Signed in now
The leading root of the Users page, showing who is signed in on this screen, what this screen can do now, and the Sign in, Switch user and Sign out verbs.
Signed in now is the first root of the Users column and the panel the page opens on. It is the page's one piece of live state: the identity in force on this screen, how far it reaches, and the way in and out. The node trails the signed-in name, or Nobody. The panel is open to every identity; nothing here needs the Manage local users permission, because signing in is how an administrator gets it.
Everything on this panel is per connection. The station's own window reads the station session; a browser, on the network or on the station's machine, reads the user signed in on that connection. Two browsers looking at the same station are two different people, and neither is the person at the bench.
Signed in here
When somebody is signed in on this screen the first card shows an avatar, the display name, the chip Signed in here, and one sentence: "Holds the role. Signing out returns this screen to what anyone can do without signing in." Two verbs trail the identity:
| Command | What it does | Greyed when (situation) | Not drawn when (role) |
|---|---|---|---|
| Switch user | Opens the sign-in dialog, the same one the title-bar chip opens, over the signed-in screen. Its title reads Switch user while the roster shows, and its header offers Sign out beside the current name. | Never. | Never. |
| Sign out | Returns this screen to the Not signed in role and reports it in the action feed (" signed out."). | Never. | Never. |
Signing out affects only this connection. On the station's own window it clears the station session; on a browser it clears that browser's own operator and leaves the bench exactly as it was.
Nobody is signed in
When nobody is signed in the first card is titled SIGNED IN NOW and reads "Nobody is signed in on this screen", with an accent Sign in button. The sentence under it depends on whether this screen has anybody to offer:
| Situation | Text |
|---|---|
| The station has local users | "Until someone signs in, this screen works with the permissions the station grants to anyone, shown in the strip below. Signing in swaps them for that user's role, here and on the title-bar chip alike." |
| The station has no local users yet | "This station has no local users yet. The first one, the primary administrator, is created on the Users page." |
| The published demonstration | "This is the published demonstration, so there is no account to sign in as. Everything here is view only." |
The verb stays put in all three cases: a way in that vanished would read as a screen that failed to load. The dialog it opens carries the same sentence in place of the roster, so the click never promises what the next screen takes back. Sign in goes through the same dialog and the same PIN check as the title-bar chip; see Signing in.
What this screen can do now
The second card, WHAT THIS SCREEN CAN DO NOW, reads the permissions actually in force on this connection: the signed-in user's role, or the Not signed in role when nobody is.
| Element | What it shows |
|---|---|
| Role name | The role behind the permissions, or No role when the role has been deleted. |
| Summary | "Can change of 6 areas" when the role reaches Operate or Manage somewhere; otherwise "View-only"; "No access" when no pip is lit. |
| Reach strip | The six labeled pips (Dashboard, Connector, Process, Histories, Logic, System), each at the height of the deepest permission held in that area, with a tooltip ": ". |
| Note, signed in | "Everything this screen may do comes from the role. Change the role under Roles and every user holding it changes with it." |
| Note, nobody signed in | "This is the reach of the "Not signed in" role, the first one under Roles, read here as what this screen may actually do." |
The strip is the same projection every role row on the page is drawn with, so signing in reads as a change to a silhouette you already know. The pip rules, and what the strip does not show, are on the Permissions page.
The reach ruler
Beneath the panels, on the floor of the detail column, sits THE REACH RULER: four rungs, No access, View, Operate, Manage, and the sentence "One pip per station area, in the same order wherever a strip appears. How far the pip fills is how deep the role reaches into that area." It stays there whichever node is selected, because the same strip appears in the column's role rows, on a user's role and here on the identity in force.
What changes when the identity changes
A sign-in or sign-out on this screen re-checks every permission-driven surface at once: the rail redraws with the entries the new role may open, the page you are on either stays or, if its rail entry is no longer visible to the new identity, gives way to the first entry that is, and every command re-reads the role at the moment it is pressed. The title-bar chip changes with the panel, because both read one seam.
Signing in and out is not a station mutation. It stays available while the runtime is stopped by the free-mode limit, when everything that writes configuration is refused with "Runtime stopped".
What the panel does not do
- It does not show who is signed in on other screens. A browser and the station window each have their own identity, and this panel reports only its own.
- It does not edit anything. The role name and the strip are read-only here; a role is changed under Roles, and a user's role on that user's page under Users.
- It never lists the roster to a screen that may not manage it. Who can be signed in as is the sign-in dialog's business, and the dialog offers the same roster to every role.