Sites
Scoping, and per-site roles
Edit this pageOn this page
Sites let one Loomscope serve several locations without mixing them up — a building, a datacentre, a client. They are both a filter and a permission boundary.
The site picker
The picker in the header scopes every page. "All sites" shows everything; picking one filters hosts, networks, vulnerabilities, certificates, topology and history. The choice persists across sessions, so an operator who works on one datacentre does not re-select it every morning.
Binding a daemon to a site
Two ways, and one of them wins:
- From the site page in the UI, at any time.
- With
LOOMSCOPE_DAEMON_SITE_CODEon the daemon, applied on first registration.
If both are set, the UI assignment wins. An operator's explicit choice should not be overridden by an environment variable somebody edited months ago and forgot.
What belongs to a site
Daemons, networks and hosts. A host inherits its site from the network it was discovered in, which means moving a network between sites moves its hosts with it.
Per-site dashboards
Each site has its own summary: hosts, services, open vulnerabilities, certificates, the daemons serving it and recent activity. For a service provider, that page is the client's status; for an enterprise, it is the datacentre's.
Scopes: per-site roles
A per-site override raises somebody's access for one location.
| Organisation role | Site override | Effective at that site |
|---|---|---|
viewer | editor | editor |
viewer | — | viewer |
admin | viewer | admin |
An override can only raise. Your organisation role is the floor, always. An override that appears to lower access would be a permission model with two answers to the same question, and the one people would rely on is whichever they tested — so it simply does not exist.
When an override is in effect, a scoped: badge appears next to the site
picker, because a permission you have and cannot see is a permission you will
be surprised by.
Manage them from Sites → site → Scopes.
Multi-tenancy versus sites
These are different mechanisms and it is worth not confusing them:
| Organisation | Site | |
|---|---|---|
| Isolation | Hard — enforced by PostgreSQL row-level security | Soft — a filter and a permission scope |
| Shared inventory | No. Nothing crosses | Yes. One inventory, grouped |
| Use it for | Separate customers with separate data | Locations within one customer |
A service provider that must guarantee client A cannot see client B uses organisations. One that manages several sites for the same client uses sites.