Skip to content

Manage your admin team

Your admin team lives under Settings → Admins — one page, one Add Admin button. Every admin you add gets two things: a role (Administrator or User) and an access level (global access to every client, or scoped access to a subset). We recommend SSO — connect Microsoft 365 or Google once, then add admins straight from your directory with no separate passwords to manage.

  • Admin access on your Microsoft 365 or Google Workspace tenant to approve the SSO consent grant once (only if you’re using SSO).
  • For a scoped admin: the list of clients they should — or shouldn’t — be able to see.

Two independent choices. Set both when you add an admin, and change either one later.

Role controls what they can do:

  • Administrator — full management of whatever they can see: settings, training, phishing, and reports.
  • User — read-oriented access; they can see the data but can’t manage admins, integrations, or take destructive actions.

Access controls which clients they can see:

  • Global — every client you manage, plus the partner-level Settings, Billing, and Insights. This is the default for your core team.
  • Scoped — a subset of your clients, with no access to partner Settings or Billing. Scoped admins still get the full dashboard and cross-client Insights — just filtered to the clients they’re allowed to see. Pick one of two ways to define the subset:
    • Only these clients — they see exactly the clients you choose. A client you onboard later won’t be visible to them until you add it.
    • All except these — they see every client except the ones you choose. A client you onboard later is visible to them automatically.

One button handles every case — global or scoped, invited by email or provisioned from your directory.

  1. Open Settings → Admins and click Add Admin.

  2. Choose who. If SSO is connected, search your directory and pick the person — they’re added with no email round-trip. If SSO isn’t connected, enter their email address and we’ll send them a sign-up link.

  3. Pick a role — Administrator or User.

  4. Pick an access level — Global, or Scoped. If you choose Scoped, select the mode (Only these clients or All except these) and check off the clients.

  5. Save. A directory-provisioned admin can sign in immediately with their Microsoft / Google account; an email-invited admin appears under Pending Invites until they accept.

After provisioning someone from your directory we’ll offer to send them a code-less welcome email with a sign-in link — handy so they know they’ve been added.

One-time partner-level setup. After this, every admin you add can come straight from your directory, and offboarding someone in your directory automatically ends their access here.

  1. Open Settings → Admins. The SSO section appears at the top.

  2. Click Connect Microsoft SSO or Connect Google SSO. A popup opens to the provider’s consent screen.

  3. Approve the consent grant using an admin account on the tenant you’re connecting. The popup closes and the SSO section shows Connected.

Email invites still work as a fallback when SSO isn’t an option — a teammate at a smaller org without a Workspace tenant, or an external collaborator. For any team already on Microsoft 365 or Google Workspace, SSO is the path to take.

Everything about an admin is editable from their row — including converting between global and scoped access in either direction.

  1. Click Edit on the admin’s row.

  2. Adjust their role and access. Switch a global admin to scoped (then pick the clients), or promote a scoped admin to global. Change the role at the same time if needed.

  3. Save. The change applies the next time that admin loads a page.

  1. Find the admin in the list and click Remove.

  2. Confirm. Their access is revoked immediately; in-flight sessions end the next time they try to act.

The removed admin’s historical activity stays in audit records — removing only revokes future access.

Once SSO is connected, you can require it: click Enable enforcement in the SSO section. Sign-in is then restricted to SSO — email/password no longer works for your admins. Disabling enforcement opens a confirmation that explains what changes (the sign-in restriction widens; nobody’s access changes). Enforcement is reversible at any time, and it’s a sign-in restriction, not an access restriction.

  • A new admin appears in the Admins list with a Global or Scoped badge and their role.
  • A scoped admin, when they sign in, sees only their clients on the dashboard and in Insights — and has no Settings or Billing menu.
  • A directory-provisioned admin can sign in with their Microsoft / Google account and land directly on the dashboard, no second step.

What’s the difference between global and scoped access? A global admin sees every client and can change partner-level settings (branding, billing, integrations, defaults). A scoped admin sees only a subset of clients and can’t open partner Settings or Billing — but they still get the dashboard and cross-client Insights for the clients they’re allowed to see.

Can I give someone access to just a few of my clients? Yes — that’s scoped access. Add or edit the admin, choose Scoped → Only these clients, and pick the ones they should see. If it’s easier to describe by exception, use All except these instead.

If I onboard a new client, will my scoped admins see it? Depends on the mode. Only these clients is a fixed list — a new client isn’t visible until you add it to that admin. All except these includes new clients automatically (unless you add the new client to their exclusion list).

Can I change a global admin to scoped later, or the other way around? Yes. Click Edit on their row and switch the access level — there’s no need to remove and re-add them.

Can a scoped admin manage other admins or change my partner settings? No. Admin management, billing, branding, integrations, and the other partner-level settings are global-admin only. Scoped admins never see those pages.

Why SSO over email invites? No separate passwords for your team to manage; access follows your directory, so disabling someone’s Microsoft / Google account ends their access here automatically; and adding someone is one click instead of an invite-accept round-trip. Worth the one-time setup for any team on Microsoft 365 or Google Workspace.

An admin left the company — what do I do? Disable their account in your directory. If they were provisioned through SSO, that ends their access automatically. If they came in by email invite, also click Remove on their row — directory offboarding doesn’t reach email-invite admins.

Can I require SSO? Yes — enable enforcement in the SSO section. It restricts sign-in to SSO only; email/password stops working for your admins.

SSO popup closed without completing — what now? Click Connect again. Each attempt is independent; the usual cause is the popup being blocked or the consent screen being cancelled.

  • Client admins — set up an admin on a single client’s People page for that client’s own IT team.
  • Partner-level settings — the hub overview of everything on the Settings page.
  • Sync users — provisioning end users (the people who take training) is a separate flow from admin management.