Navigation

10.17. Configure Roles, Permissions (RBAC), and API Keys for Your MSP

Manage roles, API keys, tenant secrets, accounting permissions, password vault audit access, and single sign-on in AlgaPSA.

10.17. Configure Roles, Permissions (RBAC), and API Keys for Your MSP
Manage roles, API keys, tenant secrets, accounting permissions, password vault audit access, and single sign-on in AlgaPSA.
10. SettingsUpdated: 10/8/2026

Navigate to Settings > Security. This section is for administrators to manage security configurations within AlgaPSA.

  • Roles: Define and manage roles (e.g., "Manager," "Admin," "Finance," "Technician," "Dispatcher," "Project Manager"). Each role has a description and specifies if it's for MSP or Client Portal users. You can add new roles or delete existing ones. To rename or update the description of a custom role, open the three-dots menu on the role row and select Edit. Built-in role names — such as Admin, Technician, and Finance — are locked and cannot be renamed, though their descriptions can be updated freely.
  • Permissions: Configure specific access permissions for different roles and resources (e.g., read, create, update, delete actions for Assets, Contacts, Documents, Time Entry, Tickets, Users, etc.). You can select a role to view or modify its permissions.
  • User Roles: Assign roles to MSP users and Client Portal users. Search for users and assign available roles (e.g., "Admin," "Finance," "Technician"). You can also remove assigned roles.
  • API Keys: This tab within Security Settings provides a centralized view of all API keys generated in the system.

Manage tenant secrets

Use Settings > Secrets to maintain tenant secrets used by workflows, such as a service API key. This gives the MSP a named secret to rotate without putting its value in routine workflow notes.

Figure 1: Tenant secrets are named, encrypted values that workflows reference without exposing the value.

  1. Select Create Secret and enter Name, Value, and an optional Description. Names use uppercase letters, numbers, and underscores, for example BACKUP_SERVICE_API_KEY.
  2. Select Create Secret to save it. The list shows its name, description, and update information.
  3. Use Edit secret to rotate the value or update its description, then select Update Secret. Leaving the value empty retains the current value.
  4. Use Delete secret to remove an obsolete secret. Review any workflow-usage warning and type its name to confirm deletion.

Creating, editing, and deleting tenant secrets writes an audit trail. Check the workflow that consumes a secret after rotation, and update dependencies before deleting it. The permissions are secrets:view for viewing the list and secrets:manage for creating, updating, and deleting entries.

Assign accounting integration permissions

Use the Accounting Integrations permission group to separate routine accounting work from connection administration and changes in the remote accounting system. The Admin and Finance defaults differ by capability:

PermissionWhat it allowsDefault MSP roles
accounting_integrations:catalog_readRead remote catalogs and integration status, including accounts, items, tax codes, terms, and connections.Admin, Finance
accounting_integrations:connections_manageSave OAuth credentials, connect or disconnect providers, and choose the default company.Admin
accounting_integrations:mappings_manageCreate, update, retarget, and reconcile accounting mappings.Admin, Finance
accounting_integrations:exports_executeCreate and execute exports and sync cycles.Admin, Finance
accounting_integrations:remote_mutatePerform destructive or money-moving operations in the connected accounting system.Admin

Review these permissions before delegating an integration to billing staff. For setup and operational checks, see 20.8. Connect QuickBooks Online to AlgaPSA for Live Two-Way Accounting Sync and 14.31. Connect Xero for Two-Way Invoice and Payment Sync.

Control password vault audit access

The credential:audit permission allows vault-wide Password audit log and per-credential History review. It defaults to the MSP Admin and Manager roles and continues to respect credential access restrictions. These audit views require the Pro tier and show activity without revealing credential values. See 7.8. Store and Share Client Credentials in the Password Vault.

Configure single sign-on

Open Settings > Security > Single Sign-On to configure staff identity providers. Keycloak / OpenID Connect is available in Community Edition and Enterprise Edition and is the Community Edition SSO option. Google and Microsoft SSO require Enterprise Edition. See 10.18. Set Up SSO with Keycloak, Google Workspace, or Microsoft 365 for realm configuration and account linking.