Roles, users and access
Who sees what, how to invite your team, and how to keep company data separated.
Roles in short
Section titled “Roles in short”Access depends on role. View-only users cannot run destructive actions. Technicians handle devices and cases. Company admin / owner manages settings, branding and users within that company.
- Viewer — mostly read-only.
- Technician — daily RMM and CRM work in their company.
- Company admin — company data, users, PDF report branding.
- Client portal —
client-view(own tickets only) orclient-manager(whole company + device preview). CRM invite: Decision maker → company account. Guide: Client portal. - Do not share one login across the team — create separate accounts.
Invites, users and profile
Section titled “Invites, users and profile”Add people in RMM → Settings → users (often /rmm/settings?tab=users) or from My companies when creating a company. Recommended: email invite with an activation link — the user sets their own password.
In the profile set password, language, timezone; optionally 2FA (TOTP). Protocol signature also lives on the user.
- Open Settings → Users (company admin permission required).
- Add a user: email, role (e.g. technician / viewer).
- Send the invite and ask them to finish signup from the email.
- After first login: profile, notification preferences, optional protocol signature.
- Do not share one login across the team — you lose accountability.
- Viewer = read-only; technician = daily work; company admin = users, branding, company data.
- Branding (logo, PDF colours) is set in Preferences — per company.
- Invite email missing: check spam and the address, then contact Darnet support.
- Expired
/inviteor/reset-passwordlink: ask an admin to resend the invite, or use Forgot password. The token is single-use and time-limited.
Companies (tenants) — important boundaries
Section titled “Companies (tenants) — important boundaries”Each company has its own devices, clients and users. Always confirm you are in the correct company context. One company’s data must not leak into another.
- Before a bulk action (script, install) check the selected company.
- MSPs with many customers: separate companies / locations per your model.
- Platform-level permissions (outside your company) — ask a Darnet administrator.
Audit log
Section titled “Audit log”Company action history is in RMM → Audit log (/audit). The table is paginated (20 rows by default) and shows the actor email — not passwords or signatures. Date and action filters speed up search; CSV is for archive / SIEM. Platform-wide audit lives under /rmm/platform (Audit tab). CRM has its own log in the CRM menu. Ransomware/phishing traces and alert-dedup refreshes stay on Protection and the alert — not in the audit log.