1.0 - Introduction
Member access roles allow for each of your MSP employees to have their own role allowing them access to different things at different levels. If you want to control your clients access roles, please read our client access roles article.
HighGround uses Role Based Access Control (RBAC), making it much easier for you to setup accessing pre-defined permission levels for the majority of access requirements.
2.0 - Types of Member Access Roles
There are 2 different types of member access roles:
Default: these are pre-defined member access roles within HighGround and cover the most common access scenarios you are likely to require.
Custom: these are member access roles created by you to meet specific needs.
3.0 Types of Access Levels
Member access roles are made up of a collection of access levels. The access levels are generic and will control access differently within different parts of HighGround.
The following table details the standard access level types.
Access Level | Description |
No Access | No access to the module or feature |
Restricted View | Can view summary details but cannot drilldown into any further data |
View | Can view summary details and drilldown data |
Edit | Can view, edit, and create data but cannot delete |
Full Access | Unrestricted access - can view, edit, create and delete data |
3.1 Permissions for member access roles
Member access roles in HighGround are broken down into two distinct sections for managing permissions:
MSP Modules: These permissions control access to MSP-specific features, such as Companies, Integrations, Sell, Security Stack, SecOps, and more.
Client Management: This section defines what members can view and manage within a client’s profile.
4.0 Matrix of access levels <> modules
There are different access levels available for different modules in HighGround, as detailed in the matrix below.
4.1 Default member access roles for MSP modules
| No Access | Restricted View | View | Edit | Full Access |
Module |
|
|
|
|
|
MSP Security Stack |
|
|
|
|
|
SecOps |
|
|
|
|
|
MSP Sell |
|
|
|
|
|
MSP Action Centre |
|
|
|
|
|
MSP Integrations |
|
|
|
|
|
PSA Integrations |
|
|
|
|
|
MSP System Settings |
|
|
|
|
|
MSP User Management |
|
|
|
|
|
4.2 Client Management
| No Access | Restricted View | View | Edit | Full Access |
Module |
|
|
|
|
|
Dashboard |
|
|
|
|
|
Assets |
|
|
|
|
|
Action Centre |
|
|
|
|
|
Technology Spend |
|
|
|
|
|
Governance & Resilience |
|
|
|
|
|
Security Packages |
|
|
|
|
|
Integrations |
|
|
|
|
|
System Settings |
|
|
|
|
|
User Management |
|
|
|
|
|
4.3 Own Organisation
| No Access | Restricted View | View | Edit | Full Access |
Module |
|
|
|
|
|
Technology Spend |
|
|
|
|
|
Dashboard |
|
|
|
|
|
Assets |
|
|
|
|
|
Action Centre |
|
|
|
|
|
Governance & Resilience |
|
|
|
|
|
Integrations |
|
|
|
|
|
Security Packages |
|
|
|
|
|
System Settings |
|
|
|
|
|
User Management |
|
|
|
|
|
5.0 - Matrix of access levels for default member access roles
The following tables detail the access levels used for each section of the default member access roles.
5.1 - MSP modules
| Global Administrator | Sales Advisor | Account Manager | Security Engineer | Senior Security Engineer |
Module |
|
|
|
|
|
MSP Security Stack | Full access | View | Full Access | Full Access | Full Access |
SecOps | Full Access | No Access | View | Full Access | Full Access |
MSP Sell | Full Access | View | Full Access | View | Full Access |
MSP Action Centre | Full Access | No Access | View | View | Full Access |
MSP Integrations | Full Access | No Access | No Access | Full Access | Full Access |
PSA Integrations | Full Access | No Access | No Access | View | Full Access |
MSP System Settings | Full Access | No Access | No Access | No Access | Full Access |
MSP User Management | Full Access | No Access | No Access | View | Full Access |
5.2 - Client Management
| Global Administrator | Sales Advisor | Accounts Manager | Security Engineer | Senior Security Engineer |
Modules |
|
|
|
|
|
Clients | Full Access | View | Full Access | Edit | Full Access |
Client User Management | Full Access | No Access | Full Access | Full Access | Full Access |
Technology Spend | Full Access | View | Full Access | Full Access | Full Access |
Assets | Full Access | No Access | View | Full Access | Full Access |
Action Centre | Full Access | No Access | Full Access | Full Access | Full Access |
Governance & Resilience | Full Access | View | Full Access | Full Access | Full Access |
Integrations | Full Access | No Access | View | Full Access | Full Access |
Security Packages | Full Access | Full Access | Full Access | Full Access | Full Access |
System Settings | Full Access | No Access | View | Full Access | Full Access |
Dashboard | Edit | View | View | Edit | Edit |
5.3 - Own Organisation
| Global administrator | Sales Advisor | Accounts Manager | Security Engineer | Senior Security Engineer |
Module |
|
|
|
|
|
Own Organisation | Full Access | Full Access | Full Access | Full Access | Full Access |
Technology Spend | Full Access | View | View | View | Full Access |
Dashboard | Edit | View | View | View | Edit |
Assets | Full Access | No Access | View | Full Access | Full Access |
Action Centre | Full Access | No Access | Full Access | Full Access | Full Access |
Governance & Resilience | Full Access | View | Full Access | Full Access | Full Access |
Integrations | Full Access | No Access | View | Full Access | Full Access |
Security Packages | Full Access | Full Access | Full Access | Full Access | Full Access |
System Settings | Full Access | No Access | View | Full Access | Full Access |
User Management | Full Access | No Access | View | Full Access | Full Access |
6.0 - Custom member access roles
For custom access control needs, you can create a custom access role using the default access levels available in HighGround.
There are two methods for creating a custom access role:
Duplicating: Duplicate an existing default member access role or a custom role you’ve already created. This method is great if you want to make slight adjustments without starting from scratch.
Create: Start fresh by creating a brand-new custom member access role. This option gives you full control over the permissions you want to assign.
The following section will walk you through how to perform each of these actions
6.1 - Create a custom member access role by Duplicating
Watch our instructional video on duplicating roles or, alternatively read the steps listed below.
Step 1: Click on your profile picture in the top right corner and select 'MSP System Settings'.
Step 2: On the left-hand side of your screen, navigate to 'Members and Access'.
Step 3: Click on 'Access Roles' to access the list of available roles.
Step 4: Locate the role you want to duplicate and click on the ellipsis (three dots) next to it.
Note: You will have the option to change the name.
Step 5: Your duplicated role will appear at the bottom of the list. From here, you can make any necessary changes.
Step 6: Once you've made your changes, click 'Save', and your custom access role will be updated automatically.
6.2 - Create a custom member access role from scratch
Watch our instructional video on creating custom roles or, alternatively read the steps listed below.
Step 1: Click on your profile picture in the top right corner and select 'MSP System Settings'.
Step 2: On the left-hand side of your screen, navigate to 'Members and Access'.
Step 3: Click on 'Access Roles' to view your access role settings.
Step 4: Select the 'Add Access Role' button to create a new role.
Step 5: Give your new access role a name and description, then customize the role as needed.
Step 6: Click 'Save', and your new access role will be added to the bottom of your list of member access roles.
7.0 - Editing member access roles
The default member access roles in HighGround cannot be edited directly. If you need to make changes, the best approach is to duplicate the role and modify the duplicate instead.
Custom member access roles, however, can be edited at any time. Just keep in mind that any changes made will take effect immediately for all members associated with that role.
To edit a member access role, follow these steps:
Step 1: Click on your profile picture in the top right corner and select 'MSP System Settings'.
Step 2: In the left-hand menu, go to 'Members and Access'.
Step 3: Choose the member access role you’d like to edit.
Step 4: Make the necessary changes to the role.
Step 5: Press 'Save', and the access role will be automatically updated.
By following these steps, you can easily manage and update your member access roles to ensure they meet your current requirements.
8.0 - Deleting member access roles
The default member access roles in HighGround can not be deleted.
Before deleting a custom access role, you must first ensure that it is not actively in use by any user.
To delete a member access role, follow these steps.
Step 1: Click on your profile picture in the top right corner and select 'MSP System Settings'.
Step 2: In the left-hand menu, go to 'Members and Access'.
Step 3: Find the access role you want to delete and click on the ellipsis (three dots) next to it.
Step 4: From the three options ('Duplicate', 'Edit', and 'Delete'), select 'Delete'.
Step 5: If the role is actively in use, you’ll see a prompt confirming whether you want
to proceed. If you’re sure you want to delete the role, click 'Delete' again to confirm.
9.0 - Applying a member access role to a MSP employee
Note: You can apply more than one access role to a member, however where they clash on the same module the access role with the highest restriction level will be applied.
Step 1: Click on your profile picture in the top right corner and select 'MSP System Settings'.
Step 2: From the left-hand menu, choose 'Members and Access'.
Step 3: Locate and select the member you want to assign an access role to.
Step 4: Next to their name, click the 'Select' dropdown menu, and your list of available access roles will appear.
Step 5: Choose the access role you'd like to apply to the member from the list.
9.1 - Previewing a members access
It can be useful to preview what permissions a member will have in HighGround. You can do this by using the 'preview' feature from an MSP employees account. Watch our instructional vide on this or, read the steps listed below.
Note: You can not edit the access role here.
Step 1: From your dashboard, click on your profile picture in the top right corner.
Step 2: Select 'MSP System Settings' from the dropdown menu.
Step 3: Navigate to 'Members and Access' in the left-hand menu.
Step 4: Choose the member you’d like to preview and click on their profile picture.
Step 5: Scroll down to the 'Access Roles' section.
Step 6: Click on 'Preview Access' to view the member's permissions.