Limiting device visibility by regionSolved

Participant
Discussion
1 week ago Feb 23, 2026

We’ve got regional IT teams and I’m trying to separate things properly in Hexnode. 

Right now, everyone can see the full device list. I was thinking of creating separate roles for North and South teams. 

Would that be enough to stop them from seeing each other’s devices? 

Replies (6)

Marked SolutionPending Review
Participant
1 week ago Feb 23, 2026
Marked SolutionPending Review

Not by itself, @vance_j . 

Roles mainly control what actions they can perform — like wipe, lock, manage apps, edit policies, and so on. 

If you only split roles, they might still see the entire fleet. To actually limit which devices they can see, you need to configure the scope. 

Marked SolutionPending Review
Participant
1 week ago Feb 23, 2026
Marked SolutionPending Review

So, roles don’t control visibility? 

Marked SolutionPending Review
Participant
6 days ago Feb 24, 2026
Marked SolutionPending Review

Not fully. 

Think of it this way: 

Role = what they’re allowed to do

Scope = which devices those permissions apply to 

You can give two techs the same role, but if one is scoped to “North Devices” and the other to “South Devices,” they’ll only see their assigned groups. 

Marked SolutionPending Review
Participant
6 days ago Feb 24, 2026
Marked SolutionPending Review

We made this mistake early on. 

Created region-based roles, thought we were done. Logged in as a regional tech and… still seeing everything 😅. 

Had to go back and restrict by device groups under scope. 

Marked SolutionPending Review
Participant
6 days ago Feb 24, 2026
Marked SolutionPending Review

One tip: make sure your regional device groups are clean before applying scope. 

If the group structure is messy, the visibility will be messy too. 

Marked SolutionPending Review
Participant
6 days ago Feb 24, 2026
Marked SolutionPending Review

Got it. So separate roles if needed, but scope is what actually hides devices. 

That clears it up. 

Save