Identity, Roles & Access
FlowPSA and FlowRMM use the same Microsoft Entra tenant but separate app registrations. FlowPSA owns its roles, queues, and audit history. FlowRMM owns endpoint permissions and execution. Being an admin in FlowRMM does not make someone an admin in FlowPSA.
At Acme MSP, alex@acme-msp.example is an Operator on the Service desk and Networking queues, while a second person on the Billing role posts Acme Corp invoices.
Sign-in
FlowPSA signs staff in through Azure Container Apps authentication with your tenant-specific issuer and an exact HTTPS callback. Unknown roles, other tenants, and unassigned users are denied.
Roles
| Role | Can |
|---|---|
| Admin | Manage policy, queues, and settings; reopen timesheets; everything an operator and billing user can do |
| Operator | Work tickets in permitted queues, log time, approve resolutions and change requests from other people |
| Billing | Manage agreements, approve timesheets, create and post invoices |
| Viewer | Read only |
| Agent | MCP access for AI agents; never decides approvals |
Roles come from Entra security groups. Multiple roles combine.
Queues and groups
Admins create queues and choose the Entra groups that work each one. Group IDs are the authority; names are only labels. Queue membership controls who can work and be dispatched from a queue. All licensed staff can still search every ticket, so queues are not confidential customer boundaries. If group claims are missing, restricted work fails closed.
The second-person rule
For approvals that need a second person, FlowPSA keeps the requester's immutable Entra object ID on the approval. Changing a display name cannot satisfy the rule.
Separate paths
- Staff in the browser use their Microsoft session.
- Integrations and MCP use bearer tokens on a separate path that ignores Microsoft identity headers.
- Client portal users use their own signed links. See Client Portal.
Checking your setup
Open Settings and select Sign-in & Access to see your verified tenant, role, and queues, plus a checklist covering identity, role assignments, queue routing, and the FlowRMM connection.
Related guides
Want hands-on help? Book a demo or get in touch.