Skip to main content
Administrators sign in to the cockpit. Each one has a role that scopes what they can see and change. Manage administrators and roles from Settings > Security & Access.

Invite an administrator

1

Go to Settings > Security & Access and click Invite new admin

2

Choose who to invite

  • Invite an employee: select an employee from your directory.
  • Invite someone outside your company: enter their email address.
3

Select a role

4

Click Confirm or Send invite

An employee gets access right away. Someone outside your company receives an invitation by email, and their row shows Invitation sent until they accept.
You can also promote an employee from their profile: open it, click Actions, then Promote to admin.

Change or revoke access

In the Administrators list, open the actions menu on an administrator’s row:
  • Edit role to give them another role.
  • Revoke access to remove their administrator rights. They keep their employee profile. You can’t revoke your own access.
  • Resend invite or Revoke invitation for a pending invitation.

Roles

Primo provides built-in roles that scope each administrator’s access:

Create a custom role

1

Go to Settings > Security & Access

2

Click Create role in the Roles section

3

Name the role and select its permissions

Permissions are grouped by area: Cockpit, Employees, Devices, MDM, Purchasing, SaaS, Tickets, AI agent, Company, Billing, HR sync, Security, Users, and API.
4

Save

The role is now available when you invite an administrator or edit their role.
To edit or delete a custom role, click it in the Roles section.