Navigation
10.17. Configure Roles, Permissions (RBAC), and API Keys for Your MSP
Manage roles, API keys, tenant secrets, accounting permissions, password vault audit access, and single sign-on in AlgaPSA.
Navigate to Settings > Security. This section is for administrators to manage security configurations within AlgaPSA.
- Roles: Define and manage roles (e.g., "Manager," "Admin," "Finance," "Technician," "Dispatcher," "Project Manager"). Each role has a description and specifies if it's for MSP or Client Portal users. You can add new roles or delete existing ones. To rename or update the description of a custom role, open the three-dots menu on the role row and select Edit. Built-in role names — such as Admin, Technician, and Finance — are locked and cannot be renamed, though their descriptions can be updated freely.
- Permissions: Configure specific access permissions for different roles and resources (e.g., read, create, update, delete actions for Assets, Contacts, Documents, Time Entry, Tickets, Users, etc.). You can select a role to view or modify its permissions.
- User Roles: Assign roles to MSP users and Client Portal users. Search for users and assign available roles (e.g., "Admin," "Finance," "Technician"). You can also remove assigned roles.
- API Keys: This tab within Security Settings provides a centralized view of all API keys generated in the system.
Manage tenant secrets
Use Settings > Secrets to maintain tenant secrets used by workflows, such as a service API key. This gives the MSP a named secret to rotate without putting its value in routine workflow notes.
Figure 1: Tenant secrets are named, encrypted values that workflows reference without exposing the value.
- Select Create Secret and enter Name, Value, and an optional Description. Names use uppercase letters, numbers, and underscores, for example
BACKUP_SERVICE_API_KEY. - Select Create Secret to save it. The list shows its name, description, and update information.
- Use Edit secret to rotate the value or update its description, then select Update Secret. Leaving the value empty retains the current value.
- Use Delete secret to remove an obsolete secret. Review any workflow-usage warning and type its name to confirm deletion.
Creating, editing, and deleting tenant secrets writes an audit trail. Check the workflow that consumes a secret after rotation, and update dependencies before deleting it. The permissions are secrets:view for viewing the list and secrets:manage for creating, updating, and deleting entries.
Assign accounting integration permissions
Use the Accounting Integrations permission group to separate routine accounting work from connection administration and changes in the remote accounting system. The Admin and Finance defaults differ by capability:
| Permission | What it allows | Default MSP roles |
|---|---|---|
| accounting_integrations:catalog_read | Read remote catalogs and integration status, including accounts, items, tax codes, terms, and connections. | Admin, Finance |
| accounting_integrations:connections_manage | Save OAuth credentials, connect or disconnect providers, and choose the default company. | Admin |
| accounting_integrations:mappings_manage | Create, update, retarget, and reconcile accounting mappings. | Admin, Finance |
| accounting_integrations:exports_execute | Create and execute exports and sync cycles. | Admin, Finance |
| accounting_integrations:remote_mutate | Perform destructive or money-moving operations in the connected accounting system. | Admin |
Review these permissions before delegating an integration to billing staff. For setup and operational checks, see 20.8. Connect QuickBooks Online to AlgaPSA for Live Two-Way Accounting Sync and 14.31. Connect Xero for Two-Way Invoice and Payment Sync.
Control password vault audit access
The credential:audit permission allows vault-wide Password audit log and per-credential History review. It defaults to the MSP Admin and Manager roles and continues to respect credential access restrictions. These audit views require the Pro tier and show activity without revealing credential values. See 7.8. Store and Share Client Credentials in the Password Vault.
Configure single sign-on
Open Settings > Security > Single Sign-On to configure staff identity providers. Keycloak / OpenID Connect is available in Community Edition and Enterprise Edition and is the Community Edition SSO option. Google and Microsoft SSO require Enterprise Edition. See 10.18. Set Up SSO with Keycloak, Google Workspace, or Microsoft 365 for realm configuration and account linking.
