Roles & Permissions

View and assign platform and app roles in the Admin Panel. Use the permission matrix and Assign Roles table to control what each user can do in Well Management, RodSim, and Calculators.

PetroBench uses two role layers: platform roles set hierarchy scope, and app roles set permissions inside each installed application. The Security section in the Admin Panel is where you review and assign both.

For the full access model, hierarchy rules, and data scoping behavior, see the RBAC reference.

Platform roles vs app roles

LayerRolesControls
PlatformHQ Admin, Division Admin, Region Admin, Key UserWhich divisions, regions, and admin pages a user can access
AppAdmin, Engineer, Advisor, GuestWhat actions a user can take inside each app

When you assign a platform role, PetroBench applies a default app role. You can override app roles per user and per application without changing their platform scope.

Automatic role sync only upgrades app roles to match a higher platform role. It never downgrades a manually elevated app role.

Role & Permissions matrix

Open Admin Panel > Security > Role & Permissions to view the permission matrix.

The page shows one tab per installed app (for example, Well Management, RodSim, Calculators). Each tab lists capabilities down the left and the four app roles across the top:

App roleSummary
AdminFull control, including archive and restore
EngineerCreate, edit, delete, import, and run simulations
AdvisorEdit existing data; cannot create or delete wells or import
GuestRead-only access to view data and results; uses a free guest seat, not a paid seat

Use the matrix when deciding which app role to assign. It reflects the current permission set for your organization's installed apps.

Guest role

Guest is the read-only app role for people who need visibility inside your organization without doing design work. Guests are still normal internal users (they sign in with your org, get a platform role and region scope)-they are not anonymous public links.

Seats

Assigning Guest for an app does not consume a paid license seat for that app. It uses the separate guest seat pool on your subscription. Admin, Engineer, and Advisor each consume a paid seat. Details: Billing & Licenses.

What Guests can see and do

Within their platform scope (division / region), Guests can typically:

  • View wells and well data
  • View and compare simulations, charts, and results
  • Open calculators and download simulation reports
  • View tags and custom equipment (not manage them)

They cannot create, edit, delete, import, or archive wells; they cannot run or change simulations; they cannot manage users, roles, or tags.

Good fits for Guest

ExampleWhy Guest works
Operations manager who reviews resultsNeeds charts and reports, not design tools
Finance or HSE stakeholderOccasional visibility into wells in their region
New hire shadowing before full Engineer seatRead-only onboarding without burning a paid seat
Shared “viewer” account for a leadership dashboardSame org login, no edit risk

Use Advisor instead when someone must edit existing well data. Use Engineer when they create wells or run simulations.

Assign Roles

Open Admin Panel > Security > Assign Roles to set app roles for each user across applications.

The table lists users in your scope. Each installed app has its own role column.

Assign or change app roles

  1. Go to Admin Panel > Security > Assign Roles
  2. Find the user in the table (use search if the list is long)
  3. Select an app role from the dropdown for each app column
  4. Click Save

Assign Roles supports Undo and Redo while you are editing. Save only when all changes look correct.

Example assignments

User typePlatform roleTypical app roles
Organization adminHQ AdminAdmin in all apps
Field engineerKey UserEngineer in Well Management and RodSim
External consultantKey UserAdvisor or Guest in affected apps
Manager (view only)Key UserGuest in all apps

Default platform-to-app mapping

Platform roleDefault app role
HQ AdminAdmin
Division AdminAdmin
Region AdminAdmin
Key UserEngineer

Override defaults on Assign Roles when a user needs tighter or broader app access than their platform role implies.

Who can manage roles

ActionHQ AdminDivision AdminRegion Admin
View Role & Permissions
Edit Assign Roles (org scope)Division users onlyRegion users only
Change platform role on userDivision scopeRegion scope

Key User accounts cannot open role management pages. Ask an administrator to change roles on their behalf.

Relationship to user records

Platform role and region assignment are set on the Users page. App role overrides are set on Assign Roles. Both layers apply together: a user must have platform scope and app permission to perform an action.

Next steps

On this page