Skip to main content

Admin Account User Roles

When adding users, they can have different roles and permissions.

These are MSP roles, meaning users with these roles log into admin.hatz.ai


What Can Each Role Do?

User Role

Permissions

Note

Primary Admin

  • Create new tenants

  • Purchase packages

  • Add users

  • Delete users

  • Resend invites

  • Create apps

  • Publish apps to all tenants

  • View Billing portal

  • Change user roles

  • Update My Interface

  • Reset MFA

Primary admin cannot be deleted by other admins

Admin

  • Create new tenants

  • Purchase packages

  • Add users

  • Delete users

  • Resend invites

  • Create apps

  • Publish apps to all tenants

  • View Billing portal

  • Change user roles

  • Update My Interface

  • Reset MFA

Admin can be deleted by Primary Admin

Tenant Manager

  • Create new tenants

  • Add users

  • Delete users

  • Resend invites

  • Create apps

  • Publish apps to all tenants

  • Change user roles

  • Update My Interface

  • Reset MFA

Not a full Admin equivalent. Cannot purchase packages or view billing information, and cannot add or remove members on a tenant's Account Team.

Compliance Manager

  • View and manage compliance resources

  • View audit and invocation logs

  • Use admin-console tools outside purchasing

Designed for compliance administration without billing or purchasing access.

Billing Manager

  • View Billing portal

  • View users and roles

Able to view billing details of a tenant / MSP

Helpdesk

  • View all tenant apps


About the Tenant Manager role

Tenant Manager was originally introduced as “everything an Admin can do except billing.” That is no longer accurate. The Admin role has since gained capabilities that were not extended to Tenant Manager, so treat the Tenant Manager list above as the current permission set rather than assuming parity with Admin.

Two differences come up most often:

  • Billing and packages. Tenant Managers cannot view the Billing portal or purchase packages.

  • Account Teams. Only Admin and Primary Admin can add or remove members on a tenant's Account Team. A Tenant Manager cannot do this, even for a tenant they already manage.

Tenant visibility works differently too. When Account Team enforcement is on, Tenant Managers only see the tenants they are assigned to, while Admin, Primary Admin, and Billing Manager keep access to every tenant. See Account Teams for how that works.

Did this answer your question?