Roles and per-person permissions for your MSP team
Give each person a role. The role decides what they can reach and do in MSPStuff and in their AI client, never more in the second than the first. Admins can adjust one person without changing everyone else.
What a role is
What a role is
A role is a named set of access
A role lists the data areas a person can reach and the things they can do. Every member who is not an admin holds one role.
Roles are live
Edit a role and everyone who holds it gets the change. Nobody has to be reassigned.
Six built-in roles
Every company starts with the same six roles, listed below. The roles running in production match these definitions exactly.
Your own roles
To make a role of your own, clone a built-in and edit the copy. A custom role is enforced the same way as a built-in.
Two channels
In MSPStuff, and in their AI client
Every role has two columns: what a person can do in MSPStuff, and what their AI client can do for them.
Column 1
In MSPStuff
The first column covers the app: sessions, reports, dashboards, files, alerts, clients, platforms and the team.
Column 2
In their AI client
The second column covers the AI client a person connects with their own key. It can list and read sessions, reports, dashboards, files and schedules, and run and create reports, when the role allows each one.
The ceiling between them
Each person gets never more in their AI client than in MSPStuff. When we took Run reports away from a technician in MSPStuff, their AI client lost it too.
Data areas reach the AI client
Platform tools in the AI client follow the data areas the person holds there. In a check on our own company, a seat limited to assets saw no ticket tools. Once service was added, with company and security, the ticket tool appeared.
No key, no AI client
Auditor and Basic have no AI-client access, and a key cannot be made for them. A revoked key stops working on the next call.
Built-in roles
The six built-in roles
These are the six roles every company starts with, exactly as they are defined.
Manager
Everything except the team, billing, connecting or purging platforms, and the Learning page.
Data areas
Service, Finance, Sales, Company, Assets, Projects, Security
In MSPStuff
- Sessions
- Read shared sessions, Start sessions, Share any session, Manage any session, Approve parked writes†
- Reports
- Read reports, Create reports, Run reports, Email report recipients, Send a report by email†, Manage any report
- Dashboards
- Read dashboards, Send a dashboard by email†, Manage any dashboard
- Files
- Read files, Upload files, Send a file by email, Manage any file
- Schedules
- Read schedules
- Sharing
- Share with people outside
- Alerts
- Acknowledge and close alerts, File and tag alerts, Purge old alerts, Manage alert webhooks
- Clients
- Edit clients
- People
- Edit people
- Signals
- Accept signals
- Learning
- Approve playbook changes
- Compliance
- Run compliance
- Questionnaires
- Manage questionnaires
- Platforms
- Refresh platform data, Request a platform
- Company
- Manage delivery, Edit the company profile†
- AI client
- Connect an AI client
In their AI client
Reads, run and create reports, and the same data areas
Technician
Service, company, assets and projects. Runs and emails reports, handles alerts, refreshes platforms.
Data areas
Service, Company, Assets, Projects
In MSPStuff
- Sessions
- Read shared sessions, Start sessions
- Reports
- Read reports, Create reports, Run reports, Email report recipients, Send a report by email†
- Dashboards
- Read dashboards, Send a dashboard by email†
- Files
- Read files, Upload files, Send a file by email
- Schedules
- Read schedules
- Alerts
- Acknowledge and close alerts, File and tag alerts
- Platforms
- Refresh platform data, Request a platform
- Compliance
- Run compliance
- Questionnaires
- Manage questionnaires
- AI client
- Connect an AI client
In their AI client
Reads, run and create reports, and the same data areas
Finance
Finance, sales and company data. Runs and emails reports.
Data areas
Finance, Sales, Company
In MSPStuff
- Sessions
- Read shared sessions, Start sessions
- Reports
- Read reports, Create reports, Run reports, Email report recipients, Send a report by email†
- Dashboards
- Read dashboards, Send a dashboard by email†
- Files
- Read files, Upload files, Send a file by email
- Schedules
- Read schedules
- Platforms
- Request a platform
- AI client
- Connect an AI client
In their AI client
Reads, run and create reports, and the same data areas
Security analyst
Security, assets, service and company data. Owns alerts and their webhooks.
Data areas
Security, Assets, Service, Company
In MSPStuff
- Sessions
- Read shared sessions, Start sessions
- Reports
- Read reports, Create reports, Run reports, Email report recipients, Send a report by email†
- Dashboards
- Read dashboards
- Files
- Read files
- Schedules
- Read schedules
- Alerts
- Acknowledge and close alerts, File and tag alerts, Manage alert webhooks, Purge old alerts
- Platforms
- Refresh platform data, Request a platform
- AI client
- Connect an AI client
In their AI client
Reads, run and create reports, and the same data areas
Auditor
Reads every data area in MSPStuff. Cannot start sessions, build reports or connect platforms. No AI-client access.
Data areas
Service, Finance, Sales, Company, Assets, Projects, People, Security
In MSPStuff
- Sessions
- Read shared sessions
- Reports
- Read reports
- Dashboards
- Read dashboards
- Files
- Read files
- Schedules
- Read schedules
In their AI client
No AI-client access
Basic
Sessions and the library, no platform data. What a member could do before roles existed.
Data areas
None
In MSPStuff
- Sessions
- Read shared sessions, Start sessions
- Reports
- Read reports, Create reports, Run reports, Email report recipients, Send a report by email†
- Dashboards
- Read dashboards, Send a dashboard by email†
- Files
- Read files, Upload files, Send a file by email
- Schedules
- Read schedules
- Alerts
- Acknowledge and close alerts, File and tag alerts
- Platforms
- Refresh platform data, Request a platform
- Compliance
- Run compliance
- Questionnaires
- Manage questionnaires
- AI client
- Connect an AI client
In their AI client
No AI-client access
† Marked permissions are part of the role's definition. Our smoke run did not exercise them, so this page makes no claim about how they behave.
The builder
Build your own roles
One grid, two columns
Team › Roles shows the built-ins and your own roles. The editor is one grid, grouped by area, with a column for MSPStuff and a column for the AI client.
Leave out what a role does not need
A custom role can leave out a read. A test role without shared sessions was refused them, in MSPStuff and in its AI client.
Who can edit roles
Creating, editing, deleting and assigning roles needs Manage the team. A member without it was refused each of those actions.
Overrides
Adjust one person
Adjust one person
On top of their role, a person can be given a permission the role lacks, or have one taken away. Nobody else who holds the role changes.
Given, then removed
A technician given Manage the team was let through to invite, assign roles and remove members. Without that override, technicians were refused the same actions.
Taken away in both places
A technician with Run reports taken away lost it in MSPStuff and in their AI client.
An override never makes an admin
A member given Manage the team still cannot make anyone an admin. Only an admin can do that.
Outside viewers
Share one item with someone outside
One person, one item
Share with client gives one outside person one report, file or dashboard.
Always the newest version
The viewer always sees the item's newest version.
Google or Microsoft sign-in
The viewer signs in with Google or Microsoft, using the exact email the item was shared with. A different email is refused.
Not a member
A viewer is not a member of your company and does not take a seat. Sharing outside needs Share with people outside, and a member without it was refused.
Change log
Every change is recorded
Every change is written down
Role edits, role assignments and per-person overrides each write a row to the change log. In our run, the change log grew by exactly the number of team changes we made.
Read it on the Team page
The Changes list at the bottom of Team shows the most recent entries.
Admins
What an admin can always do
Admins hold every permission
An admin is not given a role, because an admin already holds every permission. Our run found no action that refused an admin for lack of a permission.
Only an admin makes an admin
Making someone an admin stays with admins, even when a member manages the team.
Billing stays with admins
No built-in role carries Manage billing. Every member without it was refused checkout, seat changes and the billing portal.
How we checked
On 26 September 2026 we moved one test member through every built-in role and a custom role on production, and tried each action in MSPStuff and in their AI client that could be tried without touching real data. Permissions we could not exercise are marked † on the role cards. The test company was left as we found it, apart from the revoked test keys we keep as the record.
Questions
- Can someone have more access in their AI client than in MSPStuff?
- No. The AI-client column can only hold what the MSPStuff column holds. Take a permission away in MSPStuff and the AI client loses it too.
- What happens when I edit a role?
- Everyone who holds it gets the change. Nobody has to be reassigned.
- Who can change roles and permissions?
- Admins, and any member given Manage the team. Only an admin can make someone an admin.
- Which roles can connect an AI client?
- Manager, Technician, Finance and Security analyst. Auditor and Basic cannot, and a key cannot be made for them.
- Does an outside viewer count as a member?
- No. A viewer sees only what was shared with them, signs in with Google or Microsoft, and does not take a seat.
Get AI connected to your stack.
Apply for the beta: 14 days free on the Hosted plan against your own environment, read-only, every answer traced. Accepted MSPs get half off seats and client tenants for the first year. Dedicated infrastructure is priced separately.