Security Permissions Reference
Table of Contents
Various areas of Syncro are controlled by what users have permissions for; this includes what they can see and what actions they can perform. Permissions are defined for users as part of their belonging in a security group.
Security Groups are available under Admin > Syncro Administration - Security Groups. Whenever you click +New Group or Edit on an existing group, Syncro presents you with a list of security permissions.
This document describes what each security permission does.
Appointments
- View All (See-Own Never Restricted): When checked, users have access to all calendars. (If unchecked, they will only see their own calendar.)
Chat
- Module Enabled: When checked, users can see and access the Chats tab/module.
- Pick Up Unassigned Chats: When checked, users can select/work any unassigned chats.
- Reassign: When checked, users can reassign any chat that's already assigned to another Tech. (This may be a Tech that works dispatch, or an Admin, for example.)
- Show All Chats: When checked, users can view all chats in the Syncro account.
- Start New: When checked, users can start a chat with a Customer/Contact.
- Take Over Assigned Chats: When checked, users can reassign a chat to themselves. (This can be useful if a Tech is out of the office or if an issue needs to be escalated.)
Chat History
- Mine Only: When checked, users can view chat history only for chats they were originally assigned.
- View All: When checked, users can view all chat history in the Syncro account.
Credentials
- Delete: When checked, users can delete Customer/Contact credentials.
- Edit: When checked, users can edit/update Customer/Contact credentials.
- New: When checked, users can add Customer/Contact credentials.
- View: When checked, users can see all Customer/Contact credentials.
Customers
- Archive: When checked, users can archive a Customer.
- Create: When checked, users can create a new Customer.
- Delete: When checked, users can delete a Customer.
- Disable Scripting: When checked, users can disable all scripting on Assets associated with the Customer.
- Edit: When checked, users can edit the Customer profile.
- Edit Block Hours: When checked, users can edit block/prepay hours.
- List/Search: When checked, users can see a list of all Customers in the Syncro account.
- Manually Run Scripts When Disabled: When checked, users can override and run scripts against Customer assets when “Disable Scripting” is enabled.
- Merge Customer: When checked, users can merge Customers.
- Remote Access Enable: When checked, users can turn on remote access for Customers/Contacts. (This comes with a charge.)
- View Detail: When checked, users can view the Customer's Details page.
- View Total Invoiced: When checked, users can view the total Invoice amounts due for Customers.
Customer Purchase
- Add Manual Product: When checked, users can add a manually created inventory item to a purchase.
- Create: When checked, allows user to create a Customer Purchase order
- Override Retail: when checked, allows user to override the default retail price of an serialized item received by a Customer Purchase
- Undo Payment: when checked, allows user to undo payment on a Customer Purchase
Parts Orders
- List/Search: When checked, allows access to the Parts module overview page and to view and search the list of part orders.
- View: When checked, allows user to view individual part orders.
Pending Orders
- View All: When checked, allows user access to the pending orders page, in the Products and Services module.
POS
Allow Usage:: When checked, allows user access to the POS Module.
Purchase Orders
- Delete: When checked, allows user to delete a Purchase Order.
- Edit: When checked, allows user to edit an existing Purchase Order.
- List/Search: When checked, allows user to access the Purchase Order overview page, in the Products and Services module and to view and search the list of Purchase Orders.
- View Details: When checked, allows user to access individual purchase order details.
Registers
- Delete Adjustments: When checked, allows user to delete adjustments.
- List Adjustments: When checked, allows user to view the registers list of drawer adjustments.
- New Adjustment: When checked, allows user to create a new drawer adjustment for a Register.
- Open/Close: When checked, allows user to open and close the register.
Stock Takes
- Access: When checked, allows users to access the Stock Take feature for inventory tracking and reconciliation.
- Allow Manual Entry: When checked, allows users to manually adjust stock quantities during stock take.
- Lists: When checked, permits viewing a list of stock takes.
- Reconcile: When checked, allows users to reconcile discrepancies identified during stock takes.
Documentation
- Allow Usage: When checked, grants permission to view and use existing documentation.
- Create: When checked, allows users to add new documentation.
- Delete: When checked, allows user to delete documentation.
- Edit: When checked, permits editing of existing documentation.
Google Cloud Printers
- Edit: When checked, allows configuration or management of Google Cloud Printer settings.
Invoices
- Change Assignee: When checked, allows changing the assigned contact for the invoice.
- Create: When checked, allows user to create new invoices.
- Delete: When checked, allows user to delete invoices.
- Edit: When checked, allows user to modify existing invoices.
- List/Search: When checked, enables searching and listing of invoices
- Refund: When checked, allows user to process refunds linked to invoices
- View Details: When checked, provides user access to view invoice details
Contracts
- Delete: When checked, permits deletion of contracts.
- Edit: When checked, permits modifications to existing contracts.
- List/Search: When checked, allows users to search and view a list of contracts.
Estimates
- Create: When checked, grants permission to create new estimates.
- Delete: When checked, allows deletion of estimates.
- Edit: When checked, permits editing of existing estimates.
- List/Search: When checked, enables listing and searching of estimates.
- View Details: When checked, allows viewing detailed information about estimates.
Payments
- Clear (Unapply): When checked, allows user to remove payments from invoices.
- Create: When checked, enables creation of new payment.
- Delete: When checked, allows deletion of payment records.
- Edit: When checked, allows modifications to existing payment records.
- Refund: When checked, grants permission to process refunds.
- Verify: When checked, allows verification of payments.
- View List: When checked, enables viewing a list of payments.
- Void: When checked, permits voiding of payments.
Recurring Invoices
- Delete: When checked, allows deletion of recurring invoices.
- Edit: When checked, allows editing of recurring invoice templates.
- List: When checked, enables viewing a list of recurring invoices.
- New: When checked, grants permission to create new recurring invoices.
(Mailboxes & Mailings)
Leads
- Delete: When checked, allows deletion of leads.
- List/Search: When checked, permits viewing and searching for leads.
Marketr
- Edit Campaigns: When checked, allows editing campaigns in the Mailer Module
- View Campaigns: When checked, allows viewing campaigns in the Mailer Module
Snail Mail
- Send ($): When checked, allows sending snail mail with associated costs.
SNMP
- Generate OID Recipe Links: When checked, allows generation of Public OID recipe links.
- Import Public OID Recipe Links: When checked, enables importing OID Recipes using a public link
Products
- Create: When checked, allows creation of new products and services.
- Edit: When checked, allows modifications to existing product and services.
- Edit Quantities: When checked, permits adjustments to product inventory quantities (Non-Serial Only).
- List/Search: When checked, enables viewing and searching of the Products and Service Module
- Manage Upsell Opportunity Items: When checked, allows management of upsell-related items
- View Cost: When checked, grants permission to view cost details of products
Line Item
- Add Manual Item for Invoices/Estimates: When checked, allows adding manual line items to invoices or estimates.
- Apply Discount: When checked, permits applying discounts to line items.
- Edit Prices: When checked, enables price adjustments on line items.
- View Cost: When checked, allows viewing the cost details of line items.
Logistics
- Delete (Big Chains): When checked, enables deletion of logistics records for large chains.
- List/Search (Big Chains): When checked, allows listing and searching logistics records for big chains.
- View/Modify (Big Chains): When checked, permits viewing and modifying logistics details for big chains.
Warranties
- List: When checked, enables viewing a list of warranties.
- View Details: When checked, grants access to detailed warranty information.
Vendors
- Delete: When checked, allows deletion of a vendor.
- Edit: When checked, permits modifications to existing vendor information.
- List: When checked, enables viewing a list of vendors from the Product and Services Module.
- New: When checked, allows creation of a new vendor
- View Details: When checked, allows access to detailed vendor information.
RMM
Alerts
- Clear/Manage: If enabled, the partner is given access to manage and clear the alerts. As a note - clearing alerts will allow for the alert to fire again as necessary but will retain that original record for historical tracking.
- Create: Granting this permission gives users the ability to generate RMM alerts that were specified from a script executed from your script library.
- Delete: This adds the the user with the ability to delete RMM alert records. Please note - when an alert is deleted and that same alert triggers again, that alert will then generate as a new record and will no longer be associated with the original record.
- List: This permission provides authorization of viewing the entire open and muted alerts list from the RMM Alerts module.
Assets
- Allow Backgrounding Tools: Provides technicians with the ability to utilize the background feature across assets. This feature provides remote-in and silent functionality across all endpoints.
- Allow Installation of Rejected Patches: This permission allows technicians to manually install rejected patches in the windows patches tab of the assets details. These rejects are specified in the windows update policies that are assigned to the endpoint. This requires the permission Install Windows Patches Manually to work properly.
- Allow Remote Access: When checked, technicians can click the Remote Access button on assets to initiate a remote session with our built-in Splashtop feature. However, the steamer will only initiate properly if enabled at the assets assigned policy.
- Assets Pending Approval: Enabling this will provide users the permission needed to approve assets during their first checkin after the installation of our monitoring agent. For global admins the Asset Approval setting for the account is managed in the RMM Preferences of the admin tab.
- Broadcast Message: Enabling broadcast messaging provides users the ability to prompt a pop-up message directly on end-users devices. This function is performed from the asset detail page or bulk queued across a number of endpoints from the actions option in asset module.
- Bulk Script Execute: Checking this, provides the user with permissions of bulk action execute scripts across the assets specified in a asset saved search or from the primary page of the asset module. For this permission to work properly it does require asset list and script execution permissions enabled.
- Create: This permissions provides users with access to create manual assets.
- Delete: Enabling Delete will give users the ability to delete records of manually created assets as well as Syncro managed endpoints.
- Edit: This grants access to edit details of assets which include assigned customer instance, friendly name, custom fields, ect.,.
- Edit Policy ($): Enabling this will only allow edits to the policy tree at the customer folder level. For the full list of policy permissions you will need to refer to the permissions table labeled Policy further down in this security group.
- Install Windows Patches Manually: When checked, this will grant permission to manually queue and execute updates from assets windows patches tab. Note: If this security group provides permissions for the following reports, Vulnerable Systems and Missing Patches by KB they will also be able to bulk queue installs from those tables.
- List/Search: This provides access to view the asset list in its entirety as well as allowing isolated searches for specific assets.
- Reboot: The Reboot permissions will allow users to queue a forceful reboot on Syncro managed endpoints.
- View Details: This permissions gives the user access to view the detail pages of each individual asset.
- View Thumbnail: Enabling the Thumbnail permissions gives the user permission to see a snapshop image of the endpoints desktop within the asset detail page. This image updates every 1-5 minutes. As a note for this to work properly a global admin will need to ensure the Thumbnail image setting is not disabled in the RMM preferences of the admin tab.
- Wake On Lan: Allows the user from the asset details page to wake up assets that are asleep or powered off entirely through Wake On Lan.
Policies
- Delete: This permission provides the user the ability to delete policies. To be able to use this permissions the policy permissions List will also need to be enabled.
- Edit ($): Granting this will give the user access to edit policies in the policy settings page.
- Edit Attended/Unattended: This allows the user to edit the Syncro Remote Access setting Require Client Permission For Remote Access in policies. Note: If this user is assigned to only Edit ($) policies this will be the only setting they are unable to make changes to unless this to is enabled.
- List:Enabled this will provide the user access to the entire policy list from the policy module.
- New: This gives the permission to create and configure new policies.
Reports
- View (Toggle Granular Reports List): Toggling this permissions will open a list of all available reports. You will check each box to the report you would like to provide that user access to. Note: A global admin will need to ensure to enable the reports module from tabs customization in order for a non-global admin to navigate to the reports page since they do not have access to the admin tab.
Scripts
- Delete: Granting the Delete permission will give the user access to delete a script record. In to be able to use this function the List permission for scripts will also need to be enabled.
- Edit: Enabling Edit will allow the user to make changes to scripts
- Execute: Checking this grants the user permission to execute scripts from the library across your asset fleet.
- Favorite: This will give access to marking scripts to favorite which sorts those scripts at the top of searches for quick selection on commonly used scripts.
- List: Enabling List will provide the user access to the scripting module where they can view all the available scripts in your library.
- New: When enabled this will grant the user permissions to create and add new scripts to your library.
API Tokens
- Manage: This will give the user access to generate API tokens that would be used for third party apps or to GET or PUT information through the API. This should really only be enabled for power users with nearly all available permissions enabled.
Script Categories
- Delete: This will grant the user with permissions to delete existing script categories from your library in the scripting module.
- Edit: Enabling Edit will provide the ability to edit existing script categories.
- List: This will give the user access to view the entire list of categories which is used for quick searches and easy sorting.
- New: When checked, this gives the user the ability to add new script categories from the script module.
Tags
Contact Tags
Customer Tags
Ticket Tags
Tickets
- Create: When checked, users can create new tickets.
- Delete: When checked, users can delete existing tickets.
- Edit: When checked, users can edit existing ticket content, change ticket status, assign users, split tickets, add line items, and perform other ticket modifications.
- List/Search: When checked, users can view the tickets page and look for tickets in the search bar
- Merge: When checked, users can merge two tickets into one.
- Use Ticket Charges: When checked, users can view and add new ticket charges.
- View ‘Their Ticket’ Details (Assigned to Them): When checked, users can only view the content of tickets assigned to them.
- View Details: When checked, users can view the content of any ticket, including status, assignee, comments, and other information contained in the ticket.
Automated Remediation
- Create: When checked, allows users to create new automated remediation rules.
- Delete: When checked, grants permission to delete existing automated remediation rules.
- Edit: Enabling this gives permission to make changes to existing automated remediations.
- List: When checked, allows users to view and search the list of automated remediations.
Recurring Tickets
- Create: When checked, allows users to create new recurring ticket schedules.
- Delete: When checked, grants permission to delete recurring ticket schedules.
- Edit: When checked, allows users to modify existing recurring ticket schedules.
- List: When checked, allows users to view and search the list of recurring tickets.
Ticket Attachments
- View: When checked, allows users to view files and attachments associated with tickets.
Ticket Canned Responses
- Manage: Check this box to display the “Modify” button for techs in the Insert Canned Response pop-up window. This allows them to view and modify your list of Canned Responses.
Ticket Comments
Note: Ticket comments are also referred to as ticket communications.
- Delete: When checked, users can delete any comment on a ticket.
- Delete ‘Their Comments’ (They Created): When checked, users can delete any comments they created on a ticket.
- New: When checked, users can write comments and edit their comments on a ticket.
Ticket Custom Fields
- Manage: When checked, users can create, modify, and delete custom fields on tickets.
Ticket Parent-Child
- Edit: When checked, users can create parent-child associations between tickets and unlink existing associations.
Ticket SLA
Ticket Timers
- Add For Another Technician: When checked, users can input a ticket timer entry on behalf of another technician.
- Overview: When checked, users can view ticket timers and start, update, delete, and charge for a ticket timer entry.
- Toggle Time Entry Billable State: When checked, users have the option to charge customers for ticket timer entries.
Ticket Views
With the appropriate security permissions, you can control which Ticket Views are displayed (and specify the order they're shown) in the Tickets Views dropdown menu, and even restrict your Team's ability to create new Ticket Views.
- Create: Allows a User to create new Ticket Views.
- Edit: Allows a User to Edit existing “Public” Ticket Views and their own “Private” Ticket Views.
- Delete: Allows a User to Delete existing “Public” Ticket Views and their own “Private” Ticket Views.
- Manage Team Views: (Available on the Syncro Team Plan only.)
Allows a User to manage the “Ticket Views” of other Users in the account, including for those who don't have Create permissions. For example, a best practice for MSPs who have technicians who work on specific types of Tickets is to not give those technicians Create, Edit, or Delete Ticket View permissions and then set up a Ticket View to isolate the tickets they should work on, make that view the default, and possibly make it the only view available.
Users with this permission setting can also control Pinned Views and the Sort Order.
- My Sort: Allows a User to change the sort order of their “Ticket Views” dropdown menu.
- Pin: Allows a User to choose if a Ticket View is displayed in their "Ticket Views" dropdown menu.
Ticket Workflows
- Manage: When checked, users can create, modify, and delete ticket workflows.
Ticket Worksheets
- Add: When checked, allows users to add new worksheets to tickets.
- Add Ad-Hoc: When checked, enables users to create and attach ad-hoc worksheets directly to tickets.
- Delete: When checked, grants permission to delete worksheets from tickets.
- Edit Ad-Hoc: When checked, allows users to modify ad-hoc worksheets attached to tickets.
- Manage: When checked, enables users to manage all aspects of ticket worksheets, including configuration and assignment.
Timelogs
- Manage: When checked, users can create, modify, and delete Timelogs.