> ## Documentation Index
> Fetch the complete documentation index at: https://docs.msportal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Change a Company user’s permissions

> MSP guide to assigning a permissions group to one Company user or a selected group of users.

MSP staff manage Company user access in **Settings > Users & Roles > Company Users**. A user's **Permissions Group** assigns the Company role that controls what they can do in the portal.

<Note>
  For MSP staff with permission to edit Company users. Company administrators request access changes from their IT provider; they do not manage their own users or permission roles through these settings.
</Note>

## Choose the kind of change

| Your intention                                            | What to change                                                                         |
| --------------------------------------------------------- | -------------------------------------------------------------------------------------- |
| Give one user a different existing set of permissions     | Change that user's **Permissions Group**                                               |
| Give several selected users the same existing permissions | Use **Update Permissions** on the selection                                            |
| Change what everyone assigned to a role can do            | [Edit the permission role](/user-guides/getting-started/how-to-create-a-new-user-role) |
| Create a different set for a subset of users              | Create or duplicate a role, review it, then assign it to those users                   |

**Team Roles** are separate organizational roles. They are not the permissions group you select in the Company user editor.

## Change one user

<Steps>
  <Step title="Find the Company user">
    Open **Settings > Users & Roles**, then select **Company Users**. Use the company scope and table filters to find the right person. Confirm the company and email as well as the name.
  </Step>

  <Step title="Open the editor">
    Select the user's name, or use the row's **…** menu and edit action. The user's details open in a dialog.
  </Step>

  <Step title="Select the permissions group">
    In **Permissions**, choose the intended **Permissions Group**. The list contains the roles available for Company users. Changing the selection does not save yet.
  </Step>

  <Step title="Save and verify">
    Select **Save Changes** and wait for the result. Confirm the user's Permissions Group in the table. If other edited fields caused a save error, reopen the user and check what was saved before retrying.
  </Step>
</Steps>

The editor can also contain email, company, location, and custom fields. Review those separately if you intend to change them. A role assignment controls permissions; changing the person's company is a different operation.

## Update several users

1. Filter the Company Users table to the intended company and users.
2. Select the users' checkboxes. Review the selected count and whether you selected specific rows or all matching results across pages.
3. Open the selection's actions and select **Update Permissions**.
4. In **Bulk Update Permissions**, choose the **Permissions Group** to apply to every selected user.
5. Select **Save**, wait for the result, and verify the affected users.

<Warning>
  **No permissions group** clears the selected users' role assignments. It does not mean “leave their current permissions unchanged.” The bulk dialog starts with this option, so choose the intended group before saving.
</Warning>

If the result reports that some changes were not permitted, check the users individually. A partial failure does not mean every user's previous group was preserved.

## Check the result

Confirm the saved group, then have the Company user reopen the relevant portal area. If their session still shows old access, ask them to sign out and back in and try again.

A permissions group is only part of feature availability. The relevant company, enabled module, integration, record visibility, and action-specific requirements still apply. Granting a role does not create missing provider data or enable an integration.

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Can a Company administrator change another user's permissions?">
    Company user administration is performed by the MSP. The Company administrator should request the change from their IT provider.
  </Accordion>

  <Accordion title="Will changing one user's Permissions Group change other users?">
    Assigning a different existing group to one user changes that user's assignment. Editing the group's permission definition affects the users assigned to that role.
  </Accordion>

  <Accordion title="Can I give one person extra access without changing the shared role?">
    Create or duplicate an appropriate role, change its permissions, and assign it to that person. Check the role definition before assigning it.
  </Accordion>

  <Accordion title="Are permission changes saved as soon as I choose a group?">
    No. Use **Save Changes** for one user or **Save** in the bulk dialog. Cancel closes the dialog without submitting the selection.
  </Accordion>

  <Accordion title="What does No permissions group do?">
    Saving it clears the role assignment. It does not preserve the old group or delete the user record. Verify the resulting access rather than treating it as a general account-deactivation action.
  </Accordion>

  <Accordion title="Why is the role I want missing?">
    The Company user editor offers Company-assignable roles. An MSP staff role is a different role type. Ask an MSP administrator to review or create the appropriate Company role if needed.
  </Accordion>

  <Accordion title="Does granting a Company role give access to MSP settings?">
    Company permission roles control the Company portal experience. They do not turn a Company user into MSP staff or grant tenant-wide settings access.
  </Accordion>

  <Accordion title="Can I use Update Permissions for every matching user across pages?">
    The table supports selection across matching results. Check the selection count and scope before applying a bulk change; filtering the table alone does not apply a role.
  </Accordion>

  <Accordion title="I received a save error. Did nothing change?">
    Do not assume that. Single-user edits can save several kinds of changes, and bulk updates can affect some users before reporting a problem. Reopen the affected records and verify their groups before retrying.
  </Accordion>
</AccordionGroup>

## Related guides

* [Create and edit permission roles](/user-guides/getting-started/how-to-create-a-new-user-role)
* [Users & Roles settings](/user-guides/settings/users-roles)
* [Company guide: Understand your access](/user-guides/account/understand-your-access)
