Users, API keys and audit log
These are under Settings. Users, API keys and Audit log are visible to admins only. Everyone can see My account and Subscription.
Roles
| Role | Can |
|---|---|
| Viewer | See every screen. Change nothing. |
| Operator | Everything a viewer can, plus: edit tag data and columns, import and delete tags, manage zones and antennas, start and stop readers, manage assets, acknowledge and resolve alerts. |
| Admin | Everything an operator can, plus: manage users, create and revoke API keys, read the audit log and manage billing. |
Every account has at least one admin. Titan won't let you demote, deactivate or delete the last one.
Users
Under Settings → Users, an admin can:
- Add a user with an email address, a starting password and a role. Give the person their password through a channel you trust, and ask them to change it.
- Change a user's role, or deactivate them. A deactivated user can't sign in, and any session they already have stops working.
- Delete a user.
Passwords must be at least 12 characters (and at most 128). Titan refuses very common passwords.
My account
Anyone can change their own password under Settings → My account by entering their current password and a new one. An admin can set a new password for another user without knowing the old one.
Sessions in the hub last 12 hours. After that you sign in again.
API keys
API keys let another system use Titan without a person signing in. See the API overview for how to use one.
Under Settings → API keys, an admin can:
- Create an API key with a name that says what it's for, like "WMS sync" or "Nightly export". The key (it starts
tk_) is shown once, when you create it. Copy it into your system straight away, because Titan stores only a fingerprint of it and can't show it again. - See each key's name, when it was created and when it was last used.
- Revoke a key. It stops working immediately.
Things to know:
- A key acts as an operator. It can read everything and change operational data, but it can't manage users, API keys, the audit log or billing.
- A key belongs to your organisation, not a person. It keeps working when the admin who created it leaves. Revoke keys you no longer use.
- Use one key per integration. Then you can see which system did what in the audit log, and revoke one without breaking the others.
- If a key may have leaked, revoke it, create a new one and update the system that uses it.
Audit log
Settings → Audit log records who changed what: sign-ins (successful and refused), user and key changes, reader starts and stops, antenna mapping, zone changes, tag data edits and imports, and asset actions. Each entry shows the action, what it applied to, the person or API key that did it, the address it came from, and the time.
The screen shows the most recent 200 entries.