---
title: "Limit which machines a member can see"
description: "How to restrict an IoTFlows member to specific machines. Machine access is a per-person list of allowed assets, managed from the member directory at /members: each member row carries a control that reads All machines when the list is empty, or a stack of machine avatars when it is not. Opening it shows the Machine access dialog, where tapping a machine grants or revokes it immediately, with no Save step. An empty list is the default and means the member sees every machine. A restriction narrows everything, including the machine pickers on reports and work orders, so a member reporting that a machine disappeared has usually been restricted. Only an Organization Owner or Administrator can see or change the control."
category: "People and access"
source_url: "https://www.iotflows.com/docs/admin/machine-access/"
---
# Limit which machines a member can see

Grant a member access to specific machines instead of the whole fleet.

**You need to be an Organization Owner or Organization Administrator.** Everyone else does not see the control at all. See [Roles and permissions](/docs/admin/roles-reference/#roles).

*Machine access* is a per-person list of the machines someone is allowed to see. Each machine on that list is an *allowed asset*. The list is empty by default, and an empty list means no restriction: the member sees every machine in the organization.

You do not need machine access if everyone should see everything. It is a restriction, not a requirement, and an organization that never touches it is configured correctly.

## What machine access controls
Machine access is managed from the member directory at `/members`. Each member row carries a control between the person's role and the pencil icon:

| What the control shows | What it means |
|---|---|
| **All machines**, on a dashed pill with a globe | The list is empty. This member sees the whole fleet |
| Up to three machine avatars, then a count of the rest, such as `+4` | The member is restricted to those machines |

The restriction applies everywhere, not only to the [Assets page](/docs/monitoring/assets-overview/). It narrows the machine pickers too, so a restricted member cannot choose an off-list machine when building a report or creating a work order.

Machine access never adds a permission. It can only take machines away from what the person's role already allows.

## Grant access to specific machines
1. Go to `/members`.
2. Find the member's row and select the machine-access control on it. The **Machine access** dialog opens, with that person's name, username, and email at the top.
3. Use **Search machines** to find a machine by name or by identifier, or scroll the list.
4. Select each machine the person should see. A selected machine gets a blue check and the list header counts it, for example `Machines · 4/27 selected`.
5. Select **Done**.

![The Machine access dialog, opened from a member row. The member's avatar, name, username, and email sit at the top, above a blue note marked 1 reading Access restricted to 4 selected machines. Deselect all to grant access to every machine. Below it a Search machines field, a list header reading Machines · 4 of 27 selected, and a scrolling list of machines, each with a photo, a name, an identifier, and a circle on the right. A block of four consecutive rows, marked 2, is highlighted blue with a filled blue check. Close and Done sit at the bottom](/images/admin/adm-access-01.webp)

*Granting a member access to specific machines.*

> **Info:**
> **Is there a Save button?**
>
> No. Each machine saves the moment you select it, and a toast confirms it: "Access to Haas VF-2 granted". **Close** and **Done** do the same thing, which is to close the dialog. Closing it does not discard anything.

Grant machine access by cell, not by a person's current assignment. An operator restricted to one machine files a support ticket every time they cover for someone, and the administrator ends up granting the whole fleet anyway. Restrict a press operator to the six presses in their cell, not to the one press they ran last week.

If a grant fails, the toast reads "Failed to update machine access" and the machine goes back to unselected, because nothing was saved. Try it again, and if it keeps failing, [contact IoTFlows](/docs/get-started/get-support/).

## Revoke access
1. Open the **Machine access** dialog on the member's row.
2. Select a machine that is already highlighted. The check clears, and the toast reads "Access to Haas VF-2 revoked".

![A cropped detail of the Machine access list. One row is mid-revoke: its blue highlight has cleared and a small spinner sits where the blue check was. The rows above and below it stay highlighted blue with filled checks](/images/admin/adm-access-02.webp)

*Revoking access to one machine.*

To lift the restriction entirely, deselect every machine. The note at the top of the dialog switches to "No machines selected. This member can access all machines", and the directory row goes back to reading **All machines**.

Removing a member is a different job, and it removes their access to everything rather than narrowing it. See [Change roles and remove members](/docs/admin/manage-members/#remove).

## How access interacts with roles
A role says what someone can do. Machine access says which machines they can do it to. The two are set separately and both apply.

| Role | Machine access |
|---|---|
| Organization Owner | Can be restricted, but do not. The Owner is the billing and ownership role and needs the whole fleet |
| Organization Administrator | Can be restricted. Administrators still manage machine access for everyone, including themselves |
| Organization Member | The usual target. A Member restricted to `Haas VF-2` classifies downtime there and cannot see `Brother S700X1` |
| Organization Observer | Can be restricted. Read-only on a shorter list |

Changing someone's role does not change their machine access, and clearing their machine access does not change their role. A Member promoted to Administrator keeps the same four machines until you clear the list.

For what each role can do, see [Roles and permissions](/docs/admin/roles-reference/#matrix).

## What a restricted member sees
A restricted member sees a smaller fleet, with no indication that anything was filtered out. There is no banner, no count of hidden machines, and no request-access control.

![The Assets page as a member restricted to four machines. Four machine cards fill a grid that holds twenty-seven for an unrestricted member, and the tiles above them — uptime, utilization, downtime, and 3 of 4 machines producing — are computed from those four only. Nothing on the page states that machines are hidden](/images/admin/adm-access-03.webp)

*What a restricted member sees. A machine that 'disappeared' is usually this.*

A machine that "disappeared" is the first report you will get, and a machine missing from a report or work-order picker is the second. Both have the same cause, so check machine access before you treat either as a data problem.

Open the member's row at `/members` and read the machine-access control. If it shows a stack of avatars rather than **All machines**, the machine was not lost. For everything else that makes a machine look wrong, see [Troubleshoot monitoring](/docs/monitoring/troubleshoot-monitoring/#start).

## See also
- [Roles and permissions](/docs/admin/roles-reference/)
- [Change roles and remove members](/docs/admin/manage-members/)
- [Assets overview](/docs/monitoring/assets-overview/)
- [Review the organization audit log](/docs/admin/audit-log/)
