Glossary · HMI, SCADA and operations
Access level
Also known as: Authorization level, Password level
German: Zugriffsebene
In HMI and SCADA systems, an access level is a graded set of permissions that determines which screens, operations and parameter changes a logged-in user or user group may perform.
- HMI and SCADA
- OT security
In one sentence
An access level grades which HMI screens, operations and parameter changes a logged-in user may perform.
Example
Operators at access level 1 can start and stop the line; maintenance technicians at level 2 can also change timers; only engineers at level 3 can change recipes.
How it applies
- Engineering: Numbered access levels are a traditional HMI mechanism; modern systems map permissions to a User role and connect to central user management. Assign the lowest level that allows a person to do their job, and avoid shared accounts where individual accountability is required.
- Operation: Automatic logoff after inactivity prevents an unattended panel from staying at a high level.
- Security and compliance: Access control supports the requirements of IEC 62443 and, in regulated industries, data integrity rules. Combined with an Audit trail, it shows who changed what.
- Documentation: Operating manuals should state for each function which access level it requires. A permissions matrix (functions vs. levels or roles) belongs in the system documentation.
Access level vs. user role
An access level is a rank: higher levels include lower ones. A User role groups permissions by job and need not be hierarchical. Many systems combine both.