Manage Partner Portal access
Each member of your team who needs access to the partner portal will need a partner portal user account created.
Table of Contents
Overview
Learn how to control who on your team can access the Password Boss Partner Portal, how to grant admin-level access, how to update a user's email, and how trusted devices and password resets are handled.
The Partner Portal is where MSP admins create client companies, add users, build groups, administer shares, and manage both your account and your clients' accounts. Access is account-specific and role-driven, so getting Portal access right is the foundation of least-privilege administration across every client you manage. Saved passwords are never visible in the Portal — they live only in the client app — so Portal access governs management rights, not vault contents.
What Partner Portal access is
This section explains what Partner Portal access controls and who can use it.
Any existing user on your account can be granted Partner Portal access. Once granted, that user can create client companies, users, and groups, administer shares, and manage your account and your clients' accounts. Only Admin users on your account have access to the Partner Portal, and an administrator can configure which sections (tabs) each user is allowed to see — not all tabs are visible to all users.
Password Boss account and Partner Portal passwords
For WebApp users, the same password is used to access both the Password Boss WebApp and the Partner Portal. Changing the password updates the credentials used for both experiences.
For Legacy Password Boss users, the Password Boss application password and the Partner Portal password are separate credentials. Changing one password does not change the other.
This distinction exists because Legacy Password Boss accounts were built on a different authentication model than the current WebApp platform. Regardless of the authentication method used, CyberFOX and Password Boss do not have access to the contents of your encrypted vault. Your saved passwords remain accessible only to authorized users through the Password Boss application.
How to identify which account type you are using
- WebApp users sign in through the modern Password Boss WebApp experience and use the same password for both the Password Boss application and the Partner Portal.
- Legacy users use the Legacy Password Boss platform and maintain separate passwords for the Password Boss application and the Partner Portal.
If you are unsure which platform your organization uses, contact your Password Boss administrator or CyberFOX Support for assistance.
Security note: Partner Portal access allows administrators to manage companies, users, groups, sharing relationships, and account settings. It does not provide access to users' saved passwords or vault contents. Password data remains encrypted and accessible only through authorized Password Boss applications.
Managing who has access
Follow these steps to open the access controls for your account.
To manage Partner Portal access:
- Open the Partner Portal at partner.passwordboss.com.
- Click your company from the Company list.
- Click the Partner Portal tab.
- You will see three tabs: Portal Access, Roles, and Company Groups.
Creating a Partner Portal account for a team member
Each member of your team who needs Partner Portal access needs their own Partner Portal user account.
- On the Portal Access tab, click the blue + and select Add user.
- Choose an existing user and create a Partner Portal username for them. Spaces and
@are not allowed in usernames, and usernames must be unique. We recommend standardizing onname.companynamefor every user (for example,jsmith.contoso). - Add the user to a role and click Next.

- Add the user to the correct company group(s) and click Save.

Adding additional admin users to your team
Use this workflow when you need more than one person with full administrative control of the Partner Portal.
Admin-level access is granted through the role you assign during (or after) account creation — it is not a separate checkbox on the user record. To add another admin:
- On the Portal Access tab, click the blue + and select Add user (or open an existing user you want to promote).
- Create or confirm the Partner Portal username following the naming rules above.
- In the role step, assign the Admin role (rather than a standard or limited role). Admin role members can manage users, roles, company groups, clients, and shares across the account.
- Assign the appropriate company group(s) and click Save.
- Have the new admin confirm access by logging in at partner.passwordboss.com and verifying they can see the Portal Access, Roles, and Company Groups tabs. If those tabs are missing, the user was assigned a non-admin role — reopen the user and correct the role assignment.
Partner Portal roles
Partner Portal roles determine what users can view and what actions they can perform throughout the Password Boss Partner Portal.
Each permission includes separate View and Change rights:
- View allows a user to see data and information within that section.
- Change allows a user to modify settings, create new items, update existing items, or perform administrative actions within that section.
- In most cases, users should be granted the minimum permissions required to perform their job responsibilities.
- Administrators should regularly review assigned roles to ensure permissions remain appropriate.
Creating a custom role
- Open the Partner Portal.
- Navigate to Partner Portal → Roles.
- Click the + button to create a new role.
- Enter a role name and description.
- Select the required permissions.
- Click Save.
- Assign the role to the appropriate users
Expand each section to learn more about the available permissions when creating a role.
Partner Role - Companies permissions
The Companies section controls access to customer companies and the resources associated with them.
Add Company
Allows users to create new customer companies within the Partner Portal.
Recommended for:
- Senior technicians
- Onboarding specialists
- Administrators
Backups
Controls access to company backup information and backup-related functions.
Recommended for:
- Security administrators
- Senior support staff
Company List
Controls visibility and management of customer company records.
Recommended for:
- Help desk technicians
- Account managers
- Administrators
Connectors
Controls access to connector integrations configured for customer companies.
Recommended for:
- Integration specialists
- Administrators
Delete Company
Allows permanent removal of company records.
Security Note: This permission should be restricted to a very small number of trusted administrators.
Devices
Controls access to managed devices associated with customer companies.
Recommended for:
- Help desk technicians
- Security teams
- Administrators
Disable User 2FA
Allows disabling two-factor authentication for users.
Security Note: This permission can significantly impact account security and should be granted only when operationally necessary.
Groups
Controls management of user groups within customer organizations.
Recommended for:
- Administrators
- User-management teams
Partner Portal → Company Groups
Allows administration of Company Groups used to scope customer access and visibility.
Recommended for:
- Portal administrators
Partner Portal → Roles
Allows creation and modification of Partner Portal roles.
Security Note: Users with this permission can effectively grant additional access to other users.
Partner Portal → Users
Controls creation and management of Partner Portal users.
Recommended for:
- Administrators
- Service desk managers
Policies
Controls access to security and configuration policies.
Recommended for:
- Security administrators
- Operations teams
Shares
Controls management of shared items between users.
Recommended for:
- Administrators
- Customer success teams
Users
Controls management of end-user accounts.
Recommended for:
- Help desk staff
- User administrators
Vaults
Controls access to vault administration functions.
Important: Partner Portal access does not provide visibility into encrypted password contents.
Partner Role - Account permissions
The Account section controls access to your MSP account settings and billing information.
Payment Method
Controls visibility and modification of payment details associated with the account.
Recommended for:
- Business owners
- Financial administrators
Settings
Provides access to account-wide configuration settings.
Recommended for:
- Administrators
Summary
Allows viewing of account summary information and overall account details.
Recommended for:
- Managers
- Administrators
Transactions
Controls visibility into account transactions and billing history.
Recommended for:
- Finance personnel
- Business owners
User Counts
Allows viewing account licensing and user-count information.
Recommended for:
- Licensing administrators
- Account managers
Partner Role - Integrations
Controls access to third-party integrations configured within the Partner Portal.
Recommended for:
- Integration specialists
- Administrators
Reports → Event Log
Provides access to security and administrative event logs.
Recommended for:
- Security teams
- Compliance personnel
- Administrators
Reports → Password Auditing
Provides access to password-health and auditing reports.
Recommended for:
- Security teams
- Compliance teams
Reports → User Activity
Provides access to user activity reporting and auditing information.
Recommended for:
- Security teams
- Administrators
- Compliance personnel
Recommended role templates
Read-Only Auditor
Recommended permissions:
- View Company List
- View Users
- View Devices
- View Event Log
- View Password Auditing
- View User Activity
- View Account Summary
Use for:
- Compliance reviewers
- Security audits
- Management reporting
Help Desk Technician
Recommended permissions:
- View/Change Users
- View Devices
- View Groups
- View Shares
- View Company List
Use for:
- Tier 1 and Tier 2 support teams
Senior Technician
Recommended permissions:
- Help Desk permissions
- View/Change Groups
- View/Change Policies
- View/Change Shares
- View/Change Devices
Use for:
- Escalation technicians
- Team leads
Partner Portal Administrator
Recommended permissions:
- Full access to all Partner Portal functions
- Roles management
- User management
- Company Group management
Use for:
- MSP owners
- Operations leaders
- Designated platform administrators
Company groups
Company Groups are used to control which companies a Partner Portal user can see and manage. They provide a security boundary that allows MSPs to limit access to only the customers a technician, engineer, account manager, or department needs to support.
While Roles determine what actions a user can perform, Company Groups determine which companies those actions can be performed against.
For example:
- A Tier 1 technician may have permission to manage users and devices.
- A Company Group can restrict that technician to only the 10 customers they support.
- Even though the technician has the necessary permissions, they cannot see, search for, or access companies that are not assigned to their Company Group.
Think of Company Groups as a visibility filter that works alongside Roles to implement least-privilege access.
How Company Groups work
A Company Group contains one or more companies.
Users are then assigned to one or more Company Groups.
When a user signs into the Partner Portal:
- They can only see companies assigned to their Company Groups.
- They can only manage companies assigned to their Company Groups.
- Companies outside their assigned groups are hidden and inaccessible.
- Roles continue to determine which actions they can perform within those companies.
Understanding Roles vs. Company Groups
It is common to confuse Roles and Company Groups because both impact access.
| Feature | Controls |
|---|---|
| Role | What a user can do |
| Company Group | Which companies a user can access |
For example:
A technician may have:
- View and Change access to Users
- View and Change access to Devices
- View and Change access to Groups
If that technician only belongs to the Florida Customers Company Group, those permissions apply only to companies within that group.
The same technician cannot access companies in the Healthcare Customers Company Group unless they are also assigned to that group.
Creating a Company Group
- Open the Partner Portal.
- Navigate to Partner Portal → Company Groups.
- Click the + button.
- Enter a Company Group name.
- Enter an optional description.
- Select companies from the Available list.
- Move the companies to the Assigned list.
- Click Save.
The new Company Group can now be assigned to Partner Portal users.
Assigning users to Company Groups
Company Groups do not automatically grant permissions.
After creating a Company Group:
- Open the Partner Portal user account.
- Edit the user.
- Assign the desired Company Group(s).
- Save the changes.
The user will only see companies assigned to those groups after refreshing the Portal.
Default Company Groups
Every company is automatically added to the All Companies group when it is created.
If additional Company Groups are being used, administrators must manually assign the company to those groups as needed.
This allows organizations to immediately manage newly created companies while still maintaining structured access controls.
Multiple Company Groups
Users can belong to multiple Company Groups.
Companies can also belong to multiple Company Groups.
This flexibility allows MSPs to create overlapping access models without duplicating company records.
Example:
Company: Acme Manufacturing
Assigned to:
- Florida Customers
- Enterprise Customers
- Compliance Clients
A technician assigned to any of those groups can access Acme Manufacturing, provided their Role grants the required permissions.
Expand for some common use cases for usng Groups.
Company Group Common use cases
Technician Team Segmentation
This is the most common Company Group deployment model.
Example:
- Tier 1 Team
- Tier 2 Team
- Professional Services
- Security Team
Each group only sees the customers they support.
Geographic Segmentation
Organizations with regional support teams often create groups based on location.
Examples:
- East Coast Customers
- West Coast Customers
- Canada
- International Customers
Customer Tier Segmentation
Groups can be used to separate strategic or high-touch customers.
Examples:
- Enterprise Clients
- SMB Clients
- VIP Clients
Compliance Segmentation
Organizations supporting regulated industries often separate customers based on compliance requirements.
Examples:
- Healthcare Clients
- Financial Services Clients
- Government Clients
- Education Clients
Business Unit Segmentation
Larger MSPs may use Company Groups to separate internal departments.
Examples:
- Help Desk
- Professional Services
- Security Operations
- Account Management
Company Group Security considerations
Company Groups should be treated as a visibility and access-control boundary.
When a company is not assigned to one of a user's Company Groups:
- The company is hidden.
- The company cannot be accessed.
- The company cannot be managed.
- The company does not appear in company listings.
Because of this, Company Groups are one of the primary tools used to limit technician access to customer environments.
Company Group Best practices
- Create Company Groups based on operational responsibilities.
- Assign users only to the groups they require.
- Review group assignments regularly.
- Use multiple Company Groups when customers fit more than one category.
- Keep naming conventions consistent.
- Combine Company Groups with least-privilege Roles.
- Reserve broad access to trusted administrators.
Platform-specific behavior
The Partner Portal is a web application; the notes below cover where the app itself is involved.
Portal (web — partner.passwordboss.com)
All user creation, role assignment, company-group management, admin promotion, and email changes described above happen in the browser-based Partner Portal. This is the primary surface for everything in this article.
WebApp & Desktop (device management)
Trusted-device management overlaps with the client app. A registered browser can be removed from the Devices tab of your user account in the Partner Portal, or from the Devices tab in Settings in the Password Boss app (WebApp or Desktop).
iOS & Android
Not applicable. Partner Portal administration (adding users, roles, groups, admin access, email changes) is performed in the web Portal, not in the mobile apps. Mobile apps are for end-user vault access only.
Advanced use cases
These patterns help larger Companies keep Portal access clean at scale.
- Tiered technician access: Create standard roles for Tier 1/2 techs scoped to specific company groups, and keep a very small Admin group for account owners and senior engineers.
- Client segmentation: Use company groups to isolate sensitive or regulated clients so only cleared staff can manage them.
- Redundant admin coverage: Always maintain at least two admin users so you are never locked out if one admin is unavailable — but no more than necessary.
Best practices
Apply these to keep Portal access secure and maintainable.
- Least privilege: Grant the lowest role that still gets the job done; reserve Admin for the few who need full control.
- Two-admin minimum: Keep at least two admins for continuity, and review the admin list quarterly.
- Scope with groups: Assign users only to the company groups they support.
- Never delete-to-fix: Do not delete and recreate a user to work around a locked email field or an access issue — it breaks shares, roles, and device trust. Correct the role or open a support ticket instead.
- Offboarding: Remove Portal access and registered devices promptly when a team member leaves.
Troubleshooting
Common issues and how to resolve them.
A technician cannot see a company
If a technician cannot locate a company in the Partner Portal, verify the following:
- The company is assigned to the correct Company Group.
- The technician is assigned to that Company Group.
- The technician refreshes or reopens the Partner Portal.
- The technician's Role includes permissions for the resource they are attempting to access.
If the company appears for some users but not others, this is typically caused by differences in Company Group assignments. Compare the affected users and confirm they are assigned to the same Company Groups.
A newly created company is not visible
If a company was recently created but cannot be found:
- Verify the company was created successfully.
- Verify the company has been assigned to the appropriate Company Group.
- Verify the user belongs to that Company Group.
- Refresh the Partner Portal and try again.
Remember that newly created companies are automatically assigned only to the All Companies group. Additional Company Group assignments must be configured manually.
A user can see a company but cannot perform an action
This is usually a Role issue rather than a Company Group issue.
Remember:
- Company Groups determine which companies a user can see and access.
- Roles determine what actions a user can perform within those companies.
Verify both the user's Role and Company Group assignments when troubleshooting access issues.
New user cannot see Partner Portal administration tabs
If a user cannot see one or more of the following:
- Portal Access
- Roles
- Company Groups
The user has likely been assigned a non-admin role.
Review the user's assigned Role and ensure they have the required permissions. Users assigned to the default Admin role receive full access to all Partner Portal functions.
User can log in to the application but cannot log in to the Partner Portal
Authentication behavior depends on the account type:
- WebApp users use the same credentials for both the Password Boss WebApp and the Partner Portal.
- Legacy users have separate credentials for the Password Boss application and the Partner Portal.
If the user cannot access the Partner Portal, have them perform a Partner Portal password reset and verify which platform they are using.
Prompted for a verification code on every login
The Partner Portal uses trusted device verification to help protect administrative accounts.
Verify:
- The user's email address is correct and accessible.
- The browser has not been cleared of cookies or security settings.
- The device has not been removed from the user's trusted devices list.
- The user is not using a new browser or private/incognito session.
If necessary, re-register the browser as a trusted device by completing the verification process again.
Resetting your Partner Portal password
Use this if a user is locked out of the Portal specifically.
- Go to the Partner Portal login screen.
- Click Forgot your password?
- Enter your email address and click Send reset link.
- Follow the instructions in the email to reset your password.
Security & sync behavior
How access, trust, and data isolation work.
- Separate credentials: Portal and client-app passwords are independent by design, so no CyberFOX/Password Boss staff can reach your saved vault data.
- No vault exposure: Saved passwords are never accessible through the Portal — only from the client app. Portal access grants management rights, not vault access.
- Trusted devices: Every browser used to access the Portal is registered as a trusted device via an email verification code. Remove stale browsers from the Devices tab in the Portal or in the app's Settings.
- Admin-controlled visibility: Admins configure which Portal sections each user can access; not all tabs are visible to all users.
- Identity-protected email: Because email drives device verification and identity, the field is locked in the UI and changed through the supported workflow to preserve shares, roles, and device trust.