Skip to main content

Inky admin permissions - allow granular control

Super Admin is currently required for onboarding customers, which also grants full product access. This means 10+ engineers in an MSP need Super Admin, with most of the rest needing policy management (the second highest tier). Best practice is least-privilege access.

There should be more granular permissions:

  • Separate role for user management at MSP level (internal IT owns this, not day-to-day support staff)

  • Separate role for onboarding new customers (professional services/projects teams shouldn't need full admin)

  • Separate permissions for mail security vs signature management (different staff, different skillsets)

  • Granular control over viewing message bodies — currently restricted to Super Admin, but lower-level or custom roles should be able to view message content without full Super Admin access

  • Ability to hide the Subject field by role — all roles can currently see subjects in analysis/observations message lists, and the recent "access denied" on restricted tenants doesn't prevent seeing subjects

Status: Planned11 comments

Log in to comment and vote

Comments11

  • Andy Suarez

    •

    Mar 16

    techs not being able to onboard new clients without giving the super admin privileges seems silly. Provide more options to allow and dissalow certain features for users, or build our own levels to apply to people.

  • Mark Gibson

    •

    Jun 3

    +1 to this, more granular controlls are neeeded.

  • Mike Otradnov

    •

    Sep 3

    Guys, it’s been 8 months since this request. Can it be prioritized please and indication of some progress or roadmap presence provided?

    We are ramping up our INKY usage and finding out more and more things that Analyst role can’t do and Policy Admin can. Let alone that to “onboard” you must be a Super Admin.

    Latest struggle is that Analyst can manage allow/block list but can’t whitelist or approve a URL that end-user has marked as safe.

    Policy Admin (next role up) can do so, but also can offboard the entire customer 🤯

  • Aki Stolt

    •

    Feb 25

    Our need is restrick anyone on MSP side to see email bodies. It´s illigal in Finland

  • Monty Dahlberg

    •

    Apr 11

    •

    Merged request

    •

    3 votes

    Granular Permissions for Viewing Message Bodies

    I want to be able to grant the permission to view message bodies to lower-level or custom admin roles. Currently, this is restricted to Super Administrators, but it would be helpful to have more granular control over who can see message content without granting full Super Admin access.
    • Logan Guzman

      •

      Mar 16

      Another idea is to allow a setting that only shows Danger or Danger Hi body content for a Admin Management user under a tenant.

    • Matt Sywulak

      Team•

      Apr 11

      This request has been merged into **"Inky admin permissions - allow granular control"** which now includes granular message body viewing permissions as a specific sub-item. Votes have been transferred.
  • Dustin Shepherd

    •

    Apr 11

    •

    Merged request

    •

    1 vote

    Hide 'Subject' based on role

    Currently, all roles can see all tenant messages in the analysis/observations ‘message list.’ This includes fields for ‘from’ ‘to’ ‘subject.’ With the recent changes, selecting a message displays an ‘access denied’ message for restricted tenant/teams, which is not sufficient as the subject can be seen.

    • Matt Sywulak

      Team•

      Apr 11

      This request has been merged into **"Inky admin permissions - allow granular control"** which now includes the ability to hide the Subject field by role. Votes have been transferred.
  • Hubert Oliver

    •

    Aug 13

    The Analyst role should have the ability to do Remediation, or we should have custom roles. I shouldn’t have to give a tech the ability to change all the settings and policies for a tenant just because I need them to be able to Remediate an email.

  • Hubert Oliver

    •

    Sep 23

    This needs to be implemented NOW. I can’t go making technicians SUPER ADMINS over the entire PARTNER account just to be able to add new clients to the service. Ever hear of Least Privilege?