Unity Platform System Roles and Permissions

Overview

Use this reference to choose the right built-in role, understand who can manage whom, and see exactly which permissions each system role includes.

Use Case: Decide whether to assign Super Admin, Admin, Technician, Billing, Co-Managed, or End User, and confirm what each permission allows.

Who Should Use This: Super Admins and Admins who assign roles in Unity Platform. Technicians and Billing users can use this page to understand their own access.

Last Updated: 2026-08-14


 

How roles work

Unity Platform uses system roles (built in) and custom roles (you create).

Every user has a default role. For Super Admin, Admin, Technician, and Billing, that default reaches every customer under your partner account. For Co-Managed and End User, it reaches the user’s home tenant only (their own organization).

You can override the default on a specific customer. See Change a User’s Role and Tenant-Specific Permissions.

You cannot edit system role permissions. To mix permissions differently, create a custom role.


 

System roles

Role Best for Reach Permission count
Super Admin Owners of the partner organization Every customer under the partner 26 of 26
Admin Day-to-day partner administrators Every customer under the partner 26 of 26
Technician Engineers who manage customer environments Every customer under the partner 16 of 26
Billing Finance and subscription work Every customer under the partner 6 of 26
Co-Managed A customer-side product administrator Home tenant only 11 of 26
End User A customer-side product operator Home tenant only 3 of 26

 

Super Admin

Full access to Unity Platform and every subscribed product. Super Admin is the only role that can manage Admin users. Use this for a small set of owners.

Super Admin and Admin have the same permissions. They differ only in rank: Super Admin sits above Admin.

Admin

Full Unity Platform and product access, including billing, marketplace, branding, SSO, and role management. Admins can manage Technician, Billing, Co-Managed, End User, and custom-role users. Admins cannot change Super Admins or other Admins.

Technician

Manages customers, users, and SSO, and has operating access to ControlOne, Telivy, Tentacle, and UCaaS. Technician does not include billing, marketplace, branding, agreements, member MSP management, UCaaS Center, or Role Management. Technicians cannot create or edit roles.

Billing

Works in Command Center and Insights, views customers, and manages marketplace, subscriptions, invoices, payments, and UCaaS Center (proposals and commission payouts). Billing does not manage users, roles, SSO, branding, or product administration.

Co-Managed

Product administration for a customer, without Unity Platform partner-portal access. Includes ControlOne administration (portal, reporting, user management, teleport, and agent), Telivy Admin, and Tentacle Admin. Use this for a trusted contact at the customer who should run the products, not the partner portal.

End User

Operating access to the products that customer subscribes to: ControlOne agent, Telivy User, and Tentacle User. No Unity Platform partner-portal permissions and no product-admin permissions.


 

Who can manage whom

Role changes are allowed only when your rank is higher than the user’s current ranked role. Equal rank is not enough.

Actor Can manage Super Admin Admin Technician Billing Co-Managed / End User / custom
Super Admin No Yes Yes Yes Yes
Admin No No Yes Yes Yes
Technician No No No No No (no Role Management)
Billing No No No No No (no Role Management)

Co-Managed and End User are unranked. Assigning them still requires Role Management permission, which those roles do not have.


 

Permission descriptions

 

Unity Platform

Permission What it allows
Command Center Access the Command Center dashboard
Insights Access Access Insights and QBR tools
Customer Access View and manage customer tenants
User Management Invite and manage users
Marketplace Access the Marketplace and cart
Billing Access Manage subscriptions, invoices, and payments
Branding Access Configure partner branding
SSO Access Configure single sign-on
Role Management Create, edit, and assign roles
Agreements Access View and manage partner agreements
UCaaS Center Access Access the UCaaS Center
Member Management Manage the member MSP network

 

ControlOne

Permission What it allows
ControlOne Admin Full administrative access to ControlOne
ControlOne Agent Access Access the ControlOne agent
ControlOne Teleport Access Teleport to this company
ControlOne View Portal View portal sections
ControlOne Modify Portal Edit portal sections
ControlOne View Reporting View reporting data
ControlOne Modify Reporting Modify reporting settings
ControlOne View User Management View user-management data
ControlOne Modify User Management Create and modify ControlOne users

 

Telivy, Tentacle, and UCaaS

Permission What it allows
Telivy Admin Administrative access to Telivy
Telivy User Operating access to Telivy
Tentacle Admin Administrative access to Tentacle
Tentacle User Operating access to Tentacle
UCaaS Reseller Reseller-level access to the UCaaS platform

 

Permission matrix

Yes means the system role includes the permission.

Unity Platform

Permission Super Admin Admin Technician Billing Co-Managed End User
Command Center Yes Yes Yes Yes No No
Insights Access Yes Yes Yes Yes No No
Customer Access Yes Yes Yes Yes No No
User Management Yes Yes Yes No No No
Marketplace Yes Yes No Yes No No
Billing Access Yes Yes No Yes No No
Branding Access Yes Yes No No No No
SSO Access Yes Yes Yes No No No
Role Management Yes Yes No No No No
Agreements Access Yes Yes No No No No
UCaaS Center Access Yes Yes No Yes No No
Member Management Yes Yes No No No No

 

ControlOne

Permission Super Admin Admin Technician Billing Co-Managed End User
ControlOne Admin Yes Yes No No Yes No
ControlOne Agent Access Yes Yes Yes No Yes Yes
ControlOne Teleport Access Yes Yes Yes No Yes No
ControlOne View Portal Yes Yes Yes No Yes No
ControlOne Modify Portal Yes Yes Yes No Yes No
ControlOne View Reporting Yes Yes Yes No Yes No
ControlOne Modify Reporting Yes Yes Yes No Yes No
ControlOne View User Management Yes Yes Yes No Yes No
ControlOne Modify User Management Yes Yes Yes No Yes No

 

Telivy, Tentacle, and UCaaS

Permission Super Admin Admin Technician Billing Co-Managed End User
Telivy Admin Yes Yes No No Yes No
Telivy User Yes Yes Yes No No Yes
Tentacle Admin Yes Yes No No Yes No
Tentacle User Yes Yes Yes No No Yes
UCaaS Reseller Yes Yes Yes No No No

 

Custom roles and what you can assign

Custom roles are created per partner. They have no fixed permission set.

When you build a custom role:

  • Unity Platform permissions can be included.
  • Telivy Admin, Tentacle Admin, Telivy User, Tentacle User, and UCaaS Reseller can be included for partner custom roles.
  • Telivy User and Tentacle User can also be used on customer-scoped custom roles.
  • ControlOne permissions are not available in the custom role builder. They are granted only through system roles.

For steps, see Create and Edit Custom User Roles.

Was this article helpful?
0 out of 0 found this helpful