Users & Access

Manage who has access to your Pckgr account and what they can do.

User Roles

RolePermissions
Account OwnerFull access to all tenants. Can manage users, tenants, billing, and all settings.
AdminCan manage devices, apps, groups, deployments, policies, scripts, and the tenant's settings and users within assigned tenants.
MSP TechnicianThe day-to-day work: devices, apps, groups, deployments, policies, scripts, remote control, and agent setup. Does not see Settings, Users, or Tenants, and cannot roll an app back. Granted per tenant, or on every tenant of the account including tenants added later.
Read OnlyView-only access to assigned tenants, including a read-only view of Settings and Users. Cannot create, edit, or delete anything.

Account Owners automatically have access to all tenants. Admin and Read Only users are granted access to specific tenants. MSP Technicians are granted either specific tenants or all tenants, now and in future.

Who Can Do What

Account OwnerAdminMSP TechnicianRead Only
Devices, apps, groups, scripts, policies, deployments, Windows UpdateManageManageManageView
Remote control, agent setup, templates, audit logYesYesYesView only
Roll an app back to an earlier versionYesYesNoNo
Settings page (tenant settings, API keys, self-service branding)ChangeChangeHiddenView
Users page: see users and invitesYesYesHiddenView
Invite usersAny access typeAdmin, MSP Technician or Read Only, in tenants they administerNoNo
Change a user's access, remove a userYesNoNoNo
Rename a tenantYesYesNoNo
Create or delete tenants, billing, delete the accountYesNoNoNo
Which tenantsEvery tenant, including new onesThe tenants they are givenThe tenants they are given, or every tenant including new onesThe tenants they are given

Where a role has no access, the portal hides the control or the page. MSP Technicians who open Settings, Users or Tenants by URL see a short "not part of your role" message instead of the page.

Viewing Users

Go to Settings > Users in the sidebar. The users table shows email, display name, access level badges (per-tenant), and last login time.

Inviting a User

  1. Click Invite user.
  2. Enter the person's email address.
  3. Pick an access type. Each card says what it grants:
    • Account Owner - Full access to every tenant, billing, users and settings. Shown to Account Owners only.
    • MSP Technician on all tenants - Day-to-day work in every tenant, including tenants added later, without Settings, Users or Tenants. Shown to Account Owners only.
    • Custom per-tenant access - Tick the tenants the person should have, then choose a role for each: Admin, MSP Technician or Read Only. An Admin can offer only the tenants they administer.
  4. Click Send invite.

The person receives an email with a link to accept the invitation. They'll set their password when accepting, or sign in with Microsoft if your account uses it.

Managing Invites

Expand the Invites section on the Users page to see pending and historical invites. Each invite shows the email, status, expiration date, and assigned access.

To cancel a pending invite, click Revoke.

Editing User Access

Only Account Owners can change a user's access; the edit and remove icons appear on the Users page for them alone.

  1. Click the edit (pencil) icon on a user's row.
  2. Pick an access type: Account Owner, MSP Technician on all tenants, or Custom per-tenant access.
  3. For custom access, tick or untick tenants and set the role for each. At least one tenant must stay ticked.
  4. Click Save.

Moving someone from all-tenants access to custom access limits them to the tenants you tick. Moving them the other way gives them every tenant, including ones you add later.

Removing a User

Click the delete (trash) icon on a user's row and confirm. This removes the user from your account and revokes all their tenant access. Only Account Owners can remove users, you cannot remove yourself, and the last Account Owner cannot be removed.

Multi-Tenant Access

If your account has multiple tenants, users with custom access can have different roles in different tenants. For example, a user could be an Admin in the "Production" tenant but Read Only in the "Development" tenant.

An MSP Technician on all tenants can also be given Admin on one particular tenant; the higher role applies there. Users can switch between their assigned tenants using the tenant selector in the sidebar.