The intSignal customer portal, at portal.intsignal.com, is where your organization signs
in to work with intSignal: tickets and support, security and network visibility, assets and
monitoring, invoices and payments, and the administration of who can do what.
This section covers the account and access layer that sits under all of it. If you're an administrator setting things up for the first time, read this page, then Signing in and Users & invitations.
How people sign in
There are two kinds of accounts, and each person has exactly one:
- Microsoft accounts use Sign in with Microsoft. This is the standard option for organizations on Microsoft 365. Your organization's own Microsoft sign-in rules, such as multi-factor authentication, apply.
- Email accounts use an email address, a password, and a 6-digit code from an authenticator app. They exist for people who don't have Microsoft 365, and intSignal creates them on request.
Nobody gets in uninvited. A Microsoft account only works after an administrator has invited that email address. Full details, including first-time setup and troubleshooting, are in Signing in.
How access is decided
Every page and action in the portal is checked against three things, and all three must allow it:
- Modules enabled for your organization. intSignal switches modules on for your account, such as Monitoring or Budgets. A module that isn't enabled is hidden from everyone, administrators included.
- The person's permissions. Permissions come from roles and permission groups. A person can hold several, and they get everything any of them grants. See Roles & permission groups.
- The person's scope. Some people are limited to certain locations, and some to certain machines. See Users & invitations and Machine access.
Checks happen on every request, so changes apply immediately. If you disable someone or remove a role, their next click is already limited; they don't need to sign out first.
A menu item is missing
The sidebar only shows what a person can actually use. If an item is missing for one person, check their roles. If it's missing for everyone, including administrators, the module probably isn't enabled for your organization. Ask intSignal.
Your organization's structure
Your organization is set up by intSignal as a company, which can contain sub-companies and locations. The portal calls this your organization throughout.
Locations matter for access. By default, a person sees their whole company. When you assign someone to specific locations, they only see tickets for those locations. See Assign locations.
Where the admin tools are
Administration lives in the Admin group at the bottom of the portal sidebar. Each item only appears for people with the permission shown.
| Sidebar item | What it's for | Who sees it |
|---|---|---|
| Users | Invite people, change roles, disable accounts, assign locations | Permission to read users |
| Permission Groups | View built-in roles, create custom permission groups | Permission to read permission groups |
| Machine Access | Limit people to specific machines for monitoring and remote access | Permission to manage assets |
| My Team | Manage people at your own locations | Team managers and Administrators |
| Audit Log | Every change in your organization, exportable | Team managers and Administrators |
| Onboarding / Offboarding | Start and track employee onboarding and offboarding | Permission to read users |
Billing lives in its own Billing group: Invoices, Estimates, and Billing & Payments. See Invoices, estimates & payments.
Set up your organization
Sign in as an administrator
Use the account intSignal set up for you. If your organization uses Microsoft 365, intSignal first links your organization to your Microsoft tenant, and your Microsoft administrator approves it once. See Linking your Microsoft tenant.
Review the built-in roles
Open Permission Groups and read what each of the seven built-in roles grants. Decide whether they fit, or whether you need a custom permission group.
Invite your team
Open Users, and under Invite a user enter each person's email and name, choose their roles, and select Send invite. Give each person the narrowest role that does the job.
Limit scope where you need to
If some people should only see certain locations, use Assign locations on the Users page. Read the warning in Assign locations first: it can't be undone from the portal. To limit people to specific machines, use Machine Access.
Check billing access
Make sure the people who approve invoices hold a role that allows it, and review Billing & Payments.
Things only intSignal can change
Some settings are managed by intSignal rather than in your portal. Contact your intSignal team for any of these:
- Linking your organization to your Microsoft 365 tenant
- Creating an email account for someone without Microsoft 365
- Resetting a password or an authenticator for an email account
- Unlocking a locked account, or unblocking a blocked network
- Enabling a module for your organization
- Making someone a team manager
- Restoring company-wide access for someone after locations were assigned
- Turning on automatic payments
- Issuing API keys, or enabling API key self-service for your administrators
API access
Programmatic access to the portal's REST API uses API keys that belong to your organization, not to a person. A key has its own scopes and isn't limited by any user's locations or machine access, so within those scopes it sees your whole organization. Store keys like any other sensitive credential. See Developers.
