Skip to main content

Organization Manager

An organization is a tree of units that resources are shared into, and members are given access at a point in that tree. Share a device at a unit and everybody with access to that unit can reach it, including everybody further down.

If you have managed permissions in a file system, you already know the shape. Units are folders, resources are files, and access granted on a folder reaches everything inside it.

TermWhat it is
OrganizationThe whole tree, its members and the resources shared into it
Root unitThe top of the tree. Usually renamed to the organization name
SubunitA unit inside another unit
MemberA user account belonging to the organization
ResourceA device, app, connector, report base, basic credentials set, dashboard, image, geofence or device group

Any main account can create organizations. A user created inside an organization cannot create organizations of their own.

The Organizations menu, listing each organization with its member and subunit counts

Organizations in the top bar lists every organization you can reach, with its member and subunit counts. Opening one puts you in its tree, with the unit hierarchy in the sidebar.

Start here

Access rights are set on a unit, not on the organization. Manage organization has no permission chips; select a unit in the sidebar tree, and grant the access there.

A first organization, end to end:

  1. Open Organizations in the top bar and create one. It starts with a single root unit.
  2. Open the organization and add the people to it, on the Members tab of Manage organization. Adding somebody here makes them a member. It gives them no access to anything yet.
  3. Click a unit in the sidebar tree. The root unit will do to begin with. Access is granted per unit, so a unit has to be selected before there is anything to grant it on.
  4. On the unit's Unit members tab, find the person and click the chips for the access they should have: Read, Write, Admin or Peek.
  5. Put some resources in the unit, from its Resources tab, or by sharing a device to the unit from Device details or Select many.

The member can now reach those resources. Everything after this repeats the same three moves: add a subunit, share resources into it, and grant people access at the level of the tree that matches how much they should see.

Note: a member with no access rights at any unit belongs to the organization but sees nothing. Steps 3 and 4 are what give them access.

How access flows

Two mechanisms, and it helps to keep them apart.

Inheritance. Access granted at a unit applies to that unit and to every subunit below it. Grant a member Read at the root and they read everything in the organization. Grant it three levels down and they read that branch only.

Explicit sharing. A resource is shared into a unit and becomes reachable there. That is done from the unit, or one device at a time from Device details, or many at a time from Select many.

The two combine: a member's access level comes from the units they are granted rights at, and what they can reach comes from what has been shared into those units.

The organization

Manage organization in the top left corner opens the organization itself, whichever unit you are in. It has six tabs.

Summary

The organization summary, with member, subunit and resource counts, description, AD-group mapping and timestamps

Member, subunit and resource counts, the description, the AD-group mapping, and when the organization was created and last updated.

An organization admin can map the organization to one or more AD groups. AD-group mapping only works where a SAML identity provider is in use. Contact your technical support representative to configure one.

Members

The organization member list, with usernames, names, email addresses, phone numbers, roles and AD group

A searchable list of everyone in the organization: username, full name, email, phone number, user id with a copy button, and role. Organization admins and unit managers also see the AD group column, when the organization has an AD group, and the actions for managing each member.

Organization admins and the owner get two ways to add people.

Create new member creates a new Yggio account and puts it in the organization.

Field
First name, Last nameRequired
EmailRequired. Used for first login and password recovery
Phone numberOptional
UsernameThe login name. Using the email address is common
PasswordRequired. A one-time password is the safer choice
RoleThe member's platform role

Creating a new organization member, with the name, email, username, password and role fields

Two-factor authentication is supported and can be switched on here.

Add existing member adds an account that already exists, so one person can belong to several organizations. Enter the exact username or email address of the user to add.

Adding an existing user to the organization by username or email address

The owner of an organization can add themselves to it.

Member actions

The menu at the end of a member's row carries:

ActionWhoWhat it does
EditAnyone who may see the rowChange the member's name, email, username, password and two-factor setting
Disable / EnableOrganization admins and the ownerBlocks the account from logging in, without removing anything
RemoveOrganization admins and the ownerTakes the member out of the organization. The account itself stays
Delete userOrganization admins and the ownerDeletes the Yggio account permanently. It cannot be undone

Disable, Remove and Delete user are not offered on your own row.

Member roles

Every member's row shows their platform role - admin, editor, installer or one of the viewers. On the rows you may change, it becomes a selector.

Setting a role is not limited to organization admins. If you manage any unit of an organization the member belongs to, you may change or clear their role. Changing a role also requires your own role to be admin.

Nobody changes their own role - unit manager, organization admin and owner alike - so your own row stays plain text. Ask another admin in the organization to change it for you.

Subunits

The organization's direct subunits, with a count and a control to add one. A subunit can be removed from here, which asks for confirmation first.

Resources

The organization resources list, grouped by resource type, with access rights and the source unit

Everything shared into the organization, grouped into tabs by type: device, app, connector, report base, basic credentials set, dashboard, image, geofence and device group.

Each row shows the resource's access rights and a Source column naming the unit it is shared from. From there you can jump to that unit, or stop sharing the resource.

Search filters by resource name across the groups, and the tab counts follow the search. The list pages at 25 rows by default, and the page size goes up to 1000 for an organization with a large fleet.

Access details

The access details table, listing each user, the unit their access applies to, the rights they hold, and whether their resources are shared there

One row per user and unit, showing the rights they hold there and whether their own resources are shared at that unit.

It is the overview that answers "who can reach what", and the fastest way to set a new member up correctly: find somebody doing the same job and match their rows.

The tab is available to organization admins and to anyone who manages a unit.

A unit

Clicking a unit in the hierarchy opens it. A unit behaves like a folder: it holds resources, and access granted here reaches everything below.

The root unit shows the organization's own name and description rather than the literal name "root".

Units have four tabs.

Summary

The unit's name and description, and an icon chosen from a small set - business, groups, people, manage accounts, admin panel settings, assignment, public and account tree. The icon is what tells units apart in the organization lists.

Unit members

The unit members pane, with each member's organization role, resource permissions and share-all setting

This is where access is actually granted, and it is reached by selecting a unit in the tree first. There is no equivalent on Manage organization: that pane lists who belongs to the organization, while this one decides what they can reach.

Each member of the unit has a row with four things on it.

Organization role is Manager or Member.

ManagerManages members and their access rights from this unit down the tree, including setting the platform role of any member other than themselves - as long as their own role is admin. Creating accounts and adding existing accounts to the organization stay with organization admins and the owner
MemberThe default. No unit management

Granting and revoking Manager both ask for confirmation.

Resource permissions are four chips. Click one to grant that permission, click it again to revoke it. Each is inherited by every subunit below.

AdminManage the resources at this unit, including setting their access rights and deleting them
ReadRead data and see the resources
WriteWrite data to the resources
PeekThe system may read the resources, but they stay invisible to the account holder. Mostly used to give access to connectors

These are the same four levels as elsewhere in access rights.

Share all resources? is Yes or No. Yes shares everything the member owns at this unit, so everybody with access to the unit - direct or inherited - can work with those devices at their own access level.

A member shares their resources at one unit only. Sharing them at a second unit removes the first. Both directions ask for confirmation, because turning it off revokes everything it granted.

Subunits

The unit's own subunits, where the branch below it is built out.

Resources

The resources available at this unit, whether shared here or inherited. A resource can be unshared from here, which asks for confirmation and names the resource and the unit before it does anything.

Branding

Branding puts your own name, logo and colours on Yggio, so the people you serve see your brand rather than ours. It is worth setting up: for a municipality or a property owner giving tenants access, the platform then looks like part of your own service.

Branding is an add-on. It is not switched on by default. Contact technical support to have it enabled for your organization.

Once enabled, it is set from the Branding tab of the organization, which is available to organization admins and to anyone who manages a unit.

Tab
Predefined themesFive ready themes - default, blue, red, purple and grey - previewed before you apply one
Custom themesYour own brand name, logo and primary colours

The brand name appears in the top left corner of the application, and the logo is shown in the header and on the organization. The predefined themes change the navigation bar:

The Yggio navigation bar in the grey theme

The Yggio navigation bar in the red theme

The Yggio navigation bar in the blue theme

Custom themes go further: a brand name, an uploaded logo, and the ten shades of your primary colour, with a live preview beside the form. The result can be exported as JSON, which is how the same brand is applied to another organization without setting it again.

The Custom Themes tab, with brand name, logo upload, the ten primary colour shades and a live preview of the branded header

Note: a user who belongs to several organizations always sees the default Yggio brand, whichever brand those organizations set.

There is a fuller walkthrough in the training material.