Roles and Permissions

Six levels of access, one tenant boundary, and an audit-ready answer to "who could have done this" — for managed service providers who administer their own staff and their clients' at the same time.

The problem

The person who set up your PSA is not the person still administering it. The technician who left in March is still in a directory group that grants ticket access. A client asked for “just read-only” and got an admin account because that was the only role that let them see invoices. Nobody can say, without opening the database, which of your clients’ users can currently deactivate their own colleagues.

Multi-tenant makes it worse, because there are two organizations in every decision. Your technician outranks the client’s administrator inside the client’s own workspace — which is correct, and which almost every access model gets wrong the first time, because “administrators only” quietly includes every technician you employ.

What Solidlio does about it

The role floor answers “what rank”, the account scope answers “whose data”, and neither is allowed to stand in for the other.

The six-level hierarchy — platform admin, MSP admin, MSP technician, organization admin, power user, customer — is an ordered rank, so most routes express a threshold. Where the honest answer is a list rather than a threshold — “only administrators may rewrite role definitions” — Solidlio uses an explicit role set instead, which is the only way to exclude a technician who outranks the client’s own admin.


Capabilities

CapabilityWhat it does
Six-level role hierarchyOne ordered scale from platform admin to customer, enforced at 706 guard points across 14 services (counted 2026-07-28; the figure moves as routes are added).
Portal-level separationA person’s roles set the highest portal they may activate; they can work at that level or any below.
Tenant confinementEvery tenant-owned query is pinned to the caller’s account; a missing account context matches nothing.
Role sets, not just ranksAdministrative capabilities are guarded by a named set, so a senior role is not silently admitted.
Privilege ceilingNobody can assign a role above their own tier — enforced for organization, account and platform staff.
Custom roles per organizationCreate named job functions, or clone a shipped role and adjust the copy independently of the original.
Time-limited assignmentsAn assignment can expire on a date or be suspended; both are honoured everywhere a role is resolved.
Directory-driven rolesMap a SCIM-synced identity-provider group to an organization-owned role; membership follows the group.
Role-based routingSpend approvals, ticket workflows and expiry notifications address people by role, not by name.
Separate platform staff ranksTridacom’s own five staff ranks live outside the tenant model, with their own no-promote-above ceiling.

Built for MSPs and their clients

Two administrators exist in every managed relationship, and they are not peers. Solidlio makes that explicit rather than approximating it with a shared login.

OrganizationMSP
Rank inside the client workspaceorganization administrator administers its own peopleMSP technician and MSP administrator both rank above it
Who may rewrite role definitionsIts own adminsMSP admins — deliberately not MSP technicians
Who may promote whomNever above the promoter’s own tierNever above the promoter’s own tier
Data reachIts own organizationEvery organization inside its account
Role catalogueShared system roles plus its own custom rolesSame, plus administration of a serviced client’s
Platform-wide rolesRead-onlyRead-only — only Tridacom can edit them

The structural guarantee: a client organization’s roles are its own — another tenant cannot read them, clone them, rename them, or inherit from them — while the MSP that operates the workspace always outranks the administrator inside it.


How it works

  1. Pick a portal. Roles determine the ceiling; the person works at that level or below. Switching re-reads current memberships rather than trusting the old token.
  2. Hit a route. The route’s guard is either a rank (“this level and above”) or a named set (“exactly these roles”), and it fails closed on an unrecognised role.
  3. Read or write data. The account scope is spread into the query, so a cross-tenant identifier returns nothing rather than another tenant’s row.
  4. Administer roles. Administrators create, clone, assign and time-limit named roles from Administration → Roles, and see exactly who holds each one and whether their assignment is active, revoked or expired.

Compliance and audit

  • Every assignment is attributable. A role assignment records who assigned it, when, whether it is primary, whether it is active, and when it expires.
  • Lifetime is enforced, not decorative. An expired or suspended assignment stops counting immediately, in effective permissions, spend-approval routing and workflow role conditions alike.
  • Escalation is bounded in three places. Organization roles, account roles and platform staff ranks each refuse a grant above the granter’s own tier, and an unrecognised caller role grants nothing at all.
  • Platform-owned objects are separated from tenant-owned ones. The permission catalogue and the shared system roles can only be changed by Tridacom; a tenant administrator’s reach stops at their own account.

Editions

Role administration is not metered. Every tier includes the full model; tiers differ in how many people you can put in an organization and whether roles can be driven from your directory.

CapabilityFreeStarter / EssentialsGrowth / ProfessionalScale / BusinessEnterprise
Six-level role hierarchy
Tenant confinement
Custom roles and cloning
Time-limited assignments
Privilege ceilings
Seats per organization (MSP)5152550Unlimited
Seats per organization (customer)3102550Unlimited
Single sign-on
API accessRead-onlyFullFull

Integrations

  • Microsoft Entra ID and Google Workspace — just-in-time provisioning at first SSO login, with an administrator-chosen default organization role.
  • SCIM — inbound user and group provisioning. A synced directory group can be mapped to one organization-owned role, and membership reconciles on every directory change.
  • Microsoft 365 directory sync — role assignments maintained from the connected tenant.

Access that can be explained in one sentence, and proved in one query.

See this working on a real account.

Book a walkthrough and we will run this capability against your own clients, devices and tickets.

Book a demo All features

A 30-minute walkthrough against your own workflow. No slides.