Skip to content

Operator Guides

Identity, Roles & Access

FlowPSA and FlowRMM use the same Microsoft Entra tenant but separate app registrations. FlowPSA owns its roles, queues, and audit history. FlowRMM owns endpoint permissions and execution. Being an admin in FlowRMM does not make someone an admin in FlowPSA.

At Acme MSP, alex@acme-msp.example is an Operator on the Service desk and Networking queues, while a second person on the Billing role posts Acme Corp invoices.

Sign-in

FlowPSA signs staff in through Azure Container Apps authentication with your tenant-specific issuer and an exact HTTPS callback. Unknown roles, other tenants, and unassigned users are denied.

Roles

Role Can
Admin Manage policy, queues, and settings; reopen timesheets; everything an operator and billing user can do
Operator Work tickets in permitted queues, log time, approve resolutions and change requests from other people
Billing Manage agreements, approve timesheets, create and post invoices
Viewer Read only
Agent MCP access for AI agents; never decides approvals

Roles come from Entra security groups. Multiple roles combine.

Queues and groups

Admins create queues and choose the Entra groups that work each one. Group IDs are the authority; names are only labels. Queue membership controls who can work and be dispatched from a queue. All licensed staff can still search every ticket, so queues are not confidential customer boundaries. If group claims are missing, restricted work fails closed.

The second-person rule

For approvals that need a second person, FlowPSA keeps the requester's immutable Entra object ID on the approval. Changing a display name cannot satisfy the rule.

Separate paths

  • Staff in the browser use their Microsoft session.
  • Integrations and MCP use bearer tokens on a separate path that ignores Microsoft identity headers.
  • Client portal users use their own signed links. See Client Portal.

Checking your setup

Open Settings and select Sign-in & Access to see your verified tenant, role, and queues, plus a checklist covering identity, role assignments, queue routing, and the FlowRMM connection.

Related guides

Want hands-on help? Book a demo or get in touch.