Documentation

Platform

Platform overview

How the intSignal customer portal works for your organization: how people sign in, how access is decided, where each admin tool lives, and what only intSignal can change.

The intSignal customer portal, at portal.intsignal.com, is where your organization signs in to work with intSignal: tickets and support, security and network visibility, assets and monitoring, invoices and payments, and the administration of who can do what.

This section covers the account and access layer that sits under all of it. If you're an administrator setting things up for the first time, read this page, then Signing in and Users & invitations.

How people sign in

There are two kinds of accounts, and each person has exactly one:

  • Microsoft accounts use Sign in with Microsoft. This is the standard option for organizations on Microsoft 365. Your organization's own Microsoft sign-in rules, such as multi-factor authentication, apply.
  • Email accounts use an email address, a password, and a 6-digit code from an authenticator app. They exist for people who don't have Microsoft 365, and intSignal creates them on request.

Nobody gets in uninvited. A Microsoft account only works after an administrator has invited that email address. Full details, including first-time setup and troubleshooting, are in Signing in.

How access is decided

Every page and action in the portal is checked against three things, and all three must allow it:

  1. Modules enabled for your organization. intSignal switches modules on for your account, such as Monitoring or Budgets. A module that isn't enabled is hidden from everyone, administrators included.
  2. The person's permissions. Permissions come from roles and permission groups. A person can hold several, and they get everything any of them grants. See Roles & permission groups.
  3. The person's scope. Some people are limited to certain locations, and some to certain machines. See Users & invitations and Machine access.

Checks happen on every request, so changes apply immediately. If you disable someone or remove a role, their next click is already limited; they don't need to sign out first.

A menu item is missing

The sidebar only shows what a person can actually use. If an item is missing for one person, check their roles. If it's missing for everyone, including administrators, the module probably isn't enabled for your organization. Ask intSignal.

Your organization's structure

Your organization is set up by intSignal as a company, which can contain sub-companies and locations. The portal calls this your organization throughout.

Locations matter for access. By default, a person sees their whole company. When you assign someone to specific locations, they only see tickets for those locations. See Assign locations.

Where the admin tools are

Administration lives in the Admin group at the bottom of the portal sidebar. Each item only appears for people with the permission shown.

Sidebar itemWhat it's forWho sees it
UsersInvite people, change roles, disable accounts, assign locationsPermission to read users
Permission GroupsView built-in roles, create custom permission groupsPermission to read permission groups
Machine AccessLimit people to specific machines for monitoring and remote accessPermission to manage assets
My TeamManage people at your own locationsTeam managers and Administrators
Audit LogEvery change in your organization, exportableTeam managers and Administrators
Onboarding / OffboardingStart and track employee onboarding and offboardingPermission to read users

Billing lives in its own Billing group: Invoices, Estimates, and Billing & Payments. See Invoices, estimates & payments.

Set up your organization

Sign in as an administrator

Use the account intSignal set up for you. If your organization uses Microsoft 365, intSignal first links your organization to your Microsoft tenant, and your Microsoft administrator approves it once. See Linking your Microsoft tenant.

Review the built-in roles

Open Permission Groups and read what each of the seven built-in roles grants. Decide whether they fit, or whether you need a custom permission group.

Invite your team

Open Users, and under Invite a user enter each person's email and name, choose their roles, and select Send invite. Give each person the narrowest role that does the job.

Limit scope where you need to

If some people should only see certain locations, use Assign locations on the Users page. Read the warning in Assign locations first: it can't be undone from the portal. To limit people to specific machines, use Machine Access.

Check billing access

Make sure the people who approve invoices hold a role that allows it, and review Billing & Payments.

Things only intSignal can change

Some settings are managed by intSignal rather than in your portal. Contact your intSignal team for any of these:

  • Linking your organization to your Microsoft 365 tenant
  • Creating an email account for someone without Microsoft 365
  • Resetting a password or an authenticator for an email account
  • Unlocking a locked account, or unblocking a blocked network
  • Enabling a module for your organization
  • Making someone a team manager
  • Restoring company-wide access for someone after locations were assigned
  • Turning on automatic payments
  • Issuing API keys, or enabling API key self-service for your administrators

API access

Programmatic access to the portal's REST API uses API keys that belong to your organization, not to a person. A key has its own scopes and isn't limited by any user's locations or machine access, so within those scopes it sees your whole organization. Store keys like any other sensitive credential. See Developers.

Need a hand with Platform?Talk to our team →