Topic
This article explains how to assign permissions to end users and technicians through roles.
If you would like to learn more about assigning permissions individually, rather than through a role, refer to the Managing Permissions section of NinjaOne User Management: Resource Catalog
Before you get started with this article, you should have already created a technician or end user account in NinjaOne. If you have not yet done so, refer to the Getting Started section of NinjaOne User Management: Resource Catalog.
Environment
NinjaOne Platform
Description
NinjaOne allows system administrators to create numerous permission templates, referred to as roles, that you can assign to both new and existing NinjaOne technicians or end users. You can use roles for a variety of use cases, including customer access, apprentices, audits, and third-party collaboration. These permissions determine their level of access to different features and functionality within NinjaOne.
Index
Select a topic to learn more:
Create a Technician or End User Role
Using a template is the easiest way to set up a new role. Templates are completely customizable, regardless of which one you select.
- Blank Template: This template has no predefined permissions.
- Full Permissions Template: This template includes all predefined highest-level permissions.
To create a new role from a template, perform the following steps:
- To get started, navigate to Administration → Accounts and open the Technician roles or End users roles tab.
- Click Create Role and select either Blank Template or Full Permissions Template from the drop-down menu.

Creating a Blank Template
Select the Blank Template option from the Create role drop-down menu to customize each permission. Then, use the following instructions to configure it.
- The General section will be open by default. Provide a unique identifier in the Name field. Optionally, provide a summary of the role's purpose in the Description field.
If there are existing accounts in NinjaOne that you want to add to this role, open the Members section and click Add Members. In the resulting dialog, select the checkboxes next to the end users you want to add to this role, and then click Add Selected Members.
If you add a user to multiple roles, their permissions will default to the highest level of access amongst the assigned roles. For example, if a user is a member of a role that does not have remote access permissions and is also a member of a role that does, NinjaOne will use the higher-permission role that grants access. The user will have remote access permissions.

- In Permissions, click through each section to enable specific permissions.
Managing Roles
After you have created a role, select the checkbox next to the role name to review the following management options:
- Edit Selected Role: Open the role configuration page to update permissions or members.
- Copy Selected Role: Create a new role that copies the permissions from the selected role.
- Delete Selected Roles: Remove the role from use.

Assign a Role via the Account Configuration Page
When creating or editing roles, you can add an end user or technician from the Members section. You can also add one or more roles when you are creating or editing a technician or end user account.
To assign a role from the account configuration page, perform the following steps:
- Open the account configuration page for either a technician or end user.
- Open the Roles section and click Add Role.
- In the resulting dialog, select one or more roles by selecting the checkbox next to the role name, and then click Add Selected Role.

Figure 4: Assign a role from the account configuration page (click to enlarge)
Remove a Member From a Role
After you add members to a role, you can remove them from either the role or the individual account configuration page.
To remove a member from the role configuration page:
- Open the Members section.
- Select the checkbox next to the name of one or more members.
- Click Remove Selected Member(s).
- Click Confirm in the resulting dialog.
- Click Save Changes.

Figure 5: Remove members from a role
To remove a role from the account configuration page:
- Open the Roles section.
- Select the checkbox next to the name of one or more roles.
- Click Remove Selected Role.
- Click Save Changes.

Figure 6: Remove roles from an account
Example Permissions
The following examples show common ways to manage user permissions for IT departments so you can limit access to only the functionality that your various IT departments need.
Configure Separate Permissions for Different Technician Levels
Set these permissions from the role configuration page in the Devices section. If you want to control access to specific device types, you must select "No Access" for Create New Devices and Default Access, and then select the necessary access level from the device type drop-down menu.

Figure 7: Set permissions for specific device types
The following list provides an example of how you can set permissions for different technician levels:
- Role "Level 1" has access to workstations.
- Role "Level 2" has access to servers.
- Role "Level 3" has access to network devices.
Configure Permissions for Users Who Need Ticketing or Reporting Information Only
Enable the Ticketing section and select the options from one or more drop-down menus. Enable the System section and select an option from the Manage Reports drop-down menu.
Business Unit Permissions: Limit Access by Department
Enable the Organizations section and select an option for Default Access to control permissions to all organizations.
If you want to permit access to only specific organizations, select No Access from the Create New Organizations and Default Access drop-down menus. Then, select the checkboxes next to the organizations and click Edit Permissions.

Figure 8: Set permissions for specific organizations
Additional Resources
Refer to the following resources to learn more about user management:
- Allow a technician to edit custom fields: Global Custom Fields
- User Management: Resource Catalog