For MSP staff with permission to edit Company users. Company administrators request access changes from their IT provider; they do not manage their own users or permission roles through these settings.
Choose the kind of change
Team Roles are separate organizational roles. They are not the permissions group you select in the Company user editor.
Change one user
1
Find the Company user
Open Settings > Users & Roles, then select Company Users. Use the company scope and table filters to find the right person. Confirm the company and email as well as the name.
2
Open the editor
Select the user’s name, or use the row’s … menu and edit action. The user’s details open in a dialog.
3
Select the permissions group
In Permissions, choose the intended Permissions Group. The list contains the roles available for Company users. Changing the selection does not save yet.
4
Save and verify
Select Save Changes and wait for the result. Confirm the user’s Permissions Group in the table. If other edited fields caused a save error, reopen the user and check what was saved before retrying.
Update several users
- Filter the Company Users table to the intended company and users.
- Select the users’ checkboxes. Review the selected count and whether you selected specific rows or all matching results across pages.
- Open the selection’s actions and select Update Permissions.
- In Bulk Update Permissions, choose the Permissions Group to apply to every selected user.
- Select Save, wait for the result, and verify the affected users.
Check the result
Confirm the saved group, then have the Company user reopen the relevant portal area. If their session still shows old access, ask them to sign out and back in and try again. A permissions group is only part of feature availability. The relevant company, enabled module, integration, record visibility, and action-specific requirements still apply. Granting a role does not create missing provider data or enable an integration.Frequently asked questions
Can a Company administrator change another user's permissions?
Can a Company administrator change another user's permissions?
Company user administration is performed by the MSP. The Company administrator should request the change from their IT provider.
Will changing one user's Permissions Group change other users?
Will changing one user's Permissions Group change other users?
Assigning a different existing group to one user changes that user’s assignment. Editing the group’s permission definition affects the users assigned to that role.
Are permission changes saved as soon as I choose a group?
Are permission changes saved as soon as I choose a group?
No. Use Save Changes for one user or Save in the bulk dialog. Cancel closes the dialog without submitting the selection.
What does No permissions group do?
What does No permissions group do?
Saving it clears the role assignment. It does not preserve the old group or delete the user record. Verify the resulting access rather than treating it as a general account-deactivation action.
Why is the role I want missing?
Why is the role I want missing?
The Company user editor offers Company-assignable roles. An MSP staff role is a different role type. Ask an MSP administrator to review or create the appropriate Company role if needed.
Does granting a Company role give access to MSP settings?
Does granting a Company role give access to MSP settings?
Company permission roles control the Company portal experience. They do not turn a Company user into MSP staff or grant tenant-wide settings access.
Can I use Update Permissions for every matching user across pages?
Can I use Update Permissions for every matching user across pages?
The table supports selection across matching results. Check the selection count and scope before applying a bulk change; filtering the table alone does not apply a role.
I received a save error. Did nothing change?
I received a save error. Did nothing change?
Do not assume that. Single-user edits can save several kinds of changes, and bulk updates can affect some users before reporting a problem. Reopen the affected records and verify their groups before retrying.