Roles and permissions

Roles and per-person permissions for your MSP team

Give each person a role. The role decides what they can reach and do in MSPStuff and in their AI client, never more in the second than the first. Admins can adjust one person without changing everyone else.

What a role is

What a role is

A role is a named set of access

A role lists the data areas a person can reach and the things they can do. Every member who is not an admin holds one role.

Roles are live

Edit a role and everyone who holds it gets the change. Nobody has to be reassigned.

Six built-in roles

Every company starts with the same six roles, listed below. The roles running in production match these definitions exactly.

Your own roles

To make a role of your own, clone a built-in and edit the copy. A custom role is enforced the same way as a built-in.

Two channels

In MSPStuff, and in their AI client

Every role has two columns: what a person can do in MSPStuff, and what their AI client can do for them.

Column 1

In MSPStuff

The first column covers the app: sessions, reports, dashboards, files, alerts, clients, platforms and the team.

Column 2

In their AI client

The second column covers the AI client a person connects with their own key. It can list and read sessions, reports, dashboards, files and schedules, and run and create reports, when the role allows each one.

  • The ceiling between them

    Each person gets never more in their AI client than in MSPStuff. When we took Run reports away from a technician in MSPStuff, their AI client lost it too.

  • Data areas reach the AI client

    Platform tools in the AI client follow the data areas the person holds there. In a check on our own company, a seat limited to assets saw no ticket tools. Once service was added, with company and security, the ticket tool appeared.

  • No key, no AI client

    Auditor and Basic have no AI-client access, and a key cannot be made for them. A revoked key stops working on the next call.

Built-in roles

The six built-in roles

These are the six roles every company starts with, exactly as they are defined.

  • Manager

    Everything except the team, billing, connecting or purging platforms, and the Learning page.

    Data areas

    Service, Finance, Sales, Company, Assets, Projects, Security

    In MSPStuff

    Sessions
    Read shared sessions, Start sessions, Share any session, Manage any session, Approve parked writes†
    Reports
    Read reports, Create reports, Run reports, Email report recipients, Send a report by email†, Manage any report
    Dashboards
    Read dashboards, Send a dashboard by email†, Manage any dashboard
    Files
    Read files, Upload files, Send a file by email, Manage any file
    Schedules
    Read schedules
    Sharing
    Share with people outside
    Alerts
    Acknowledge and close alerts, File and tag alerts, Purge old alerts, Manage alert webhooks
    Clients
    Edit clients
    People
    Edit people
    Signals
    Accept signals
    Learning
    Approve playbook changes
    Compliance
    Run compliance
    Questionnaires
    Manage questionnaires
    Platforms
    Refresh platform data, Request a platform
    Company
    Manage delivery, Edit the company profile†
    AI client
    Connect an AI client

    In their AI client

    Reads, run and create reports, and the same data areas

  • Technician

    Service, company, assets and projects. Runs and emails reports, handles alerts, refreshes platforms.

    Data areas

    Service, Company, Assets, Projects

    In MSPStuff

    Sessions
    Read shared sessions, Start sessions
    Reports
    Read reports, Create reports, Run reports, Email report recipients, Send a report by email†
    Dashboards
    Read dashboards, Send a dashboard by email†
    Files
    Read files, Upload files, Send a file by email
    Schedules
    Read schedules
    Alerts
    Acknowledge and close alerts, File and tag alerts
    Platforms
    Refresh platform data, Request a platform
    Compliance
    Run compliance
    Questionnaires
    Manage questionnaires
    AI client
    Connect an AI client

    In their AI client

    Reads, run and create reports, and the same data areas

  • Finance

    Finance, sales and company data. Runs and emails reports.

    Data areas

    Finance, Sales, Company

    In MSPStuff

    Sessions
    Read shared sessions, Start sessions
    Reports
    Read reports, Create reports, Run reports, Email report recipients, Send a report by email†
    Dashboards
    Read dashboards, Send a dashboard by email†
    Files
    Read files, Upload files, Send a file by email
    Schedules
    Read schedules
    Platforms
    Request a platform
    AI client
    Connect an AI client

    In their AI client

    Reads, run and create reports, and the same data areas

  • Security analyst

    Security, assets, service and company data. Owns alerts and their webhooks.

    Data areas

    Security, Assets, Service, Company

    In MSPStuff

    Sessions
    Read shared sessions, Start sessions
    Reports
    Read reports, Create reports, Run reports, Email report recipients, Send a report by email†
    Dashboards
    Read dashboards
    Files
    Read files
    Schedules
    Read schedules
    Alerts
    Acknowledge and close alerts, File and tag alerts, Manage alert webhooks, Purge old alerts
    Platforms
    Refresh platform data, Request a platform
    AI client
    Connect an AI client

    In their AI client

    Reads, run and create reports, and the same data areas

  • Auditor

    Reads every data area in MSPStuff. Cannot start sessions, build reports or connect platforms. No AI-client access.

    Data areas

    Service, Finance, Sales, Company, Assets, Projects, People, Security

    In MSPStuff

    Sessions
    Read shared sessions
    Reports
    Read reports
    Dashboards
    Read dashboards
    Files
    Read files
    Schedules
    Read schedules

    In their AI client

    No AI-client access

  • Basic

    Sessions and the library, no platform data. What a member could do before roles existed.

    Data areas

    None

    In MSPStuff

    Sessions
    Read shared sessions, Start sessions
    Reports
    Read reports, Create reports, Run reports, Email report recipients, Send a report by email†
    Dashboards
    Read dashboards, Send a dashboard by email†
    Files
    Read files, Upload files, Send a file by email
    Schedules
    Read schedules
    Alerts
    Acknowledge and close alerts, File and tag alerts
    Platforms
    Refresh platform data, Request a platform
    Compliance
    Run compliance
    Questionnaires
    Manage questionnaires
    AI client
    Connect an AI client

    In their AI client

    No AI-client access

† Marked permissions are part of the role's definition. Our smoke run did not exercise them, so this page makes no claim about how they behave.

The builder

Build your own roles

One grid, two columns

Team › Roles shows the built-ins and your own roles. The editor is one grid, grouped by area, with a column for MSPStuff and a column for the AI client.

Leave out what a role does not need

A custom role can leave out a read. A test role without shared sessions was refused them, in MSPStuff and in its AI client.

Who can edit roles

Creating, editing, deleting and assigning roles needs Manage the team. A member without it was refused each of those actions.

Overrides

Adjust one person

Adjust one person

On top of their role, a person can be given a permission the role lacks, or have one taken away. Nobody else who holds the role changes.

Given, then removed

A technician given Manage the team was let through to invite, assign roles and remove members. Without that override, technicians were refused the same actions.

Taken away in both places

A technician with Run reports taken away lost it in MSPStuff and in their AI client.

An override never makes an admin

A member given Manage the team still cannot make anyone an admin. Only an admin can do that.

Outside viewers

Share one item with someone outside

One person, one item

Share with client gives one outside person one report, file or dashboard.

Always the newest version

The viewer always sees the item's newest version.

Google or Microsoft sign-in

The viewer signs in with Google or Microsoft, using the exact email the item was shared with. A different email is refused.

Not a member

A viewer is not a member of your company and does not take a seat. Sharing outside needs Share with people outside, and a member without it was refused.

Change log

Every change is recorded

Every change is written down

Role edits, role assignments and per-person overrides each write a row to the change log. In our run, the change log grew by exactly the number of team changes we made.

Read it on the Team page

The Changes list at the bottom of Team shows the most recent entries.

Admins

What an admin can always do

Admins hold every permission

An admin is not given a role, because an admin already holds every permission. Our run found no action that refused an admin for lack of a permission.

Only an admin makes an admin

Making someone an admin stays with admins, even when a member manages the team.

Billing stays with admins

No built-in role carries Manage billing. Every member without it was refused checkout, seat changes and the billing portal.

How we checked

On 26 September 2026 we moved one test member through every built-in role and a custom role on production, and tried each action in MSPStuff and in their AI client that could be tried without touching real data. Permissions we could not exercise are marked † on the role cards. The test company was left as we found it, apart from the revoked test keys we keep as the record.

Read the security sheet

Questions

Can someone have more access in their AI client than in MSPStuff?
No. The AI-client column can only hold what the MSPStuff column holds. Take a permission away in MSPStuff and the AI client loses it too.
What happens when I edit a role?
Everyone who holds it gets the change. Nobody has to be reassigned.
Who can change roles and permissions?
Admins, and any member given Manage the team. Only an admin can make someone an admin.
Which roles can connect an AI client?
Manager, Technician, Finance and Security analyst. Auditor and Basic cannot, and a key cannot be made for them.
Does an outside viewer count as a member?
No. A viewer sees only what was shared with them, signs in with Google or Microsoft, and does not take a seat.

Get AI connected to your stack.

Apply for the beta: 14 days free on the Hosted plan against your own environment, read-only, every answer traced. Accepted MSPs get half off seats and client tenants for the first year. Dedicated infrastructure is priced separately.

MSPStuff