Overview
Use this reference to choose the right built-in role, understand who can manage whom, and see exactly which permissions each system role includes.
Use Case: Decide whether to assign Super Admin, Admin, Technician, Billing, Co-Managed, or End User, and confirm what each permission allows.
Who Should Use This: Super Admins and Admins who assign roles in Unity Platform. Technicians and Billing users can use this page to understand their own access.
Last Updated: 2026-08-14
How roles work
Unity Platform uses system roles (built in) and custom roles (you create).
Every user has a default role. For Super Admin, Admin, Technician, and Billing, that default reaches every customer under your partner account. For Co-Managed and End User, it reaches the user’s home tenant only (their own organization).
You can override the default on a specific customer. See Change a User’s Role and Tenant-Specific Permissions.
You cannot edit system role permissions. To mix permissions differently, create a custom role.
System roles
| Role | Best for | Reach | Permission count |
|---|---|---|---|
| Super Admin | Owners of the partner organization | Every customer under the partner | 26 of 26 |
| Admin | Day-to-day partner administrators | Every customer under the partner | 26 of 26 |
| Technician | Engineers who manage customer environments | Every customer under the partner | 16 of 26 |
| Billing | Finance and subscription work | Every customer under the partner | 6 of 26 |
| Co-Managed | A customer-side product administrator | Home tenant only | 11 of 26 |
| End User | A customer-side product operator | Home tenant only | 3 of 26 |
Super Admin
Full access to Unity Platform and every subscribed product. Super Admin is the only role that can manage Admin users. Use this for a small set of owners.
Super Admin and Admin have the same permissions. They differ only in rank: Super Admin sits above Admin.
Admin
Full Unity Platform and product access, including billing, marketplace, branding, SSO, and role management. Admins can manage Technician, Billing, Co-Managed, End User, and custom-role users. Admins cannot change Super Admins or other Admins.
Technician
Manages customers, users, and SSO, and has operating access to ControlOne, Telivy, Tentacle, and UCaaS. Technician does not include billing, marketplace, branding, agreements, member MSP management, UCaaS Center, or Role Management. Technicians cannot create or edit roles.
Billing
Works in Command Center and Insights, views customers, and manages marketplace, subscriptions, invoices, payments, and UCaaS Center (proposals and commission payouts). Billing does not manage users, roles, SSO, branding, or product administration.
Co-Managed
Product administration for a customer, without Unity Platform partner-portal access. Includes ControlOne administration (portal, reporting, user management, teleport, and agent), Telivy Admin, and Tentacle Admin. Use this for a trusted contact at the customer who should run the products, not the partner portal.
End User
Operating access to the products that customer subscribes to: ControlOne agent, Telivy User, and Tentacle User. No Unity Platform partner-portal permissions and no product-admin permissions.
Who can manage whom
Role changes are allowed only when your rank is higher than the user’s current ranked role. Equal rank is not enough.
| Actor | Can manage Super Admin | Admin | Technician | Billing | Co-Managed / End User / custom |
|---|---|---|---|---|---|
| Super Admin | No | Yes | Yes | Yes | Yes |
| Admin | No | No | Yes | Yes | Yes |
| Technician | No | No | No | No | No (no Role Management) |
| Billing | No | No | No | No | No (no Role Management) |
Co-Managed and End User are unranked. Assigning them still requires Role Management permission, which those roles do not have.
Permission descriptions
Unity Platform
| Permission | What it allows |
|---|---|
| Command Center | Access the Command Center dashboard |
| Insights Access | Access Insights and QBR tools |
| Customer Access | View and manage customer tenants |
| User Management | Invite and manage users |
| Marketplace | Access the Marketplace and cart |
| Billing Access | Manage subscriptions, invoices, and payments |
| Branding Access | Configure partner branding |
| SSO Access | Configure single sign-on |
| Role Management | Create, edit, and assign roles |
| Agreements Access | View and manage partner agreements |
| UCaaS Center Access | Access the UCaaS Center |
| Member Management | Manage the member MSP network |
ControlOne
| Permission | What it allows |
|---|---|
| ControlOne Admin | Full administrative access to ControlOne |
| ControlOne Agent Access | Access the ControlOne agent |
| ControlOne Teleport Access | Teleport to this company |
| ControlOne View Portal | View portal sections |
| ControlOne Modify Portal | Edit portal sections |
| ControlOne View Reporting | View reporting data |
| ControlOne Modify Reporting | Modify reporting settings |
| ControlOne View User Management | View user-management data |
| ControlOne Modify User Management | Create and modify ControlOne users |
Telivy, Tentacle, and UCaaS
| Permission | What it allows |
|---|---|
| Telivy Admin | Administrative access to Telivy |
| Telivy User | Operating access to Telivy |
| Tentacle Admin | Administrative access to Tentacle |
| Tentacle User | Operating access to Tentacle |
| UCaaS Reseller | Reseller-level access to the UCaaS platform |
Permission matrix
Yes means the system role includes the permission.
Unity Platform
| Permission | Super Admin | Admin | Technician | Billing | Co-Managed | End User |
|---|---|---|---|---|---|---|
| Command Center | Yes | Yes | Yes | Yes | No | No |
| Insights Access | Yes | Yes | Yes | Yes | No | No |
| Customer Access | Yes | Yes | Yes | Yes | No | No |
| User Management | Yes | Yes | Yes | No | No | No |
| Marketplace | Yes | Yes | No | Yes | No | No |
| Billing Access | Yes | Yes | No | Yes | No | No |
| Branding Access | Yes | Yes | No | No | No | No |
| SSO Access | Yes | Yes | Yes | No | No | No |
| Role Management | Yes | Yes | No | No | No | No |
| Agreements Access | Yes | Yes | No | No | No | No |
| UCaaS Center Access | Yes | Yes | No | Yes | No | No |
| Member Management | Yes | Yes | No | No | No | No |
ControlOne
| Permission | Super Admin | Admin | Technician | Billing | Co-Managed | End User |
|---|---|---|---|---|---|---|
| ControlOne Admin | Yes | Yes | No | No | Yes | No |
| ControlOne Agent Access | Yes | Yes | Yes | No | Yes | Yes |
| ControlOne Teleport Access | Yes | Yes | Yes | No | Yes | No |
| ControlOne View Portal | Yes | Yes | Yes | No | Yes | No |
| ControlOne Modify Portal | Yes | Yes | Yes | No | Yes | No |
| ControlOne View Reporting | Yes | Yes | Yes | No | Yes | No |
| ControlOne Modify Reporting | Yes | Yes | Yes | No | Yes | No |
| ControlOne View User Management | Yes | Yes | Yes | No | Yes | No |
| ControlOne Modify User Management | Yes | Yes | Yes | No | Yes | No |
Telivy, Tentacle, and UCaaS
| Permission | Super Admin | Admin | Technician | Billing | Co-Managed | End User |
|---|---|---|---|---|---|---|
| Telivy Admin | Yes | Yes | No | No | Yes | No |
| Telivy User | Yes | Yes | Yes | No | No | Yes |
| Tentacle Admin | Yes | Yes | No | No | Yes | No |
| Tentacle User | Yes | Yes | Yes | No | No | Yes |
| UCaaS Reseller | Yes | Yes | Yes | No | No | No |
Custom roles and what you can assign
Custom roles are created per partner. They have no fixed permission set.
When you build a custom role:
- Unity Platform permissions can be included.
- Telivy Admin, Tentacle Admin, Telivy User, Tentacle User, and UCaaS Reseller can be included for partner custom roles.
- Telivy User and Tentacle User can also be used on customer-scoped custom roles.
- ControlOne permissions are not available in the custom role builder. They are granted only through system roles.
For steps, see Create and Edit Custom User Roles.