The business

Your team
and access.

Roles say what somebody can do. Scoping says where. Both are enforced on every request rather than by hiding a button.

The roles

Manage, Users, Team as seen by a test Operator: 5 teammates, 0 pending, 0 deactivated. In place of an invite button it reads Your tenant admin adds and edits teammates. A search box and an All states filter sit above the list of test teammates with their example.test emails, roles (Tenant Admin, Operator, Property Manager, Charger Owner and Fleet Operator), Active state, two-factor status and when each was last seen.
Manage, Users, Team, as an Operator sees it: each teammate’s role, state, two-factor status and last seen. 2FA OFF means they have not yet set up two-factor, which happens on their first console sign-in; last seen also counts the driver app. Sample screen with test data.

Give people the narrowest role that lets them do the job. It is not distrust, it is that a smaller blast radius makes everybody braver about actually using the thing.

Scoping

Scoping is real, not cosmetic. It is enforced per request. A building manager scoped to one building cannot reach another one by editing a URL, because the boundary is checked on the server every time rather than by leaving a menu item out of the page.

Change what somebody can reach
Do it yourself
  1. To change the role: Manage, Users, Team, open the person.
  2. To change the scope: System, Access Management, open the person and tick the stations and chargers they can reach.
  3. Save. Save replaces their whole scope, and it applies on their next request, not at their next sign-in.
Or just ask EVII™
Give Sam the Plymouth site as well as Balboa.
What can Sam actually see right now?

Scope applies to the scoped roles, such as Property Manager and Building Admin. An Operator and a Viewer read across the whole account.

Access Management detail for Pat Manager (test), pat.manager@example.test, role Property Manager, opened by a test Tenant Admin, with Back to Access Management above and Clear access and Save buttons on the right. The intro explains how stations and chargers are picked. Station cards show Sample Towers (sample data) and Sample Lofts (sample data) ticked with all four of their chargers ticked, and Sample Inn (sample data) and Sample Fleet Depot (sample data) unticked. The footer reads 2 stations, 4 chargers selected, and notes that Save replaces the user’s entire scope.
Access Management for one teammate: tick the stations and chargers they can reach. Save replaces their whole scope. Sample screen with test data.
Nobody outranks themselves

You cannot grant a role or a scope above your own. There is no path, accidental or otherwise, to creating somebody more powerful than the person who created them. EVII is bound by exactly the same rule and cannot grant permissions to anybody, including herself.

Two identities, one person

Everybody on the platform is a driver underneath. Administrative power is a grant layered on top, and it only wakes on the admin console behind two-factor sign-in.

That gives you two separate levers, on purpose:

There is also a back-office-only option when somebody is added: an admin with no driver identity at all, for a person who will never charge a car. Only a super admin can tick it, so ask EV Initiative.

The audit log

Every change made in the console writes a row: which account, what, when. Every remote command to a charger writes one too, including what was sent and what came back.

It exists for a specific conversation, the one you will have three months from now about why a price changed or who reset that charger. Nobody thinks about it until exactly then.

Finding out who did something

Open the charger and its audit panel for every command and change on that unit. A network-wide audit screen is not built yet, and EVII cannot search the log for you: if you need a change traced across the network, ask us and we pull it from the record.

The Audit tab on the charger page for TEST-TWR-02, seen by a test Operator, with a Refresh button. Four sample rows show the time, the action and who did it: ocpp.reset by a user, charger.display_name_changed by a user, ocpp.change_availability by a user, and ocpp.set_charging_profile by the system. Each user is shown as the last six characters of the user id, not a name. The ocpp.reset row is open, showing the Payload with type Soft and the Response with status Accepted.
A charger’s Audit tab: each command and change, who made it, and, opened, what was sent and what came back. A person shows as the end of their user ID. Sample screen with test data.

Adding somebody

Invite a teammate
Do it yourself
  1. Team, then invite.
  2. Their email, their role, and the scope they need.
  3. If they should have no driver account at all, ask EV Initiative: only a super admin can tick Native admin account (no driver identity).
  4. Send. The invite is single-use and lasts fourteen days.
Or just ask EVII™
Invite dana@example.com as a viewer across everything.

After saving, fine-tune their site and charger scope on the access management page.

Invite teammate dialog opened from Manage, Users, Team by a test Tenant Admin. Name is New Manager (test), email new.manager@example.test, and Role is Property Manager, with a hint that roles drive what the teammate can do and that station and charger scope can be fine-tuned on the Access Management page. Under Where can they work?, the Sample Towers (sample data) station and both of its chargers, TEST-TWR-01 and TEST-TWR-02, are ticked, while Sample Lofts, Sample Inn and Sample Fleet Depot (all sample data) are left unticked. Cancel and Send invite buttons are at the bottom.
Invite teammate, from Manage, Users, Team: the name, email and role, then the stations and chargers they can work at. Sample screen with test data.
The Invite teammate dialog with Name Nico Backoffice (test), email nico.backoffice@example.test and Role Operator. The box Native admin account (no driver identity) is ticked, with the note that by default a new admin also gets a driver account and signs into the driver app with the same email, and that ticking it creates a back-office-only admin. This option appears only for a super admin; this capture uses a test super admin. Cancel and Send invite buttons are at the bottom. Nothing was sent.
The Native admin account box creates a back-office-only admin with no driver account. It appears only when a super admin sends the invite. Sample screen with test data.