Authorization Policy rule Inheritance and Hierarchy

Julian Ares

Last Update 16 days ago

InControl employs a hierarchical system to manage authorization policies, ensuring precise control over access permissions. Understanding this hierarchy is crucial for effectively configuring and troubleshooting access settings.​


Hierarchal Structure 

Authorization rules in InControl follow a specific hierarchy:


  1. Account Level: Broad policies applicable across the entire organization.​
  2. Site Level: Policies specific to individual sites within the organization.​
  3. Charger/Vehicle Level: Highly specific rules for individual chargers or vehicles.

In cases of conflicting rules, the more specific rule takes precedence. For example, a rule set at the charger level will override a conflicting rule at the site or account level.

Inheritance of Rules

If a specific rule is not defined at a lower level, it inherits the rule from the higher level. For instance, if no rule is set at the charger level, it will inherit the site-level rule.​


Conflict Resolution

  • Priority: More specific rules override broader ones.​
  • Duplication: Duplicate rules are permitted.​
  • Conflicts: Conflicting rules at the same hierarchy level are not allowed.

Practical Examples

  • Account-Level Rule: Allow PIN "4321" for all chargers.​


  • Charger-Level Rule: Forbid PIN "4321" on charger "ICE30-SIM-1000".
What happens: PIN "4321" is allowed on all chargers except "ICE30-SIM-1000", where it is explicitly forbidden.

  • Site-Level Rule: Forbid all vehicles at "Middle School".​


  • Charger-Level Rule: Allow vehicle "3GNKDCRJ2RS187992" on charger "ICE-SIM-1002".

What happens: Vehicle "3GNKDCRJ2RS187992" will be able to charger at charger "ICE-SIM-1002", however, no other vehicles will be able to charge at any charger at "Middle School".

  • Account-Level Rule: Forbid any vehicle at the account named "Green School District". 


  • Site-Level Rule: Allow any vehicle at the site named "Middle School".

What happens: Vehicles will only be able to charge at "Middle School", while no other vehicles can charger at any other sites of that account. 

  • Site-Level Rule: Forbid Vehicle "1G1FX6S04P4200588" at the site named "Elementary School". 


  • Charger-Level Rule: Allow any Vehicle at the charger named "ICE30-SIM-1003".
What happens: All vehicles, including "1G1FX6S04P4200588", can charge at "ICE30-SIM-1003". 


To enforce the restriction, the vehicle must be forbidden at each charger individually.


  • Site-Level Rule: Allow vehicle named "3GNKDBRJ1RS225226" at the site named "Middle School". 


  • Charger-Level Rule: Forbid all vehicles at the charger named "ICE30-SIM-1001".
What happens: The policy at the charger level will be used, and charging will be prohibited at charger "ICE-SIM-1001".

Was this article helpful?

0 out of 0 liked this article

Still need help? Message Us