What a person can see and do in the portal comes from the roles and permission groups they hold. You'll find them under Admin → Permission Groups, titled "Predefined roles and custom permission groups."
Roles only grant access within modules that are enabled for your organization. Even an Administrator can't use a module intSignal hasn't switched on.
How permissions work
A permission is always a component plus an action, such as Invoices → approve. A person can hold several roles, and gets every permission any of them grants. Nothing a role grants is ever taken away by another role.
| Action | Means |
|---|---|
| read | See it |
| create | Add new items, such as raising a ticket or inviting a user |
| update | Change existing items |
| delete | Remove items, such as revoking an invitation or deleting a permission group |
| approve | Approve or reject, such as an invoice, estimate, budget, or purchase request |
| export | Download or export the data |
| connect | Start a remote session to a device (Remote Access only) |
| manage | Full control of that component, which includes every other action on it |
The built-in roles
Every organization has seven built-in roles. They're marked System on the Permission Groups page, and they can't be edited or deleted. Each card also shows how many people hold the role.
Administrator
Full access to every component, plus user and permission-group management.
Administrators hold every permission on every component enabled for your organization. They're also always treated as team managers, and they aren't limited by machine access restrictions. Keep this role to the smallest number of people you can.
User
Standard end user: submit and track tickets, view billing and reports.
| Component | Actions |
|---|---|
| Dashboard | read |
| Tickets | read, create, update |
| Invoices | read |
| Estimates | read |
| Assets | read |
| Contacts & Engineers | read |
| Reports | read |
Billing
Invoices, estimates, payments and budgets.
| Component | Actions |
|---|---|
| Dashboard | read |
| Invoices | read, approve, export |
| Estimates | read, approve |
| Payments | read, manage |
| Budgets | read |
| Purchasing | read |
| Contacts & Engineers | read |
| Reports | read |
Reports
Read and export reports across modules.
| Component | Actions |
|---|---|
| Dashboard | read |
| Reports | read, export |
| Tickets | read |
| Invoices | read |
| Assets | read |
| Security | read |
| Risk & Compliance | read |
Security
ESET endpoint security telemetry, assets and risk.
| Component | Actions |
|---|---|
| Dashboard | read |
| Security | read, export |
| Assets | read |
| Risk & Compliance | read |
| Reports | read |
| Tickets | read |
Risk Management
Risk scoring and compliance, with supporting security and asset data.
| Component | Actions |
|---|---|
| Dashboard | read |
| Risk & Compliance | read, export |
| Security | read |
| Assets | read |
| Reports | read, export |
| Tickets | read |
COO
Broad read access across all modules, with approval authority.
| Component | Actions |
|---|---|
| Dashboard | read |
| Tickets | read |
| Invoices | read, approve |
| Estimates | read, approve |
| Payments | read |
| Assets | read |
| Contacts & Engineers | read |
| Security | read |
| Reports | read, export |
| Risk & Compliance | read, export |
| Budgets | read, approve |
| Purchasing | read, approve |
| User Management | read |
Note
None of the built-in roles except Administrator include Monitoring, Network, Remote Access, Settings, or the ability to change users and permission groups. To give someone those without making them an Administrator, create a custom permission group.
Create a custom permission group
When no built-in role fits, build your own. It works exactly like a role: assign it on the Users page, alone or together with other roles.
Start a new group
On Permission Groups, select New permission group.
Name and describe it
Enter a Name of 2 to 80 characters that isn't already used in your organization. Add a Description that says who it's for. It appears on the group's card, which helps whoever reviews access next.
Choose permissions
The grid lists every Component with its available Permissions. Select an action to grant it, and select it again to remove it. Granting manage on a component gives full control of that component.
Save
Select Save, which becomes available once there's a name, or Cancel to discard. The group now appears in the Roles choices when you invite or edit people.
To change a group later, select Edit on its card. The editor reopens as Edit permission group, and changes apply at once to everyone who holds it.
To remove a group, select Delete on its card. A group that people still hold can't be deleted. You'll see "Reassign members before deleting this permission group", so first move those people to other roles on the Users page.
A custom permission group can never be an administrator group; only the built-in Administrator role has administrator status.
Component reference
This is every component a role or permission group can include, and the actions available on each.
| Component | Covers | Available actions |
|---|---|---|
| Dashboard | Landing overview and summary widgets | read |
| Tickets | Support and service tickets | read, create, update, export |
| Invoices | Invoices, approval and payment | read, approve, export |
| Estimates | Estimates and approval | read, approve, export |
| Payments | Online payments and saved payment methods | read, manage |
| Assets | Assets, lifecycle, assignment and location | read, manage, export |
| Monitoring | Live device health: online status, disk, memory, CPU, patches and antivirus | read, export |
| Remote Access | Remote-desktop sessions to managed devices, where enabled for your organization | read, connect, manage |
| Contacts & Engineers | Your points of contact and assigned engineers | read, manage |
| Security | Endpoint security telemetry and reports | read, export |
| Network | Network devices and reporting across sites | read, export |
| Reports | Cross-module reports and graphs | read, export |
| Risk & Compliance | Risk scoring and compliance dashboards | read, export |
| Budgets | Budgeting and approval requests | read, create, approve, manage |
| Purchasing | Purchasing requests tied to service tickets | read, create, approve |
| User Management | Inviting and managing people | read, create, update, delete |
| Permission Groups | Built-in roles and custom permission groups | read, create, update, delete |
| Settings | Organization settings and integrations | read, manage |
Grant sensitive permissions carefully
Some permissions let a person change who has access, move money, or reach your devices. Give these only to people you'd trust with full administration:
- User Management → create or update, because it controls who can get in and with what roles
- Permission Groups → create, update, or delete, because it changes what every role grants
- Payments → manage, because it covers saved payment methods
- Remote Access → connect, because it reaches your devices directly
- Assets → manage, because it controls machine access
Reviewing access
A regular access review is good security practice, and it's evidence auditors ask for. Quarterly works for most organizations:
- On Permission Groups, check how many people hold each role, especially Administrator.
- On Users, check every person's roles, and use Last login to find accounts nobody uses. Disable anyone who no longer needs access.
- Export the Audit Log to keep a dated record of role and account changes. See Team managers & audit log.
Keep what you find. A dated user list, with who reviewed it, is one of the first things a SOC 2 or ISO 27001 auditor asks for, and the free compliance evidence workspace gives you somewhere to file it against the matching control.
