise with deep industry knowledge to help factories optimize their operations.
Share this article
Related Articles
How to Create a Watched-File Integration in EDGEBIC
Create a watched-file integration in EDGEBIC: point it at the file your ERP drops, pick the target entity and import mask, set the debounce, and let a new file trigger the run.
How to Rehearse an Integration With the EDGEBIC Simulator
Use the built-in Simulator to provision demo data, watch real integration runs happen, and prove the mechanism before you point anything at a live ERP. Includes the tear-down rule.
How to Run an Integration Now and Pause All Schedules in EDGEBIC
Force one integration to run with Run Now, cancel a run in progress, disable a single definition, or tick Pause all schedules to stop every automatic sync for the session.
