Skip to main content
Open Settings > Users & Roles > Roles to manage the permission sets assigned to users. The page separates Tenant Roles for MSP staff from Company Roles for Company users.
For MSP staff with access to role settings and permission to create or edit the relevant role type. Company role administration uses Company-user management permissions. Deleting and duplicating roles require the corresponding management permission.

Choose the role type

A role named Administrator does not set the account’s Primary Admin flag. A role named Company Admin does not make Company users administrators of MSP settings or user management.

Create a role

1

Choose the correct section

In Roles, select Add Role in Tenant Roles or Company Roles, according to the users who will receive it.
2

Describe the role

Enter a clear Name and Description. The dialog title identifies the type, such as Create Company Role.
3

Choose permissions

Use Search permissions to find the relevant resource, then choose its available Read, Write, and Manage controls. Review group and column selections carefully: All can affect multiple permissions.A dash indicates that the particular resource does not offer that control. Viewing a resource does not automatically permit every action within it.
4

Create and check the role

Select Create Role, wait for success, and find the new role in the appropriate section. Reopen it to verify its permissions before assigning it to users.
Create Company Role dialog with name, description, ticket display group, permission matrix, and Create Role button

Unsaved Company role editor in the MSP view. This example names the role but has not selected or saved permissions.

Creating a role does not assign existing users to it. Use the relevant user editor afterward; Company users follow change a user’s permissions.

Edit a role’s permissions

  1. Select the role name or its … > Edit action.
  2. Wait for its current permissions to load. Review the existing selections before changing them.
  3. Adjust the required permissions and any relevant role options.
  4. Select Update Role and wait for the result.
  5. Reopen the role to verify the saved definition, then check the intended workflow with a user assigned to it.
Editing a role changes the permission definition used by all users assigned to it. For a change intended for only one person or a subset of users, create or duplicate a separate role and assign that role to those users.
If a save fails, reopen the role and check its name, permissions, and options before retrying. The editor can save these through separate operations; an error does not guarantee that every part remained unchanged.

Duplicate a role

Open the role’s … menu and select Duplicate. This creates a copy immediately; it does not open an unsaved creation form first. Find the copy, edit its name and permission selections, and select Update Role. Duplication copies role configuration, not user assignments. Review the copy before assigning it, including any Company ticket or quote visibility settings and staff company-scope options.

Import a starting role

Where Import is available in a role section, open it and read the preset descriptions. Selecting an available preset creates the role; it is not a preview. Already imported presets are marked or unavailable. Review the imported role’s actual permissions and assign it deliberately. Preset names describe a starting configuration; they do not override Company scope, feature availability, or account-level administrator status.

Set a default and review extra options

After creating the role, reopen it to review its saved options. To choose a default, select the intended role and save its Default role for new… users setting. Tenant role menus also provide Set as Default, which saves immediately. Check the default indicator in the role list. To replace a default, choose the other intended role; do not treat unchecking the current default as a reliable way to leave no default. Choosing a default does not reassign all existing users. Depending on the role type and available features, the editor can also include:
  • Bypass Company Restrictions for staff roles. This affects staff company scope; it does not enable missing integrations or supply all action permissions.
  • Product-update email preferences for staff roles. Review these after the role is created, alongside the user’s personal notification preferences.
  • Ticket Display Group for Company roles, when configured groups are available.
  • Additional visibility controls for resources such as Calendar or Quotes, when available. Review the resource’s options as well as its basic permission checkbox.
These options are part of the role definition. Verify them after saving, especially when changing an existing role used by several users.

Delete a role

Reassign users before removing a role they rely on. Use the role’s … > Delete action only for a role you intend to remove. The Tenant Roles delete menu submits the deletion directly. The Company Roles flow opens a deletion confirmation. Follow any dependency or permission error; do not assume every role can be deleted. Deleting a role is a different action from deleting its user accounts.

Frequently asked questions

In Settings > Users & Roles > Roles, use Add Role under Company Roles. Assign the resulting role through the Company user’s Permissions Group field.
The MSP manages Company users and permission roles. Company administrators request access changes from their IT provider.
Creation does not assign existing users. Editing a role already assigned to users changes their shared permission definition.
No. A role name and permission set are separate from the account’s Primary Admin flag. The Company Admin preset also does not grant MSP user-management access.
No. Duplicate creates the copy immediately. Edit and review the new role before assigning it.
Import creates a role from the preset. User assignments remain a separate step.
No. Use the controls available for each resource. Some resources expose fewer actions, and some have additional visibility settings.
Confirm the saved role and the user’s assignment, then check company scope, module availability, integration setup, and record visibility. If the user still has an old session view, have them sign out and back in before checking again.
No. Team Roles represent organizational responsibilities. Tenant and Company permission roles define portal access.
No. Existing user assignments are separate. Check the actual selected role when adding, importing, or editing users.