Working with role-based access control (RBAC)
David Starr
Add admins and team members to the MSP portal, choose their partner roles, and control which customer Workspaces each member can access.
Open the MSP Dashboard from the Workspace picker at the top of the Workbrew Console sidebar by choosing Managed Services, or navigate directly to https://console.workbrew.com/partners/<partner-name>. The tasks here use the Members and Customer Workspaces pages in the portal sidebar.
Partner roles
There are two partner roles:
- Admin can manage partner members, create customer Workspaces, and gets admin access to every managed Workspace.
- Member can only access customer Workspaces they have been explicitly granted.
What a member can do in a customer Workspace
Workspace roles are hierarchical:
- Read can view everything in the Workspace, including Devices, packages, vulnerabilities, Policies, and the event log, but cannot change anything.
- Write can manage Devices and Device Groups, create and assign Policies, run Brew Commands, edit Brewfiles, and approve or decline package requests (includes Read)
- Admin can manage Workspace members, integrations such as Slack and GitHub, Taps, notifications, and Workspace settings. (includes Read and Write)
What a member can do in a customer Workspace comes from two things, their partner role and any per-Workspace grants:
| Partner role | Per-Workspace grant | Access to the customer Workspace |
|---|---|---|
| Admin | not needed | Admin on every managed Workspace |
| Member | none | No access |
| Member | Read | Read on that Workspace |
| Member | Write | Write on that Workspace |
| Member | Admin | Admin on that Workspace |
In the event that a member is also a direct member of the customer Workspace, direct membership takes priority over the access derived through the partner roles.
Grant a member access to a customer Workspace
- On the Customer Workspaces page, find the Workspace and click its User Access action.
- Click Grant Access, choose the partner member and a Workspace role (read, write, or admin), and confirm.
To revoke a member's access, click Revoke next to their grant on the same page. Grants apply to that one Workspace only. Partner admins do not need grants because they already have admin access to every managed Workspace.
Add MSP admins and members
The Members page lists everyone in your organization and their partner role. Partner admins manage the team from it.
To add people, use Add Partner Member, which allows an admin to add several team members at once with the same role:
- Click Add Partner Member.
- Enter up to five email addresses, one per team member.
- Choose the partner role for the batch and click Add Member. Everyone added appears in the Members list with that role.
Each new member receives an invitation email. People without a Workbrew account get one created for their email address and can sign in with Email sign-in. Everyone added to the MSP team members list also gets read access to the partner's sandbox Workspace automatically (and loses it when they leave).
From the Members page, admins can change a member's role with the role dropdown or remove a member with Remove. Admins can leave the partner themselves with Leave Partner. The partner owner cannot have their role changed and cannot be removed.
Legal agreement and notifications
The admin role is also the legal approver role for your organization. Admins accept the initial partner agreement during initial setup. The initial agreement page offers Print / Save as PDF for your records.
When Workbrew revises the MSP Partner Agreement, all partner admins receive written notice by email at least 30 days before the new version takes effect.
Any admin or member can review the latest version of the partner agreement at any time by selecting MSP Partner Agreement under the user menu in the sidebar or directly at https://console.workbrew.com/partners/
Related docs
- Working with customer Workspaces - creating the Workspaces you grant access to, and why your team never appears in the customer's member list
- Working with the MSP dashboard - why partner members see only some Workspaces in its tables
- Workbrew MSP overview - what Workbrew MSP is and the guides for its other areas
- Console login and SSO enforcement - how new members sign in to the Workbrew Console