Evo Portal
Roles & Permissions (RBAC)
Role-Based Access Control (RBAC) allows you to control what administrators can access and manage in the Evo Partner Portal.
Roles are made up of permissions and can be assigned directly to users or to groups. A user's effective access is the combined access provided by all roles assigned to them.
RBAC is managed from:
Evo Admin → Permissions → Roles

How RBAC works
RBAC follows two important rules:
Access can only be added. There is no explicit "deny" permission. If a user has access to something, that access is coming from one of their assigned roles.
Roles are reusable. A role is not tied to a specific user or tenant. Create a role once and assign it to multiple users or groups as needed.
Note: A role does not give a standard user access to the Partner Portal. The user must already be a portal admin. Roles determine what a portal admin can access after they sign in.
Creating a Role
To create a role:
- Navigate to Evo Admin → Permissions → Roles.
- Select New role.
- Enter the role name.
- Enter a description.
- Configure the required permissions.
- Assign users or groups.
- Select Create role.

The Roles & Permissions interface uses green and blue indicators to show how access is granted. The color of an indicator, along with how it is filled, makes it easy to understand a role's access at a glance.
Green — Inherited Access
Marker | Meaning |
○ Empty outline | No access to anything in this category. |
● Solid green | Everything in the category is on, and it comes from a category or group grant. |
◐ Half green | Some of the category is on, from a group grant (the category isn't fully covered). |
● Solid blue | Everything in the category is on, but only because every permission was ticked individually. |
◐ Half blue | Some permissions are on, all of them ticked individually. |
◑ Half green / half blue | Everything is on, from a mix of standing grants and individual picks. |
◔ Quarter blue + quarter green | Partial access, from a mix of both. |
Built-in Roles
Evo provides a set of Built-in roles designed for common administrative responsibilities. These roles are available by default in a new environment and provide a predefined set of permissions for specific areas of the Partner Portal.
Built-in roles are identified by the BUILT-IN badge in the Roles list.
Role | What it covers |
Super Admin | Full access to every Admin Portal capability. |
Billing & License Admin | Billing and license assignment. |
Tenant Admin | Customers, tenant access, directories, users, groups, group members, customer activity. |
EUE Admin | End-user elevation requests, elevation rules, system elevation, notifications. |
HDV Admin | Help desk verifications, plus View Users. |
RADIUS Admin | RADIUS servers and configuration (plus Dashboard). |
Endpoint Admin | Computers, local admin accounts, domain accounts, web accounts (plus Dashboard, and View Groups / Directory so those screens are usable). |
Policy Admin | Endpoint and environment policies (plus Dashboard). |
Integrations Admin | SIEM, PSA, RMM and password-sync integrations (plus Dashboard). |
Access & Token Admin | Access and deployment tokens, and user login keys (plus Dashboard, and View Users / Directory). |
Auditor | Read-only visibility across the portal — 18 individually granted read permissions. |
Mobile Admin | Elevation and help desk verification actions in the Evo mobile app (see section 8). |

Built-in roles are managed by Evo and have a predefined set of permissions. As a partner, you can assign these roles to administrators, but you cannot modify the role itself.
Built-in roles cannot be edited or deleted. Their name, description, and permissions are managed by Evo to ensure they remain consistent across environments. Built-in roles display a View icon instead of an Edit icon, and the Delete option is not available.
Built-in roles can be assigned to users and groups. You can add or remove assignments at any time. When managing assignments for a Built-in role, the save option is displayed as Save assignments.
Built-in roles can be cloned. If a Built-in role is close to what you need but requires additional permissions or restrictions, use Clone to create a Custom role. The cloned role can then be modified and assigned as needed.
List of Roles
The Role-Based Permissions section includes a variety of Built-in and Custom roles, each designed to provide access to specific areas of the Evo Partner Portal.
While some role names are straightforward, others may not immediately make their purpose clear. The sections below provide an overview of each available role and the permissions it provides.
Access And Deployment Tokens
Tokens used to enroll agents and authenticate deployments.
Permission | Description |
View Tokens | View access and deployment token listings. |
Manage Tokens | Create, update, and delete access and deployment tokens. |
Create Access Token | Create new access or deployment tokens. |
Delete Access Token | Delete access or deployment tokens. |
Update Access Token | Update existing access or deployment tokens. |
Applications
Application registrations and permission grants.
Permission | Description |
Manage Application Permissions | Manage permission grants for applications. |
Manage Applications | Manage application registrations. |
Billing
Billing details, invoices, and payment settings for global and tenant accounts.
Permission | Description |
Manage Global Billing | Manage global billing settings and payment methods. |
Manage Tenant Billing | Manage billing settings for individual tenants. |
View Billing | View billing details and invoice history. |
Branding
White-label branding such as logos and color schemes.
Permission | Description |
View Customization Section | Access the Customization section of the portal. |
Manage Branding | Upload logos and clear unsaved logo changes. |
Add Logo | Upload a custom logo. |
Clear Logo Changes | Display the Clear control in the logo editor to discard unsaved changes. |
Command Center
Environment management and global admin impersonation.
Permission | Description |
Access Command Center | Access the Command Center environment manager. |
Impersonate Global Admin | Impersonate a global admin account for support purposes. |
Computers
Managed computers and devices, including updates, removal, and synchronization.
Permission | Description |
Manage Agent Updates | Manage agent update settings and trigger agent updates. |
View Agent Runtime State | View live agent status on the endpoint list. |
View Computers | View computer and device listings. |
Manage Computers | Update, refresh, and remove managed computers. |
Delete Device | Remove computers from management. |
Update Device | Update computer device records. |
Customer Activity
Customer activity, audit events, and security event logs.
Permission | Description |
View Customer Activity | View customer activity logs. |
View Customer Audit Events | View customer audit event history. |
View Security Events | View security event logs. |
Customers
Tenant environments and their lifecycle.
Permission | Description |
Manage Customers | Create and delete tenant environments. |
Create Tenant | Create a new tenant environment. |
Delete Tenant | Delete a tenant environment. |
Dashboard
Main dashboard and summary metrics.
Permission | Description |
View Dashboard | View the main dashboard and summary metrics. |
Directories
Connected identity directories such as Azure AD and LDAP.
Permission | Description |
Manage Directories | Connect, edit, and remove directory connections. |
Create Directory | Connect a new directory. |
Delete Directory | Remove a directory connection. |
Edit Directory | Edit directory connection settings. |
View Directories | View connected directories and their integrations. |
Directory | View connected directories. |
View Directory Integrations | View directory integrations. |
Domain Accounts
Elevated domain account logins and their day-to-day use.
Permission | Description |
Use Domain Account Elevation | Use an elevated domain account to log in. |
View Domain Accounts | View domain accounts and elevated login listings. |
Manage Domain Accounts | Create, edit, and delete elevated domain account logins. |
Create Elevated Logins | Create new elevated domain account logins. |
Delete Elevated Logins | Delete elevated domain account logins. |
Edit Elevated Logins | Edit existing elevated domain account logins. |
Elevation Requests
Pending privilege elevation requests.
Permission | Description |
Manage Elevation Requests | View and action pending elevation requests. |
Elevation Rules
Rules governing privilege elevation.
Permission | Description |
Manage Elevation Rule Scope Priorities | Set the priority order for elevation rule scopes. |
Manage Elevation Rules | Create, edit, and delete global elevation rules. |
Manage Environment Elevation Rules | Create, edit, and delete environment-scoped elevation rules. |
Group Members
User membership within groups.
Permission | Description |
Manage Members | Add and remove users from groups. |
Add Members | Add users to a group. |
Remove Members | Remove users from a group. |
Groups
User groups and their membership rules.
Permission | Description |
View Groups | View group listings. |
Manage Groups | Create, edit, and delete groups. |
Add Group | Create new groups. |
Destroy Group | Delete groups. |
Edit Group | Edit group details and membership rules. |
Help Desk Verifications
Help desk identity verification settings.
Permission | Description |
Manage Help Desk Verifications | Configure and manage help desk identity verification settings. |
Licenses
Product license assignment.
Permission | Description |
Assign Licenses | Assign product licenses to tenants or users. |
Local Admin Accounts
Local administrator accounts on managed devices.
Permission | Description |
Manage Local Admin Accounts | Manage local admin accounts on managed devices. |
Login Keys
Login keys issued to users.
Permission | Description |
View Login Keys | View login keys issued to users. |
Manage Login Keys | Issue, activate, deactivate, and delete user login keys. |
Activate or Deactivate Login Key | Activate or deactivate a user login key. |
Delete Login Key | Delete a user login key. |
Issue Login Key | Issue a new login key to a user. |
Mobile
Capabilities available to technicians in the Evo mobile app.
Permission | Description |
Mobile Elevation Technician | Perform elevation actions from the mobile app. |
Mobile Help Desk Verification Technician | Perform help desk identity verifications from the mobile app. |
Notifications
Elevation and general notification configuration.
Permission | Description |
Manage Elevation Notifications | Configure global elevation notification settings. |
Manage Environment Elevation Notifications | Configure environment-scoped elevation notification settings. |
Manage Notification Configuration | Manage general notification configuration. |
Onboarding
Onboarding enrollments for bringing new users and devices into the portal.
Permission | Description |
View Onboarding | View onboarding and enrollment listings. |
Manage Onboarding | Create, edit, and delete onboarding enrollments. |
Create Enrollment | Create new onboarding enrollment records. |
Delete Enrollment | Delete onboarding enrollment records. |
Edit Enrollment | Edit onboarding enrollment settings. |
PSA Integrations
Professional Services Automation integrations.
Permission | Description |
Manage PSA Integrations | Configure and manage PSA integrations. |
Partner API
Partner API keys used to authenticate API access.
Permission | Description |
Manage Partner API | Manage Partner API keys and settings. |
Password Sync Integrations
Password synchronization integrations.
Permission | Description |
Manage Password Sync Integrations | Configure and manage password synchronization integrations. |
Policies
Security policies, including the global default policy and individual policies.
Permission | Description |
Manage Global Policy | Edit the global default policy. |
View Policies | View policy listings and configurations. |
Manage Policies | Create, edit, delete, enable, and disable policies. |
Create Policy | Create a new policy. |
Delete Policy | Delete a policy. |
Edit Policy | Edit an existing policy. |
Update Policy | Enable or disable a policy. |
RADIUS
RADIUS servers used for network authentication.
Permission | Description |
View RADIUS Servers | View RADIUS server listings. |
Manage RADIUS Servers | Add, edit, and remove RADIUS servers. |
Create RADIUS | Add a new RADIUS server. |
Delete RADIUS | Remove a RADIUS server. |
Edit RADIUS | Edit RADIUS server settings. |
RMM
RMM integrations and deployment settings.
Permission | Description |
Manage RMM Deployments | Manage RMM deployment settings. |
Manage RMM Integrations | Configure and manage RMM integrations. |
Role Management
Roles and permissions that define administrator access.
Permission | Description |
View Roles | View roles and permission group listings. |
Manage Roles | Create, edit, and delete roles. |
Create Role | Create new roles. |
Delete Role | Delete roles. |
Edit Role | Edit role names and permissions. |
Sessions
Active user sessions.
Permission | Description |
Manage Sessions | View and revoke active user sessions. |
Support Access
Evo support access to environments.
Permission | Description |
Manage Evo Support Access | Grant or revoke Evo support team access to environments. |
System Elevation
System-level elevation capabilities.
Permission | Description |
Use System Level Elevations | Use system-level elevation capabilities. |
Tenant Access
Tenant access settings.
Permission | Description |
Manage Tenant Access | Manage access settings for tenants. |
Users
User accounts, profiles, and lifecycle management.
Permission | Description |
Reset Security Questions | Reset a user's security questions. |
Send Password Reset | Display the Password Reset action on a user. Users can also request the same email from the sign-in page. |
Send Welcome Email | Send a welcome email to a user. |
View Users | View user listings and profile details. |
Manage Admin Status | Promote users to admins and demote admins to users. |
Convert Admin To User | Demote an admin account to a standard user. |
Convert User To Admin | Promote a standard user to an admin. |
Manage User | Create, disable, and delete users and manage user MFA and aliases. |
Create User | Create new user accounts. |
Delete User | Delete user accounts. |
Disable MFA | Disable MFA for a user. |
Disable User | Disable a user account. |
Manage User Aliases | Manage email aliases for a user account. |
Web Accounts
Web account credentials used for authentication.
Permission | Description |
Manage Web Accounts | Manage web account credentials. |
Use Web Accounts | Use web account credentials for authentication. |
