evosecurity

Evo Portal

Roles & Permissions (RBAC)

Role-Based Access Control (RBAC) allows you to control what administrators can access and manage in the Evo Partner Portal.

Roles are made up of permissions and can be assigned directly to users or to groups. A user's effective access is the combined access provided by all roles assigned to them.

RBAC is managed from:

Evo Admin → Permissions → Roles

Notion image

How RBAC works

RBAC follows two important rules:

Access can only be added. There is no explicit "deny" permission. If a user has access to something, that access is coming from one of their assigned roles.

Roles are reusable. A role is not tied to a specific user or tenant. Create a role once and assign it to multiple users or groups as needed.

Note: A role does not give a standard user access to the Partner Portal. The user must already be a portal admin. Roles determine what a portal admin can access after they sign in.

Creating a Role

To create a role:

  1. Navigate to Evo Admin → Permissions → Roles.
  1. Select New role.
  1. Enter the role name.
  1. Enter a description.
  1. Configure the required permissions.
  1. Assign users or groups.
  1. Select Create role.
Notion image

The Roles & Permissions interface uses green and blue indicators to show how access is granted. The color of an indicator, along with how it is filled, makes it easy to understand a role's access at a glance.

Green — Inherited Access
Marker
Meaning
○ Empty outline
No access to anything in this category.
● Solid green
Everything in the category is on, and it comes from a category or group grant.
◐ Half green
Some of the category is on, from a group grant (the category isn't fully covered).
● Solid blue
Everything in the category is on, but only because every permission was ticked individually.
◐ Half blue
Some permissions are on, all of them ticked individually.
◑ Half green / half blue
Everything is on, from a mix of standing grants and individual picks.
◔ Quarter blue + quarter green
Partial access, from a mix of both.

Built-in Roles

Evo provides a set of Built-in roles designed for common administrative responsibilities. These roles are available by default in a new environment and provide a predefined set of permissions for specific areas of the Partner Portal.

Built-in roles are identified by the BUILT-IN badge in the Roles list.

Role
What it covers
Super Admin
Full access to every Admin Portal capability.
Billing & License Admin
Billing and license assignment.
Tenant Admin
Customers, tenant access, directories, users, groups, group members, customer activity.
EUE Admin
End-user elevation requests, elevation rules, system elevation, notifications.
HDV Admin
Help desk verifications, plus View Users.
RADIUS Admin
RADIUS servers and configuration (plus Dashboard).
Endpoint Admin
Computers, local admin accounts, domain accounts, web accounts (plus Dashboard, and View Groups / Directory so those screens are usable).
Policy Admin
Endpoint and environment policies (plus Dashboard).
Integrations Admin
SIEM, PSA, RMM and password-sync integrations (plus Dashboard).
Access & Token Admin
Access and deployment tokens, and user login keys (plus Dashboard, and View Users / Directory).
Auditor
Read-only visibility across the portal — 18 individually granted read permissions.
Mobile Admin
Elevation and help desk verification actions in the Evo mobile app (see section 8).
Notion image

Built-in roles are managed by Evo and have a predefined set of permissions. As a partner, you can assign these roles to administrators, but you cannot modify the role itself.

Built-in roles cannot be edited or deleted. Their name, description, and permissions are managed by Evo to ensure they remain consistent across environments. Built-in roles display a View icon instead of an Edit icon, and the Delete option is not available.

Built-in roles can be assigned to users and groups. You can add or remove assignments at any time. When managing assignments for a Built-in role, the save option is displayed as Save assignments.

Built-in roles can be cloned. If a Built-in role is close to what you need but requires additional permissions or restrictions, use Clone to create a Custom role. The cloned role can then be modified and assigned as needed.

List of Roles

The Role-Based Permissions section includes a variety of Built-in and Custom roles, each designed to provide access to specific areas of the Evo Partner Portal.

While some role names are straightforward, others may not immediately make their purpose clear. The sections below provide an overview of each available role and the permissions it provides.

Access And Deployment Tokens

Tokens used to enroll agents and authenticate deployments.

Permission
Description
View Tokens
View access and deployment token listings.
Manage Tokens
Create, update, and delete access and deployment tokens.
Create Access Token
Create new access or deployment tokens.
Delete Access Token
Delete access or deployment tokens.
Update Access Token
Update existing access or deployment tokens.

Applications

Application registrations and permission grants.

Permission
Description
Manage Application Permissions
Manage permission grants for applications.
Manage Applications
Manage application registrations.

Billing

Billing details, invoices, and payment settings for global and tenant accounts.

Permission
Description
Manage Global Billing
Manage global billing settings and payment methods.
Manage Tenant Billing
Manage billing settings for individual tenants.
View Billing
View billing details and invoice history.

Branding

White-label branding such as logos and color schemes.

Permission
Description
View Customization Section
Access the Customization section of the portal.
Manage Branding
Upload logos and clear unsaved logo changes.
Add Logo
Upload a custom logo.
Clear Logo Changes
Display the Clear control in the logo editor to discard unsaved changes.

Command Center

Environment management and global admin impersonation.

Permission
Description
Access Command Center
Access the Command Center environment manager.
Impersonate Global Admin
Impersonate a global admin account for support purposes.

Computers

Managed computers and devices, including updates, removal, and synchronization.

Permission
Description
Manage Agent Updates
Manage agent update settings and trigger agent updates.
View Agent Runtime State
View live agent status on the endpoint list.
View Computers
View computer and device listings.
Manage Computers
Update, refresh, and remove managed computers.
Delete Device
Remove computers from management.
Update Device
Update computer device records.

Customer Activity

Customer activity, audit events, and security event logs.

Permission
Description
View Customer Activity
View customer activity logs.
View Customer Audit Events
View customer audit event history.
View Security Events
View security event logs.

Customers

Tenant environments and their lifecycle.

Permission
Description
Manage Customers
Create and delete tenant environments.
Create Tenant
Create a new tenant environment.
Delete Tenant
Delete a tenant environment.

Dashboard

Main dashboard and summary metrics.

Permission
Description
View Dashboard
View the main dashboard and summary metrics.

Directories

Connected identity directories such as Azure AD and LDAP.

Permission
Description
Manage Directories
Connect, edit, and remove directory connections.
Create Directory
Connect a new directory.
Delete Directory
Remove a directory connection.
Edit Directory
Edit directory connection settings.
View Directories
View connected directories and their integrations.
Directory
View connected directories.
View Directory Integrations
View directory integrations.

Domain Accounts

Elevated domain account logins and their day-to-day use.

Permission
Description
Use Domain Account Elevation
Use an elevated domain account to log in.
View Domain Accounts
View domain accounts and elevated login listings.
Manage Domain Accounts
Create, edit, and delete elevated domain account logins.
Create Elevated Logins
Create new elevated domain account logins.
Delete Elevated Logins
Delete elevated domain account logins.
Edit Elevated Logins
Edit existing elevated domain account logins.

Elevation Requests

Pending privilege elevation requests.

Permission
Description
Manage Elevation Requests
View and action pending elevation requests.

Elevation Rules

Rules governing privilege elevation.

Permission
Description
Manage Elevation Rule Scope Priorities
Set the priority order for elevation rule scopes.
Manage Elevation Rules
Create, edit, and delete global elevation rules.
Manage Environment Elevation Rules
Create, edit, and delete environment-scoped elevation rules.

Group Members

User membership within groups.

Permission
Description
Manage Members
Add and remove users from groups.
Add Members
Add users to a group.
Remove Members
Remove users from a group.

Groups

User groups and their membership rules.

Permission
Description
View Groups
View group listings.
Manage Groups
Create, edit, and delete groups.
Add Group
Create new groups.
Destroy Group
Delete groups.
Edit Group
Edit group details and membership rules.

Help Desk Verifications

Help desk identity verification settings.

Permission
Description
Manage Help Desk Verifications
Configure and manage help desk identity verification settings.

Licenses

Product license assignment.

Permission
Description
Assign Licenses
Assign product licenses to tenants or users.

Local Admin Accounts

Local administrator accounts on managed devices.

Permission
Description
Manage Local Admin Accounts
Manage local admin accounts on managed devices.

Login Keys

Login keys issued to users.

Permission
Description
View Login Keys
View login keys issued to users.
Manage Login Keys
Issue, activate, deactivate, and delete user login keys.
Activate or Deactivate Login Key
Activate or deactivate a user login key.
Delete Login Key
Delete a user login key.
Issue Login Key
Issue a new login key to a user.

Mobile

Capabilities available to technicians in the Evo mobile app.

Permission
Description
Mobile Elevation Technician
Perform elevation actions from the mobile app.
Mobile Help Desk Verification Technician
Perform help desk identity verifications from the mobile app.

Notifications

Elevation and general notification configuration.

Permission
Description
Manage Elevation Notifications
Configure global elevation notification settings.
Manage Environment Elevation Notifications
Configure environment-scoped elevation notification settings.
Manage Notification Configuration
Manage general notification configuration.

Onboarding

Onboarding enrollments for bringing new users and devices into the portal.

Permission
Description
View Onboarding
View onboarding and enrollment listings.
Manage Onboarding
Create, edit, and delete onboarding enrollments.
Create Enrollment
Create new onboarding enrollment records.
Delete Enrollment
Delete onboarding enrollment records.
Edit Enrollment
Edit onboarding enrollment settings.

PSA Integrations

Professional Services Automation integrations.

Permission
Description
Manage PSA Integrations
Configure and manage PSA integrations.

Partner API

Partner API keys used to authenticate API access.

Permission
Description
Manage Partner API
Manage Partner API keys and settings.

Password Sync Integrations

Password synchronization integrations.

Permission
Description
Manage Password Sync Integrations
Configure and manage password synchronization integrations.

Policies

Security policies, including the global default policy and individual policies.

Permission
Description
Manage Global Policy
Edit the global default policy.
View Policies
View policy listings and configurations.
Manage Policies
Create, edit, delete, enable, and disable policies.
Create Policy
Create a new policy.
Delete Policy
Delete a policy.
Edit Policy
Edit an existing policy.
Update Policy
Enable or disable a policy.

RADIUS

RADIUS servers used for network authentication.

Permission
Description
View RADIUS Servers
View RADIUS server listings.
Manage RADIUS Servers
Add, edit, and remove RADIUS servers.
Create RADIUS
Add a new RADIUS server.
Delete RADIUS
Remove a RADIUS server.
Edit RADIUS
Edit RADIUS server settings.

RMM

RMM integrations and deployment settings.

Permission
Description
Manage RMM Deployments
Manage RMM deployment settings.
Manage RMM Integrations
Configure and manage RMM integrations.

Role Management

Roles and permissions that define administrator access.

Permission
Description
View Roles
View roles and permission group listings.
Manage Roles
Create, edit, and delete roles.
Create Role
Create new roles.
Delete Role
Delete roles.
Edit Role
Edit role names and permissions.

Sessions

Active user sessions.

Permission
Description
Manage Sessions
View and revoke active user sessions.

Support Access

Evo support access to environments.

Permission
Description
Manage Evo Support Access
Grant or revoke Evo support team access to environments.

System Elevation

System-level elevation capabilities.

Permission
Description
Use System Level Elevations
Use system-level elevation capabilities.

Tenant Access

Tenant access settings.

Permission
Description
Manage Tenant Access
Manage access settings for tenants.

Users

User accounts, profiles, and lifecycle management.

Permission
Description
Reset Security Questions
Reset a user's security questions.
Send Password Reset
Display the Password Reset action on a user. Users can also request the same email from the sign-in page.
Send Welcome Email
Send a welcome email to a user.
View Users
View user listings and profile details.
Manage Admin Status
Promote users to admins and demote admins to users.
Convert Admin To User
Demote an admin account to a standard user.
Convert User To Admin
Promote a standard user to an admin.
Manage User
Create, disable, and delete users and manage user MFA and aliases.
Create User
Create new user accounts.
Delete User
Delete user accounts.
Disable MFA
Disable MFA for a user.
Disable User
Disable a user account.
Manage User Aliases
Manage email aliases for a user account.

Web Accounts

Web account credentials used for authentication.

Permission
Description
Manage Web Accounts
Manage web account credentials.
Use Web Accounts
Use web account credentials for authentication.
Did this answer your question?
😞
😐
🤩