Documentation

Platform · Reference

Roles & permission groups

The seven built-in portal roles and exactly what each one grants, every component and action, and how to build, edit, and delete custom permission groups safely.

What a person can see and do in the portal comes from the roles and permission groups they hold. You'll find them under Admin → Permission Groups, titled "Predefined roles and custom permission groups."

Roles only grant access within modules that are enabled for your organization. Even an Administrator can't use a module intSignal hasn't switched on.

How permissions work

A permission is always a component plus an action, such as Invoices → approve. A person can hold several roles, and gets every permission any of them grants. Nothing a role grants is ever taken away by another role.

ActionMeans
readSee it
createAdd new items, such as raising a ticket or inviting a user
updateChange existing items
deleteRemove items, such as revoking an invitation or deleting a permission group
approveApprove or reject, such as an invoice, estimate, budget, or purchase request
exportDownload or export the data
connectStart a remote session to a device (Remote Access only)
manageFull control of that component, which includes every other action on it

The built-in roles

Every organization has seven built-in roles. They're marked System on the Permission Groups page, and they can't be edited or deleted. Each card also shows how many people hold the role.

Administrator

Full access to every component, plus user and permission-group management.

Administrators hold every permission on every component enabled for your organization. They're also always treated as team managers, and they aren't limited by machine access restrictions. Keep this role to the smallest number of people you can.

User

Standard end user: submit and track tickets, view billing and reports.

ComponentActions
Dashboardread
Ticketsread, create, update
Invoicesread
Estimatesread
Assetsread
Contacts & Engineersread
Reportsread

Billing

Invoices, estimates, payments and budgets.

ComponentActions
Dashboardread
Invoicesread, approve, export
Estimatesread, approve
Paymentsread, manage
Budgetsread
Purchasingread
Contacts & Engineersread
Reportsread

Reports

Read and export reports across modules.

ComponentActions
Dashboardread
Reportsread, export
Ticketsread
Invoicesread
Assetsread
Securityread
Risk & Complianceread

Security

ESET endpoint security telemetry, assets and risk.

ComponentActions
Dashboardread
Securityread, export
Assetsread
Risk & Complianceread
Reportsread
Ticketsread

Risk Management

Risk scoring and compliance, with supporting security and asset data.

ComponentActions
Dashboardread
Risk & Complianceread, export
Securityread
Assetsread
Reportsread, export
Ticketsread

COO

Broad read access across all modules, with approval authority.

ComponentActions
Dashboardread
Ticketsread
Invoicesread, approve
Estimatesread, approve
Paymentsread
Assetsread
Contacts & Engineersread
Securityread
Reportsread, export
Risk & Complianceread, export
Budgetsread, approve
Purchasingread, approve
User Managementread

Note

None of the built-in roles except Administrator include Monitoring, Network, Remote Access, Settings, or the ability to change users and permission groups. To give someone those without making them an Administrator, create a custom permission group.

Create a custom permission group

When no built-in role fits, build your own. It works exactly like a role: assign it on the Users page, alone or together with other roles.

Start a new group

On Permission Groups, select New permission group.

Name and describe it

Enter a Name of 2 to 80 characters that isn't already used in your organization. Add a Description that says who it's for. It appears on the group's card, which helps whoever reviews access next.

Choose permissions

The grid lists every Component with its available Permissions. Select an action to grant it, and select it again to remove it. Granting manage on a component gives full control of that component.

Save

Select Save, which becomes available once there's a name, or Cancel to discard. The group now appears in the Roles choices when you invite or edit people.

To change a group later, select Edit on its card. The editor reopens as Edit permission group, and changes apply at once to everyone who holds it.

To remove a group, select Delete on its card. A group that people still hold can't be deleted. You'll see "Reassign members before deleting this permission group", so first move those people to other roles on the Users page.

A custom permission group can never be an administrator group; only the built-in Administrator role has administrator status.

Component reference

This is every component a role or permission group can include, and the actions available on each.

ComponentCoversAvailable actions
DashboardLanding overview and summary widgetsread
TicketsSupport and service ticketsread, create, update, export
InvoicesInvoices, approval and paymentread, approve, export
EstimatesEstimates and approvalread, approve, export
PaymentsOnline payments and saved payment methodsread, manage
AssetsAssets, lifecycle, assignment and locationread, manage, export
MonitoringLive device health: online status, disk, memory, CPU, patches and antivirusread, export
Remote AccessRemote-desktop sessions to managed devices, where enabled for your organizationread, connect, manage
Contacts & EngineersYour points of contact and assigned engineersread, manage
SecurityEndpoint security telemetry and reportsread, export
NetworkNetwork devices and reporting across sitesread, export
ReportsCross-module reports and graphsread, export
Risk & ComplianceRisk scoring and compliance dashboardsread, export
BudgetsBudgeting and approval requestsread, create, approve, manage
PurchasingPurchasing requests tied to service ticketsread, create, approve
User ManagementInviting and managing peopleread, create, update, delete
Permission GroupsBuilt-in roles and custom permission groupsread, create, update, delete
SettingsOrganization settings and integrationsread, manage

Grant sensitive permissions carefully

Some permissions let a person change who has access, move money, or reach your devices. Give these only to people you'd trust with full administration:

  • User Management → create or update, because it controls who can get in and with what roles
  • Permission Groups → create, update, or delete, because it changes what every role grants
  • Payments → manage, because it covers saved payment methods
  • Remote Access → connect, because it reaches your devices directly
  • Assets → manage, because it controls machine access

Reviewing access

A regular access review is good security practice, and it's evidence auditors ask for. Quarterly works for most organizations:

  1. On Permission Groups, check how many people hold each role, especially Administrator.
  2. On Users, check every person's roles, and use Last login to find accounts nobody uses. Disable anyone who no longer needs access.
  3. Export the Audit Log to keep a dated record of role and account changes. See Team managers & audit log.

Keep what you find. A dated user list, with who reviewed it, is one of the first things a SOC 2 or ISO 27001 auditor asks for, and the free compliance evidence workspace gives you somewhere to file it against the matching control.

Need a hand with Platform?Talk to our team →