Configure AVEVA Web Client Role Management
- Last UpdatedJun 19, 2026
- 4 minute read
Use AVEVA Web Client - Role Management plugin of the Configurator to create or manage the RW (Read Write) and RO (Read Only) groups, assign or remove users from groups, validate group membership, and apply security changes. By default, below two local Windows groups will be created during the Web Client installation:
AVEVA Web RW Users
-
Will have access to view the Web Client
-
Will have permission to perform write operations
-
Will have ability to modify, update, or interact with applications where applicable
-
Will have permission to acknowledge alarms
-
Will have access to view current usage of licenses
-
Is intended for operators or personnel requiring modification capabilities.
AVEVA Web RO Users
-
Will have access to view the Web Client
-
Will not have ability to edit or modify data
-
Will have restricted UI elements and disabled write actions
-
Is intended for monitoring or supervisory personnel who require visibility but not control.
-
Will see [R/O] appended in the browser button.

Note: If you use remote System Management Server, you need to create these groups manually or use existing groups in the respective Windows Domain Controller.
When Federated Identity Provider is set to external groups, such as Microsoft Entra ID or CONNECT, all authenticated users will have read and write access.
For an upgrade from an older version to the latest InTouch version, the following local groups are created/retained:
-
aaInTouchRWUsers
-
Will have access to write to the InTouch Web Client applications.
-
-
aaInTouchROUsers
-
allows users in the group to only view/read the InTouch Web Client application.
-
After the upgrade, any existing users who belong to these user groups will automatically be included in those groups.
Note: When you install the latest version of InTouch on a machine for the first time, or when upgrading from a older version to latest, the user account that is logged in during installation or upgrading is automatically added to the AVEVA Web RW User (Read/Write) group.
User roles
You need to assign appropriate roles to user groups so that the users within those groups have the correct permissions to perform specific actions. Available roles that can be assigned to the groups are: Read, Write, and LicenseViewer.
-
Read: Allows you to only view or read the Web Client applications.
-
Write:Allows you to read and write to the Web Client applications. Can acknowledge alarms.
-
LicenseViewer: Allows you to monitor Web Client license usage through the License Usage Monitor on the Web Client application page.
Add Group
You can create additional groups if needed and assign roles to the groups as required.
-
In the AVEVA Web Client - Role Management plugin of the Configurator, select Add Group.
The Select Groups dialog appears.
-
In the From this location field, browse Locations of the device to add to the group.
-
In the Enter the object name to select field, enter the object name. See Microsoft learning website for an example.
-
Select Check Names to validate the object name.
-
Select OK. The new group is successfully added to the list.
Advanced search for object name
-
Select Advanced to find object names using query.
Note: The options under Common Queries tab will be unable only if a domain account is selected as a location.
-
The Common Queries tab opens.
-
In the Name filed, select Starts with or Is exactly from the drop down and enter the object name you want to search.
-
Select Columns. The Choose Columns dialog appears.
-
From Columns available, select the columns you would like to display, and then select Add.
The added columns are displayed in the Columns shown list.
-
From Columns shown, select the columns you would like to remove, and then select Remove.
-
Select OK.
-
-
In the Description filed, select Starts with or Is exactly from the drop down and enter the object name you want to search.
-
Enter the description.
-
Select Find Now to get the results based on Name and Description provided. You can select Stop to pause the search.
-
-
Select the checkbox Disabled accounts to return accounts that are currently disabled.
-
Select the checkbox Non expiring password to return users configured with password that does not expire.
-
Select the number for Days since last logon from the drop down to filters accounts based on elapsed days since last logon.
-
Select OK to the add the object name.
Assign roles for the Group
After the group is added, if you have access to configurator, you can add or edit roles to the group. Roles provide permission to read, write, and view license for the group.
-
Select the group to add or edit roles.
-
In the Roles column, select the drop down to view the available roles. Each group can be assigned Read, Write, and LicenseViewer.
-
Select the roles checkbox to add to permissions the group.
-
Clear the checkbox to remove the permission.
Delete Group
-
In the Delete Groups column, select the checkbox of the group to be deleted.
The Delete Groups option is enabled.
-
Select Delete Groups. A confirmation dialog appears.
-
Select Yes to delete the group.