Overview
When using an SGC200 or SGC500 edge device, asset ownership and permissions are managed through a user group. Understanding how user groups and permissions work is essential when migrating an existing Managed Asset to a Connected Asset.
Managed Assets may either be created manually in Netilion or automatically during the ordering process using the Auto Registration option. This article explains how SGC200 and SGC500 assign asset permissions and how to make these assets accessible to an edge device.
Terminology
The following terms are used throughout this article:
- Managed Asset = An asset that exists in Netilion but is not yet connected to an SGC200 or SGC500. A Managed Asset may have been created manually or automatically during the ordering process using the Auto Registration option.
- Connected Asset = An asset that is physically connected to an SGC200 or SGC500 edge device and for which data is provided through that edge device.
When a Managed Asset is assigned to the user group of an edge device and becomes accessible to the device, it can be migrated from a Managed Asset to a Connected Asset.
How Asset Management Works with SGC200 and SGC500
Each SGC200 or SGC500 is assigned to a specific user group. The assigned user group can be found on the Edge Device Details page.
In addition to human users, every edge device has its own technical user. This technical user is assigned to the same user group as other users, such as the subscription owner or other authorized users.
User Group Structure
The following entities are typically members of the same user group:
- Subscription owner
- Additional human users
- SGC200 or SGC500 technical user
The edge device uses its technical user account when interacting with Netilion services.
Automatically Created Assets
When an SGC200 or SGC500 automatically creates an asset, the asset is assigned to the edge device's user group with the following permissions:
- Read
- Write
- Permit
- Delete
As a result, all members of the user group—including the edge device's technical user—can access and manage the asset.
Managed Assets
Managed Assets may be created in different ways:
- Manually by a user in Netilion
- Automatically as part of the ordering process
By default, these assets are not automatically visible to an SGC200 or SGC500.
As a result, the edge device cannot:
- Find the asset
- Connect a device to the asset
- Update asset information
- Upload measurements or metadata related to the asset
- Perform any Heartbeat-related tasks
To enable access, the asset must be assigned to the same user group as the edge device.
Required Permissions
When assigning a Managed Asset to the edge device's user group, the following permissions are required:
- Read
- Update
- Permit
These permissions allow the technical user of the edge device to access and manage the asset.
Note: The Delete permission is not required for the migration process.
Migrating a Managed Asset to a Connected Asset
- Determine the user group assigned to the edge device.
- Open the asset in Netilion.
- Assign the edge device's user group to the asset.
- Grant the following permissions:
- Read
- Update
- Permit
- Save the changes.
Wait for the edge device to recognize the migration.
- SGC500: up to 20 minutes
- SGC200: up to 24 hours
Once these permissions are in place and the synchronization period has elapsed, the edge device can interact with the asset.
Alternative Migration Method Using Nodes
If a large number of Managed Assets need to be migrated, assigning each asset individually to the edge device user group can be time-consuming.
When assets are organized in a node hierarchy, a more efficient approach is to assign the edge device's user group to the root node instead of configuring permissions for each asset separately.
Required Permissions
Assign the edge device user group to the root node with the following permissions:
- Read
- Update
- Permit
All assets and subnodes below the selected root node will then become accessible to the edge device's technical user through the inherited permissions.
Migration Procedure
- Identify the root node that contains the assets to be migrated.
- Open the node in Netilion.
- Assign the edge device's user group to the root node.
- Grant the following permissions:
- Read
- Update
- Permit
- Save the changes.
- Wait for the edge device to recognize the updated permissions.
- SGC500: up to 20 minutes
- SGC200: up to 24 hours
Summary
- Every SGC200 and SGC500 belongs to a user group.
- Each edge device uses a technical user that is also a member of this user group.
- Managed Assets may be created manually in Netilion or automatically as part of the ordering process.
- Automatically created Connected Assets are assigned to the user group with full permissions (Read, Update, Permit, Delete).
- Managed Assets are not visible to the edge device by default.
- To migrate a Managed Asset to a Connected Asset, assign the asset to the edge device's user group with at least Read, Update, and Permit permissions.
- When migrating multiple Managed Assets, permissions can be assigned to a root node instead of configuring each asset individually. All assets below the node become accessible to the edge device.
- Once discovered through a node, the edge device automatically assigns the assets directly to its user group with full permissions (Read, Update, Permit, Delete).
- The migration is typically recognized within 20 minutes on an SGC500 and within 24 hours on an SGC200.