Back to Use Cases
Admin Suite

User Roles

Roles, permissions & access

Used byOperations

Control who can do what, everywhere — with roles, SSO, and automated provisioning.

User Roles is the Admin Suite control center for your workspace: manage members, define custom roles with granular per-module permissions, organize teams, and enforce access policies. It solves the problems of over-provisioned accounts, manual onboarding, and inconsistent security by combining RBAC, SSO/OIDC, SCIM provisioning, and workspace-wide MFA and domain rules in one place.

4 use cases

Documented use cases

01

Onboard an Agent in Minutes with the Right Role and Team

Support or Operations Manager
Problem

New agents often wait days for access while a manager files a ticket and an admin manually toggles permissions across tools. In the meantime, people either sit idle or get handed an over-permissioned account that was copied from a colleague, creating security debt no one ever cleans up.

How BOL7 solves it

From the Users tab, send an invite and attach a preset role plus the right team in a single step. The role carries its scoped permissions automatically, and Workspace Settings default roles and MFA enforcement apply the moment the agent accepts.

Outcome

New hires start with exactly the access their job requires on day one, and managers stop relying on risky copy-a-colleague shortcuts.

onboardingRBACteams
02

Build a Scoped Sales Manager Role Without Over-Granting Access

Sales Operations Lead / Workspace Admin
Problem

Generic built-in roles rarely fit how a sales team actually works, so admins default to handing managers broad admin rights just to unblock them. That over-granting exposes billing, settings, and other teams' data, and it surfaces as a finding the next time auditors review who can touch what.

How BOL7 solves it

In the Roles tab, create a custom Sales Manager role and use the granular per-module permission checkboxes to grant only what the role needs. Pair it with Policies for fine-grained resource/action/effect rules and conditions when you need allow or deny logic beyond a simple checkbox.

Outcome

Managers get full reach over their own domain while everything else stays locked down, making least-privilege the default instead of the exception.

custom-rolesleast-privilegepolicies
03

Migrate or Scale Your Team with a Single CSV Import

IT Admin / People Operations
Problem

Standing up a new department or migrating from another tool means creating dozens of accounts by hand, one at a time. The process is slow and error-prone — typos in emails, wrong roles, and missed users that only get noticed when someone complains they can't log in.

How BOL7 solves it

Use the bulk CSV import on the Users tab to create many members at once, each mapped to a role and status. Default roles and corporate-domain requirements from Workspace Settings are applied on import, so every account lands consistent and compliant.

Outcome

Whole teams come online in one pass instead of one ticket at a time, with far fewer manual mistakes to chase down afterward.

bulk-importprovisioningmigration
04

Enforce Azure AD SSO with Company-Wide MFA

Security / IT Administrator
Problem

When access depends on standalone passwords, offboarded employees can linger with live accounts and there's no single switch to require strong authentication. Each separate login is another credential to phish and another gap an auditor will flag.

How BOL7 solves it

Configure SSO & OIDC with your Azure AD issuer and metadata discovery, then enforce SSO so every sign-in routes through your identity provider. Turn on MFA enforcement and the corporate-domain requirement in Workspace Settings, and add SCIM 2.0 provisioning so joiners and leavers sync automatically.

Outcome

Authentication is centralized and consistent, deprovisioning happens through your identity provider, and MFA is mandatory rather than optional.

SSOAzure ADMFASCIM