Multi-Tenancy (ish)
Snipe-IT offers a sort of multi-tenancy within the application, which allows super-admins to restrict the assets non-super-admins can see.
This guide explains how Snipe-IT restricts what users can see and do based on company membership. These features are designed for organizations that manage assets across multiple companies or business units and need to keep those companies' data separated.
Full Multiple Company Support (FMCS)
Setting: Admin → General Settings → Full Multiple Company Support.
When FMCS is off (the default), everyone with the right permissions sees every record in the system: assets, users, licenses, locations, everything.
When FMCS is on, Snipe-IT filters lists, searches, dropdowns, exports, imports, and API responses to only include records that belong to the same company as the user viewing them.
A single user can be assigned to more than one company. That user sees the union of records across all of those companies.
Superusers are always exempt. They see everything no matter how FMCS or the settings below it are configured.
Floater Mode
Setting: Admin → General Settings → Treat items and users without company associations as floaters.
FMCS only knows what to do with records that have a company assigned. Floater mode controls what happens to records that DON'T have a company assigned.
Floater mode OFF (the default). Records with no company assigned are treated as belonging to their own invisible bucket. They are only visible to other records that also have no company assigned.
- A user in Company A cannot see assets, users, or locations that have no company.
- A user with no company cannot see any records that do have a company.
- An asset with no company can only be checked out to a target that also has no company.
Use this mode when you want strict isolation between companies AND you want any legacy uncompanied data kept walled off from the rest of the system.
Floater mode ON. Records with no company assigned "float" and are visible to everyone.
- A user in Company A can see their own company's records AND every uncompanied record.
- A user with no company can see every record in the system.
- An asset with no company can be checked out to anyone.
- Any asset can be checked out to a target that has no company.
Use this mode when you have shared resources that any company's users should be able to access, such as a pool of spare laptops or a shared conference-room location.
Location Scoping
Setting: Admin → General Settings → Scope Locations with Full Multiple Company Support.
This setting requires FMCS to be on. It controls checkout validation for locations.
When location scoping is off (the default with FMCS on), Snipe-IT doesn't check whether the destination location's company matches the item's company at checkout time. A user can still only SEE their own company's locations in dropdowns, but if the location and the item somehow ended up with different companies, the checkout would still be allowed.
When location scoping is on, Snipe-IT rejects any checkout where the location's company doesn't match the item's company. If you try to save a mismatch, you'll see a validation error.
Turning this setting on requires running the built-in compatibility check first. Snipe-IT scans your existing data for users or assets already sitting in a location that belongs to a different company. If any conflicts are found, you'll need to resolve them before the setting can be enabled, or your existing records would start failing the new rule immediately.
Quick reference for the base behavior
What a user assigned to Company A sees, and whether they can use a no-company location:
| FMCS | Floater | Location Scoping | Sees | Can use a no-company location |
|---|---|---|---|---|
| Off | (any) | (any) | Everything | Yes |
| On | Off | Off | Company A records only | No, no-company locations aren't visible to them |
| On | Off | On | Company A records only | No |
| On | On | Off | Company A records plus every no-company record | Yes |
| On | On | On | Company A records plus every no-company record | Yes, only if the location also has no company assigned |
Superusers always see everything regardless of the settings above.
Parent Companies
Parent companies let you group related companies into a two-level hierarchy. You can promote a company to be the parent of one or more other companies. Snipe-IT then treats membership in the parent as covering membership in each of its children.
The rules
- Every company can optionally point to another company as its parent.
- The hierarchy is exactly one level deep. A child company cannot itself be a parent. Snipe-IT will refuse to save that arrangement.
- A parent company cannot be deleted while it still has children. You need to reassign or delete the children first.
- If you have a saved company you want to make a parent, the child companies you want to attach to it must not themselves already be parents.
What membership in a parent company means
Adding a user to a parent company automatically extends their visibility to every child of that parent. If your user is a member of "Acme Corp" and Acme Corp has two children "Acme West" and "Acme East", that user sees records from all three: Acme Corp, Acme West, and Acme East. You do NOT need to add them to the children separately.
The reverse is not true. Adding a user to a child company only gives them access to that specific child. Membership in "Acme West" does not extend to "Acme East" and does not extend to "Acme Corp."
If a use case is "everyone in the group should see each other's records," add each user to the parent company, not to individual children.
What checking out looks like across the hierarchy
Snipe-IT allows checkouts along the parent-child line, in these directions:
- A user in a parent company can receive items that belong to any child of that parent, in addition to items that belong to the parent itself.
- A user in a child company can only receive items that belong to that child, not items from the parent or from other children.
- When location scoping is on, a location that belongs to either the parent OR one of its children is a valid destination for an item in any company in that same hierarchy branch.
Asset-to-asset checkout (attaching one asset to another as its container) does NOT walk the hierarchy. The two assets must belong to the same specific company.
Parent companies and Floater Mode
Parent companies and floater mode work independently. Turning floater mode on doesn't change how the parent-child rules behave. Turning parent-child on doesn't change how floater mode behaves.
Example. A user is a member of Acme Corp (a parent) whose children are Acme West and Acme East. In addition to Acme's records, they have some legacy assets in the system that have no company assigned.
- With floater mode off, that user sees records from Acme Corp, Acme West, and Acme East, but not the legacy no-company assets.
- With floater mode on, that user sees all four categories.
Parent companies and Location Scoping
Location scoping considers the whole one-level hierarchy when validating a checkout. A location whose company is anywhere in the item's parent-child line is accepted. That way, if you use a parent company for shared inventory and children for regional teams, a location in the parent can still receive items owned by any child, and vice versa.
If you want locations to be shared across your children, put the shared location in the parent company. Users of the children will see and use it correctly.
Quick reference for parent companies
| Situation | Result |
|---|---|
| User added to parent only | Sees parent + all children |
| User added to one child only | Sees only that child |
| User added to two children (siblings) but not the parent | Sees each of those two children separately, not the parent, not the third sibling |
| User added to parent AND a specific child | Same as parent alone (child membership is already implied) |
| Superuser | Sees everything regardless of hierarchy |
| Checking out a parent-company item to a child-company user | Not allowed |
| Checking out a child-company item to a parent-company user | Allowed |
| Checking out an item to a location in the same parent-child branch, with location scoping on | Allowed |
| Deleting a company that has children | Not allowed until children are re-parented or deleted |
| Making a child company itself a parent | Not allowed |
Common questions and gotchas
"I added a user to a child company but they can't see items from the parent."
That's expected. Membership only expands downward, from parent to children. If you want the user to see records from both, add them to the parent instead of the child.
"I want two sibling companies to see each other's data."
Add the users to the parent company. Membership in sibling children does not automatically bridge across siblings.
"Turning on Location Scoping fails compatibility check."
Snipe-IT is telling you that some of your current users or assets are already assigned to a location whose company doesn't match. Fix those records first, then rerun the check.
"Under Location Scoping, I want a shared location for all my regional teams."
Put the shared location under the parent company. Because location scoping accepts any location in the same parent-child branch, users of the children can still be checked in and out to it.
"Turning off Location Scoping doesn't make no-company locations visible to companied users."
Correct. Location Scoping only affects checkout validation, not visibility. To make a location visible across companies, put it under a common parent or make it uncompanied AND turn floater mode on.
"My child company won't delete."
If it has children (which shouldn't happen because of the one-level limit, but occasionally legacy data slips through), reassign or delete those first. If it has no children but still won't delete, check whether it still has assets, users, or other records assigned to it that block deletion for the normal reasons.
Updated 16 days ago
