Skip to main content
MSP staff use Settings > Users & Roles to manage portal users and their access. The available tabs and actions depend on your administrative permissions.
Company user administration is performed by the MSP. Company administrators request user or permission changes from their IT provider. A Company role does not grant access to MSP settings.

Choose a tab

Company Roles within the Roles tab are permission sets. Team Roles are a separate concept. Onboarding contact roles are also configured separately for the onboarding workspace.

Compare every role

The Permission Matrix sub-tab on the Roles tab shows every role at once, so you can see exactly what each role can reach without opening each one. Each row is a permission and each column is a role. The column header shows how many active users hold the role.
Permission Matrix sub-tab of the Roles tab, with a row per permission and a column per role, each cell showing None, Read, Write, or Manage

Permission Matrix for Tenant roles in MSPortal Demo.

  1. Open Settings > Users & Roles > Roles, then select Permission Matrix.
  2. Choose Tenant roles or Company roles.
  3. Read each cell as the role’s access level. Manage includes Write and Read, and Write includes Read.
  4. Select the arrow beside a permission such as Projects to see its detailed options, like which project views a role can open.
A Custom tag means the role’s detailed options differ from the defaults for its level. Expand the row to see them. Use the column filters to narrow the matrix. For example, filter a role’s column to Manage to list everything that role fully controls, or filter Section to Settings. Use Columns to hide roles you are not comparing.

Change access from the matrix

If you can edit roles, each cell is a control:
  1. Change the level in a cell, or tick a detailed option in an expanded row. Edited cells are outlined.
  2. Repeat for any other roles. Nothing is saved yet.
  3. Select Save changes to save every edited role, or Discard to drop the edits.
Permission Matrix with one edited cell outlined and the toolbar showing Unsaved changes to 1 role, Discard, and Save changes

An unsaved change to one role, outlined, with Save changes and Discard in the toolbar.

Saving a role changes access for every user who holds it. Options that Manage grants stay locked until you lower the level. To rename a role, set it as the default, or change Company role settings such as quote visibility, use the Role List sub-tab.

Global team roles and membership automation

The Global Team Roles guide previews assigning the same staff across companies, preserving company-specific exceptions, and automating additions or removals. This feature is a branch preview and is separate from permission-role administration.

Change access

Changing one user’s role assignment and editing the role itself have different effects. A role edit affects the shared permission definition for users assigned to that role. Use a separate role when only a subset needs different access.

Work with user lists

Choose the correct user type before looking up a person. Confirm their name, email, and company, where applicable. Table filters and the current company scope affect which Company users appear. Selection actions operate on the selected users. Review the count and whether the selection includes matching results across multiple pages before applying a bulk action. An error can report partial completion; verify the affected records before retrying. Invitation emails, user role assignments, permission-role definitions, and account removal are separate operations. A role change does not send an invitation or create missing company data. Clearing a Permissions Group does not delete the user record.

Check feature availability

Permissions determine allowed actions, while other settings determine what data or features are available. When a user cannot do something, check:
  1. Their user type and saved role assignment.
  2. The permissions in that role, including the specific action they need.
  3. Their company scope and any record-specific visibility.
  4. Whether the module and required provider integration are configured.
  5. Any restriction shown by the workflow itself.
If a saved change is not reflected in an existing user session, have the user sign out and back in before testing again. Do not infer access solely from a role’s name or a visible menu item.

Frequently asked questions

Company Users. Users contains MSP staff accounts.
In Roles > Company Roles. To assign an existing group to a particular user, edit the user’s Permissions Group in Company Users.
Viewing roles and editing them are separate permissions. Tenant roles need write access to roles, and Company roles need write access to Company users.
User, role, and Company-user administration have separate permissions. Ask the MSP administrator to review the administrative access needed for your task.
No. The MSP manages Company users and permissions. The role name describes a Company permission set, not MSP administrator status.
No. The Primary Admin account flag is separate from the role’s name and permission definition.
MSPortal disables a Company user when the connected systems show they have left:
  • Microsoft 365: every Microsoft 365 account linked to the user has sign-in blocked. This applies even if their PSA contact is still active.
  • PSA: their contact is marked inactive in ConnectWise, Autotask, or Halo PSA, and they have no other active contact.
A disabled user loses portal access and is signed out. They no longer appear in user dropdowns such as a ticket form’s employee field. Company Users hides them unless you filter Status to Disabled. If sign-in is unblocked in Microsoft 365, the next sync restores a user disabled by the Microsoft 365 rule.
No. Team responsibilities and permission-role assignments serve different purposes. Use Tenant or Company permission roles to define portal access.