Admin Roles & Permissions
This article explains the differences between each role at Symbol Security and the permissions they have for MSP/vCISO Partners & Single Companies.
Admin Permissions for Single Companies
This guide outlines the permissions for Owner, Member, and Reporting roles, with a specific focus on the Company Program features.
Owner
The Owner has total control over the platform, including all high-level security and financial settings.
- Company Program: Full permission to see and manage all aspects. This includes viewing the schedule, adding/editing mandatory content, generating program schedules, and creating corrective workflows.
- Key Features: Exclusive access to Entra ID (Azure AD) sync, SAML SSO, and billing/invoices. They are also the only role that can assign training courses individually from the Library.
Member
Members handle day-to-day operations and campaign management.
- Company Program: Like Owners, they can see and manage the program. They can add content to the schedule, manage the mandatory content list, and modify corrective workflows.
- Key Features: Can manage users, create phishing campaigns, and assign training/policies. However, they cannot sync with Entra ID or manage core system settings like SSO.
Reporting
The Reporting role provides visibility into the company's status without the ability to change settings.
- Company Program: They have view-only access to all program areas. While they can see the schedule, view month details, see the mandatory content list, and see corrective workflows, they cannot add, edit, or manage any of these items.
- Key Features: Authorized to view all dashboards, drill down into charts, and export data (users, assignments, logs) to CSV for analysis.
Admin Permissions for MSP and vCISO Companies
MSP and vCISO permissions are different from those of single companies. For the case of MSP and vCISO partners, we only offer 2 roles: Members and Owners.
This guide outlines the primary responsibilities and access levels for the administrative roles within the Command Center for managing multiple companies.
MSP Owner
The MSP Owner has unrestricted administrative authority across the entire partner account and all their child companies.
- Full Company Control: Ability to create, manage, and delete companies or groups.
- Admin Management: Exclusive permission to invite new admins, edit admin profiles, change roles, and manage admin notifications.
- System & Whitelabel: Full access to MSP billing, invoices, and whitelabeling settings to customize the platform's appearance.
- Program Templates: Full authority to generate, edit, and assign program templates to multiple companies or groups.
MSP Member
MSP Members handle multi-company operations but have restricted access to sensitive admin and account settings.
- Operational Management: Can create companies and groups, but cannot delete companies.
- Campaigns & Training: Full access to create phishing campaigns and manage training assets, including assigning them individually to companies or groups.
- Limited Admin Access: They can see the user list and generate password resets, but they cannot invite admins, edit admin information, or change roles.
- Program Templates: Like Owners, they can generate, edit, and assign program templates.
Multi-Company Program & Assignments
- Program Templates: Both roles can create and manage templates that define the security strategy across multiple organizations.
- Assignments & Queue: Both roles have full visibility into the training queue and can manage assignments, including changing due dates and marking items as completed.
- Reporting: Both roles can generate boardroom reports and access the full history of reports and audit logs.
If you need help with anything related to the use of the app, don't hesitate to contact us at support@symbolsecurity.com.