Guide

Working with role-based access control (RBAC)

David Starr

Add admins and team members to the MSP portal, choose their partner roles, and control which customer Workspaces each member can access.

Open the MSP Dashboard from the Workspace picker at the top of the Workbrew Console sidebar by choosing Managed Services, or navigate directly to https://console.workbrew.com/partners/<partner-name>. The tasks here use the Members and Customer Workspaces pages in the portal sidebar.

Partner roles

There are two partner roles:

  • Admin can manage partner members, create customer Workspaces, and gets admin access to every managed Workspace.
  • Member can only access customer Workspaces they have been explicitly granted.

What a member can do in a customer Workspace

Workspace roles are hierarchical:

  • Read can view everything in the Workspace, including Devices, packages, vulnerabilities, Policies, and the event log, but cannot change anything.
  • Write can manage Devices and Device Groups, create and assign Policies, run Brew Commands, edit Brewfiles, and approve or decline package requests (includes Read)
  • Admin can manage Workspace members, integrations such as Slack and GitHub, Taps, notifications, and Workspace settings. (includes Read and Write)

What a member can do in a customer Workspace comes from two things, their partner role and any per-Workspace grants:

Partner rolePer-Workspace grantAccess to the customer Workspace
Adminnot neededAdmin on every managed Workspace
MembernoneNo access
MemberReadRead on that Workspace
MemberWriteWrite on that Workspace
MemberAdminAdmin on that Workspace

In the event that a member is also a direct member of the customer Workspace, direct membership takes priority over the access derived through the partner roles.

Grant a member access to a customer Workspace

  1. On the Customer Workspaces page, find the Workspace and click its User Access action.
  2. Click Grant Access, choose the partner member and a Workspace role (read, write, or admin), and confirm.

To revoke a member's access, click Revoke next to their grant on the same page. Grants apply to that one Workspace only. Partner admins do not need grants because they already have admin access to every managed Workspace.

Add MSP admins and members

The Members page lists everyone in your organization and their partner role. Partner admins manage the team from it.

To add people, use Add Partner Member, which allows an admin to add several team members at once with the same role:

  1. Click Add Partner Member.
  2. Enter up to five email addresses, one per team member.
  3. Choose the partner role for the batch and click Add Member. Everyone added appears in the Members list with that role.

Each new member receives an invitation email. People without a Workbrew account get one created for their email address and can sign in with Email sign-in. Everyone added to the MSP team members list also gets read access to the partner's sandbox Workspace automatically (and loses it when they leave).

From the Members page, admins can change a member's role with the role dropdown or remove a member with Remove. Admins can leave the partner themselves with Leave Partner. The partner owner cannot have their role changed and cannot be removed.

The admin role is also the legal approver role for your organization. Admins accept the initial partner agreement during initial setup. The initial agreement page offers Print / Save as PDF for your records.

When Workbrew revises the MSP Partner Agreement, all partner admins receive written notice by email at least 30 days before the new version takes effect.

Any admin or member can review the latest version of the partner agreement at any time by selecting MSP Partner Agreement under the user menu in the sidebar or directly at https://console.workbrew.com/partners//agreement.

We use cookies to analyze traffic and improve your experience. You can accept all cookies or decline non-essential ones. Read our Privacy Policy for details.