> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage administrator access

> Invite administrators, assign them a role, and revoke their access from Settings > Security & Access.

Administrators sign in to the cockpit. Each one has a role that scopes what they can see and change. Manage administrators and roles from **Settings** > **Security & Access**.

## Invite an administrator

<Steps>
  <Step title="Go to Settings > Security & Access and click Invite new admin" />

  <Step title="Choose who to invite">
    * **Invite an employee**: select an employee from your directory.
    * **Invite someone outside your company**: enter their email address.
  </Step>

  <Step title="Select a role" />

  <Step title="Click Confirm or Send invite">
    An employee gets access right away. Someone outside your company receives an invitation by email, and their row shows **Invitation sent** until they accept.
  </Step>
</Steps>

<Info>
  You can also promote an employee from their profile: open it, click **Actions**, then **Promote to admin**.
</Info>

## Change or revoke access

In the **Administrators** list, open the actions menu on an administrator's row:

* **Edit role** to give them another role.
* **Revoke access** to remove their administrator rights. They keep their employee profile. You can't revoke your own access.
* **Resend invite** or **Revoke invitation** for a pending invitation.

## Roles

Primo provides built-in roles that scope each administrator's access:

| Role | Access |
| - | - |
| **Admin** | Full access to all settings, billing, and user management |
| **HR Manager** | Employee management, onboarding and offboarding, and HR system sync |
| **MDM Manager** | Device management, MDM settings, controls, and enrollment |
| **SaaS Manager** | SaaS connections, provisioning rules, identities, and licences |

### Create a custom role

<Steps>
  <Step title="Go to Settings > Security & Access" />

  <Step title="Click Create role in the Roles section" />

  <Step title="Name the role and select its permissions">
    Permissions are grouped by area: Cockpit, Employees, Devices, MDM, Purchasing, SaaS, Tickets, AI agent, Company, Billing, HR sync, Security, Users, and API.
  </Step>

  <Step title="Save">
    The role is now available when you invite an administrator or edit their role.
  </Step>
</Steps>

To edit or delete a custom role, click it in the **Roles** section.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.