Multiple digital-twin users: shared camera or independent navigation?

Multiuser access does not automatically mean a shared camera. Business data can be common while navigation remains independent; presentation and collaboration need explicit control rules.

On this page5 sections

Several people opening the same digital twin should not automatically compete for its camera. First decide whether they share business data, a presentation view or a collaborative control session. Independent equipment inspection, presenter-led viewing and collaborative operation are different requirements. “Supports multiple online users” does not describe the expected behavior adequately.

Define which state is shared

StateIndependent useShared presentation
Equipment business dataRead under each user's permissionsDisplay within the session's allowed scope
Camera and floorIndependent for each userPresenter-controlled or explicitly followed
Filters and selected objectDo not overwrite another user's stateSpecify what follows the presentation
Business changesGoverned by business authorizationCamera control does not grant editing rights

The ability to move a camera does not establish permission to acknowledge alarms, edit an asset or control equipment. Accept presentation control separately from business authorization. Sharing a view also does not mean that every viewer is entitled to every piece of data that may appear in it.

One shared stream differs from independent scenes

Epic's Pixel Streaming hosting guide describes one Unreal Engine instance serving browser endpoints with different viewing or control interfaces. The page inspected here is presented as UE 5.8 documentation; an actual project must verify its own version. This shows a shared-session route, not an automatic independent world for every connected browser.

If every user needs a separate camera and navigation state, establish whether rendering happens independently on each terminal, whether separate server sessions are allocated, or whether multiple views are implemented inside the engine. These approaches have different resource and maintenance conditions. Validate capacity with the actual scene, terminals, network and resources rather than deriving an architecture from an unsupported user-count promise.

Make presentation takeover explicit

A shared presentation can distinguish presenter, follower and temporary independent viewer. Specify who can start control, whether followers may leave, which camera is retained on leaving, and whether rejoining requires confirmation. Someone inspecting a fault should not be pulled away without explanation merely because a remote presenter changed the view.

For collaborative control, define who holds control at a particular time, how it is transferred and how it is released after disconnection. Hiding buttons in a player page reduces accidental input but is not an authorization mechanism. The receiving service must validate requests. A shared presentation address should not bypass the original identity checks.

Prevent another user's state from leaking through reconnection

After a participant leaves, the remaining cameras and filters should behave according to the agreed session type. A newcomer to a shared presentation may join its current state. A newcomer to an independent session needs an appropriate starting view, not a previous user's private filters or retained data.

Also define behavior when one account is used on several devices. If only one controlling endpoint is permitted, make takeover explicit. If independent use is permitted, a later page should not silently overwrite the first device's actions. Reconnection should establish the current session and control rights before accepting renewed input. Test abandoned sessions as well as an orderly logout.

Accept the behavior with at least two terminals

Use two accounts with different permissions. Rotate and filter on one terminal while locating equipment on the other, and confirm the expected independence or following relationship. Then transfer control, disconnect, reconnect, leave, join as a new user and attempt an unauthorized control request. Keep recordings from both endpoints and session records. Several tabs in one browser do not fully represent separate terminal conditions.

WebGL , Cesium , Unity and UE for Digital Twins: How to Choose discusses implementation routes, while Existing Unity or UE Digital Twin Project: What to Check Before Continuing Development supports assessment of an existing engine project. For this part of digital twin development services (Chinese), deliver a shared-state table and two-endpoint behavior examples before testing capacity. Being able to connect simultaneously is not the same as enabling each person to complete the intended task.