## Roles overview

There are several roles that define how admins can access tenants:

- `Global administrator` - full admin access to everything
- `Administrator` - full access but only to designated tenants
- `Read-only administrator` - read only access to designated tenants

### Global administrator role

- Access admin portal of your parent tenant
- Navigate to your `Users` section
- Click on `...` and choose `Make admin`

### Administrator role

- Access admin portal of your parent tenant
- Navigate to your `Tenants` section
- Click on `...` for a chosen organization and choose `Delegate admin`
- From the dropdown search for technician email address and assign the `Administrator` role

### Read-only administrator role

- Access admin portal of your parent tenant
- Navigate to your `Tenants` section
- Click on `...` for a chosen tenant and choose `Delegate admin`
- From the dropdown search for technician email address and assign the `Read-only administrator` role

## How to delegate access to customer tenant

- Login to your parent MSP tenant admin portal
- Access `Tenants` on the left menu, find the tenant that you need, click on `...` and then choose `Delegate admin access`
- You can now choose users from the dropdown along with the role they will assume
- At the bottom you will have a list of all `Global admins` who have access to all tenants by default
