Choose a tab
Compare every role
The Permission Matrix sub-tab on the Roles tab shows every role at once, so you can see exactly what each role can reach without opening each one. Each row is a permission and each column is a role. The column header shows how many active users hold the role.
Permission Matrix for Tenant roles in MSPortal Demo.
- Open Settings > Users & Roles > Roles, then select Permission Matrix.
- Choose Tenant roles or Company roles.
- Read each cell as the role’s access level. Manage includes Write and Read, and Write includes Read.
- Select the arrow beside a permission such as Projects to see its detailed options, like which project views a role can open.
Change access from the matrix
If you can edit roles, each cell is a control:- Change the level in a cell, or tick a detailed option in an expanded row. Edited cells are outlined.
- Repeat for any other roles. Nothing is saved yet.
- Select Save changes to save every edited role, or Discard to drop the edits.

An unsaved change to one role, outlined, with Save changes and Discard in the toolbar.
Global team roles and membership automation
The Global Team Roles guide previews assigning the same staff across companies, preserving company-specific exceptions, and automating additions or removals. This feature is a branch preview and is separate from permission-role administration.Change access
- Change a Company user’s permissions: assign a different Permissions Group to one user or a selected set of users.
- Create and edit permission roles: define what the role permits, duplicate a starting role, or import a preset.
- Understand your own access: view your role and access information in your personal settings.
Work with user lists
Choose the correct user type before looking up a person. Confirm their name, email, and company, where applicable. Table filters and the current company scope affect which Company users appear. Selection actions operate on the selected users. Review the count and whether the selection includes matching results across multiple pages before applying a bulk action. An error can report partial completion; verify the affected records before retrying. Invitation emails, user role assignments, permission-role definitions, and account removal are separate operations. A role change does not send an invitation or create missing company data. Clearing a Permissions Group does not delete the user record.Check feature availability
Permissions determine allowed actions, while other settings determine what data or features are available. When a user cannot do something, check:- Their user type and saved role assignment.
- The permissions in that role, including the specific action they need.
- Their company scope and any record-specific visibility.
- Whether the module and required provider integration are configured.
- Any restriction shown by the workflow itself.
Frequently asked questions
Which tab manages employees at my customer companies?
Which tab manages employees at my customer companies?
Where do I change the permissions inside a Company permissions group?
Where do I change the permissions inside a Company permissions group?
Why is a cell read-only in the Permission Matrix?
Why is a cell read-only in the Permission Matrix?
Why can I see one settings tab but not another?
Why can I see one settings tab but not another?
Does Company Admin mean the customer can manage users?
Does Company Admin mean the customer can manage users?
Does an Administrator role make an account Primary Admin?
Does an Administrator role make an account Primary Admin?
Why was a Company user disabled automatically?
Why was a Company user disabled automatically?
- Microsoft 365: every Microsoft 365 account linked to the user has sign-in blocked. This applies even if their PSA contact is still active.
- PSA: their contact is marked inactive in ConnectWise, Autotask, or Halo PSA, and they have no other active contact.
Can I use a Team Role instead of a permission role?
Can I use a Team Role instead of a permission role?