Skip to main content
Create permission roles for your own team, then assign them to staff. This page is for MSP administrators with role-management access.

Before you start

  • You must be the Primary Admin or have role-management access in Settings > Users & Roles.
  • Plan which modules each kind of staff member needs, for example help desk, account manager, or read-only.
  • Tenant Roles are for MSP staff. Company Roles are for your clients’ users. See Company access groups.
Tenant Roles are the permission-bearing roles for internal staff.

Tenant Roles are the permission-bearing roles for internal staff.

Create a staff role

1

Open the Roles tab

In Launch Center, select Access and permissions in Setup guide. It opens Users & Roles on the Roles tab. You can also go to Settings > Users & Roles and open Roles.
2

Start a new role

In Tenant Roles, click Add Role. To start from an existing role instead, open its row menu and click Duplicate, then edit the copy.
3

Name the role

Enter a Name such as Help Desk Technician, and a Description. Check Default role for new Tenant users only if this role should be the default for new staff.
4

Set the permissions

Under Permissions, set Read, Write, or Manage for each resource in Main Navigation, MSP Tools, and Settings. Use Search permissions… to find a resource. The All checkbox on a section selects everything in it, so check before you save. You can only grant permissions you hold yourself.
5

Save the role

Click Create Role. To edit a saved role later, click Update Role.

Assign the role to staff

1

Open the Users tab

Go to Settings > Users & Roles and open Users.
2

Edit the user

Open the row menu for the person and click Edit. Choose the role in Role.
3

Save

Click Save Changes. Role changes apply the next time the user signs in.
4

Test the access

Ask the staff member to sign in and check that they can open what they need and nothing more. A role name alone does not prove what it permits.

Check launch readiness

In Launch Center, open Live verification. At least one permission group beyond Administrator is configured is a blocking check. It passes when your organization has at least one tenant or company group of its own other than Administrator. It does not check that each staff member holds the right role.

Troubleshooting

Frequently asked questions

No. Roles grant permissions. Team Roles describe responsibilities and grant none.
No. A new role has no users until you assign it.
No. Test a real staff account.