Access in ICP is organized around your organization (your workspace), the people in it, and the permissions they hold. Everyone gets in through Microsoft sign-in with role-based permission groups — there's no separate password for your team to manage.
Signing in
Everyone signs in with Microsoft using their work account. A person can belong to more than one organization and choose which to sign into — but only among the ones they actually belong to.
Roles are permission groups
Authorization is expressed as fine-grained permissions bundled into named permission groups. Every organization has four built-in groups, and you can add your own.
| Built-in group | Can do |
|---|---|
| Admin | Everything, including access administration |
| Dispatcher | Runs the board — full ticket and work-order lifecycle, dispatch, device and customer management (but not access admin) |
| Technician | Reads their own work and acts only on their own assigned orders |
| Viewer | Read-only |
Custom groups let you build your own roles from the permission catalog. Permissions include things like: site read; ticket read/create/acknowledge/resolve; dispatch assign; work-order read/create/schedule/dispatch/cancel and on-site check-in/complete (own vs. any); manage permission groups; manage members; manage devices and monitoring; and manage customers.
Members
Members are the people in your organization — one membership each. Admins can reassign a member's group and link them to a technician record. A few safety rules keep access sane:
- You can't grant a group whose permissions you don't hold yourself
- You can't act on a member who outranks you
- You can't remove the organization's last administrator
Invitations
The only way to bring a new person in is an invitation:
Invite a Microsoft identity into a group
An admin invites a specific person (by their Microsoft identity) into a permission group.
It redeems automatically
The invitation is redeemed the next time that person signs in — no separate acceptance step. Unused invitations expire.
Invitations can be listed and revoked before they're used.
Audit log
Every significant action is recorded in the audit log — actor, action, entity, and outcome, with a timestamp. Admins can review it in the console and export it to CSV.
Tip
Give people the narrowest group that lets them do their job, and use custom groups when the four built-ins don't fit — for example, a "senior technician" who can act on any order, not just their own.
