Your people, your vault and your security page in the client portal
Who has access to your portal, where your team's own private passwords and documents live, and what your security page shows.
Access legend
A tip explains that each person's access follows their role, and three badges define the tiers underneath it: View means read-only, Edit means create and modify, and Admin means full control.
Search
Search users looks up anyone already on this list by name or email.
The one portal user
Miguel Santos is the only person on this list today, marked with an Owner badge and Full Access on the right. Anyone else given a role here shows up as its own row, with that role's name in place of the badge.
Access by section
Opening a row expands a note plus a part-by-part breakdown. The Owner's note reads Account owner - full admin access on every section. Role is locked, and every part below it reads Admin except My Vault, which reads Personal, since My Vault access proves entry, not authority over someone else's items.
My Vault: the team's own private passwords and documents
Documents and Passwords
My Vault splits into two tabs: Documents holds the team's own notes and how-tos, and Passwords holds logins the team keeps for itself. Neither one is visible to the IT provider, even while looking at the portal as this organization.
Password Vault
The Passwords tab lists every entry, with an Import button for bringing in an existing export and a New Entry button for adding one by hand. KB walk - example is one such entry, created for this walk and left in place.
Private or Shared
Each entry carries a Private or Shared badge. This one reads Shared because it now has an active outside share link; an entry with no teammate linked, no everyone-can-see toggle on, and no outside link reads Private instead.
Opening an entry: who on the team can see it, and sharing it outside
Team visibility
Opening an entry shows Team visibility: a toggle for Visible to everyone in your organization, plus Visible to specific users with its own Add User button for naming one teammate at a time. Left off, as here, the entry stays visible only to whoever made it and anyone named.
Share links
New link opens a form for sharing outside the portal: how long the link works, an optional cap on how many times it can be opened, and an optional passphrase. The full link shows only once, right after it is created; afterward the list shows it as Active, how many times it has been opened, and a button to revoke it early.
Security: the current picture
Overview and History
Security splits into two tabs for most people: Overview for the current picture, and History for handled threats.
Monitoring status and recent activity
Until the first Microsoft 365 data arrives, Overview reads Monitoring hasn't started yet in both the top banner and the Recent security activity card, and says plainly that this is expected for a new connection and does not mean anything is wrong.
History: every threat handled, newest first
Threats handled
History lists every threat handled for the organization, newest first, with its severity, the alert, the linked ticket, and when it was detected. It reads No handled threats on record yet until the first one is resolved.
Why it works this way
A User, Billing, IT Admin, or Primary Contact role can each be given here once that person already appears in the company's Microsoft 365 or Google Workspace directory. Opening their row shows a Role dropdown instead of the Owner's locked note: User sees only their own tickets and reads most other pages, Billing sees every invoice plus read access to devices, licenses, documentation, and meetings, IT Admin works tickets in full and can edit devices, licenses, and documentation, and Primary Contact can do almost all of it, including adding users and changing settings. This organization's directory carries one such person today, so only the Owner's row shows live.
The Security tabs shown here are the ones most people get. If the client's own team runs IT together with the provider, Overview grows to add the full event list and the organization's protection settings, and History is replaced by Response Rules: the set responses that run for the organization on their own.
Questions this page answers
How do I manage portal users?
Owners, the Primary Contact and IT Admins can open Users. The list shows who can sign in and what role each person holds. You can give someone access there, and you can change their role. Your IT provider can also set this from their side.
What are the portal access roles?
Each person gets one role. A User sees only their own tickets. They can read most other pages. Billing can see every invoice. They can also read devices, licenses, docs, and meetings. They cannot change settings or users. An IT Admin works tickets in full. They can also edit devices, licenses, and docs. A Primary Contact can do almost all of it. That includes adding users and changing settings. The Owner has a badge by their name. The Owner always has full access.
How do I give someone portal access?
You need the Primary Contact, IT Admin or Owner role. Go to Users and find the person by name or email. They must already have a Microsoft 365 or Google Workspace account at your company. Open their row and pick a role. The role sets what they can reach. There are no separate switches per section.
How do per-section permissions work?
A role sets them. You do not set them one by one. Expand a row to see what that role gives for each part of the portal. Each part reads View, Edit, Admin or No access. To change what someone can do, change their role. The access then shifts to match. The Owner always has Admin on every part.
What is My Vault, and who can see it?
My Vault is your own private space. It has a Documents part for your notes and how-tos. It has a Passwords part for logins your team keeps for itself. Your IT provider never sees any of it. Not in their tools. Not even when they view the portal as your company. Only your own people can see it, and only what they were given.
How do I say who on my team sees an entry?
Open the entry. Owners, the Primary contact and IT Admins get a visibility panel. Turn on visible to everyone to let the whole company read it. Or leave it off and add teammates by name. Whoever makes an entry can always see it. People with the User or Billing role see only what is shared with them.
Can I bring in my passwords from another vault?
Yes. Open "Passwords" in My Vault and press "Import". There are two ways in. If you are typing the list yourself, press "Download CSV template", fill it in, then pick it. If you already have an export from another password vault, pick that file. Use "Choose a file" either way, for a .csv or a .json. Your file is read in your browser. It never leaves your computer. If we know the export, we say so, and the columns are matched for you. If not, "Match your columns" lets you set each one yourself. Next you see every row and what will happen to it. A row with no name, no password, or a bad web address is left out. So is a row you already have. Nothing is saved until you press the import button. Your IT provider never sees any of it.
What do the tabs on this page show?
What you see depends on your access. Most people get two tabs. Overview is your security picture right now. It holds your Microsoft 365 secure score, sign-in checks, threats handled this month, and things to improve. History lists every threat handled for your company, newest first. If your own team runs IT with us, Overview is fuller: it adds the whole event list and your protection settings. In place of History you get Response Rules. Those are the set responses that run for your company on their own.
Was this helpful?