An organization buys seats, not features. This page puts the two together: the products on one side, the user types an administrator hands out on the other, and one table saying which of them may do each thing.
The table is not written by hand. Every tick is read from the platform's own permission model when the documentation is built, and the build fails if the two disagree — so nothing here can promise something the product refuses.
Products¶
Everything in the list is one platform and one sign-in — a layer published in one is the layer the others read.
- Hyz Workspace — Load your layers, run the analysis, share the result — in the browser. from Contributor
- Hyz Maps — Publish an interactive map your teams or the public open by link. from Editor
- Hyz Dashboards — Operational dashboards over your data — indicators, charts and a map that filter each other. from Editor
- Hyz Field — Send crews out with a form, capture offline, review what comes back. from Contributor
- Hyz Data Items — Your organization's data as items people can open, download, edit and version. from Contributor
- Hyz Services — Turn a layer into tiles, features and OGC endpoints other systems can call. from Publisher
- Hyz Catalog — One index of everything published — searched in Arabic and English. from Viewer
- Hyz Data Rooms — Hand a data item to a party outside the organization, with an access log. from Editor
- Hyz AI — Describe the dashboard, the map style or the layer you want and review what it proposes. from Contributor
- Hyz Console — Members, roles, sign-in, seats, applications and the audit log for the whole organization. from Security administrator
- Hyz API — Call the same geoprocessing from your own systems. from Administrator
- Hyz Desktop — The native workbench with a local engine, for the heavy work. from Contributor · coming soon
- Hyz Earth — A globe for the data you already publish — briefings and flythroughs rather than a workbench. from Viewer · coming soon
User types¶
These are the roles an administrator assigns in the Console. Two more exist and are not seats you buy: the organization's owner, and any custom role your administrator writes.
- Viewer — Opens and downloads what the organization has shared with them. Changes nothing.
- Contributor — The field and data-entry seat: adds and edits records, uploads a new version, creates a data item or a workspace.
- Editor — Makes the things people open — maps, dashboards, campaigns and data rooms — and shares them inside the organization.
- Publisher — Everything an Editor does, and decides what leaves the organization: publishes a layer, a service or a map.
- Content manager — Answers for the organization's content as a whole — publishes, deletes, and transfers ownership when someone leaves.
- Security administrator — Members, roles, sign-in and the audit log. Reads content but does not author it — the split that lets you separate the two duties.
- Administrator — Both halves at once: everything the content manager and the security administrator hold, and the organization's API applications.
What each user type may do¶
Read across a row to see which seats include it. A blank is a refusal the product enforces, not a limit we chose for this page.
Open and read¶
|
Viewer |
Contributor |
Editor |
Publisher |
Content manager |
Security administrator |
Administrator |
| Open a data item shared with them |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
| Download the data behind it |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
| Open a map |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
| Open a dashboard |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
| Open a data room |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
Collect and edit data¶
|
Viewer |
Contributor |
Editor |
Publisher |
Content manager |
Security administrator |
Administrator |
| Add records to a layer |
— |
✓ |
✓ |
✓ |
✓ |
— |
✓ |
| Edit and delete records |
— |
✓ |
✓ |
✓ |
✓ |
— |
✓ |
| Upload a new version of a data item |
— |
✓ |
✓ |
✓ |
✓ |
— |
✓ |
| Create a data item |
— |
✓ |
✓ |
✓ |
✓ |
— |
✓ |
| Create a workspace and run analysis |
— |
✓ |
✓ |
✓ |
✓ |
— |
✓ |
Make maps, dashboards and campaigns¶
|
Viewer |
Contributor |
Editor |
Publisher |
Content manager |
Security administrator |
Administrator |
| Create a map |
— |
— |
✓ |
✓ |
✓ |
— |
✓ |
| Create a dashboard |
— |
— |
✓ |
✓ |
✓ |
— |
✓ |
| Create a field campaign |
— |
— |
✓ |
✓ |
✓ |
— |
✓ |
| Create a data room |
— |
— |
✓ |
✓ |
✓ |
— |
✓ |
| Make a layer editable, and lock its features |
— |
— |
✓ |
✓ |
✓ |
— |
✓ |
| Share inside the organization |
— |
— |
✓ |
✓ |
✓ |
— |
✓ |
Publish outside the organization¶
|
Viewer |
Contributor |
Editor |
Publisher |
Content manager |
Security administrator |
Administrator |
| Publish a layer |
— |
— |
— |
✓ |
✓ |
— |
✓ |
| Publish a data item as a service |
— |
— |
— |
✓ |
✓ |
— |
✓ |
| Share a published service by link |
— |
— |
— |
✓ |
✓ |
— |
✓ |
| Publish a map to the public |
— |
— |
— |
✓ |
✓ |
— |
✓ |
Administer the organization¶
|
Viewer |
Contributor |
Editor |
Publisher |
Content manager |
Security administrator |
Administrator |
| Create API applications and keys |
— |
— |
— |
— |
— |
— |
✓ |
| Delete the organization's content |
— |
— |
— |
— |
✓ |
— |
✓ |
| Transfer ownership to someone else |
— |
— |
— |
— |
✓ |
— |
✓ |
| Invite, suspend and remove members |
— |
— |
— |
— |
— |
✓ |
✓ |
| Assign roles and write custom ones |
— |
— |
— |
— |
— |
✓ |
✓ |
| Configure sign-in, SSO and directory sync |
— |
— |
— |
— |
— |
✓ |
✓ |
| Read the audit log |
— |
— |
— |
— |
— |
✓ |
✓ |
Connects to what you already run¶
None of these is a separate purchase.
- Single sign-on (SAML and OpenID Connect) — Your identity provider issues the session. Active Directory, Entra ID, Okta or anything speaking SAML 2.0 or OIDC.
- Directory sync (SCIM) — Members and groups arrive from your directory, and a person removed there loses access here.
- Linked services — Read an Esri REST or OGC service you already publish as a live layer — no copy, no scheduled export.
- Open standards out — What you publish is readable by any desktop or web client that speaks WMS, WFS, OGC API Features, or vector tiles — no adapter of ours in between.
- Power BI connector — Pull a published Hyz service into a Power BI report as a refreshing table and map. (coming soon)
Where it runs¶
The same products and the same user types. The edition decides where the data sits.
- Haiyz Cloud — We run it. Data in the Kingdom, seats bought per month, upgrades arrive when they ship.
- Haiyz Enclave — You run it, on your own servers, with no outbound connection required. Available on a quarterly release channel; installs are scheduled with us.
How to read this page¶
Every tick is read from the platform's authorization model when the documentation is built, and the build fails if the two disagree. If a row here says a user type may do something, the product will let them; if it is blank, the product returns a refusal.