< back to blog

New Feature: Scoped Users for Customers and Partners

Product UpdatesMSP

Introduction

MSPs regularly ask whether a client can log in and see their own domains. Until now, the answer was a separate organisation for each client, or sharing screenshots and reports by email.

Our recent release added read-only and scoped user roles. You can now invite customers and partners into your organisation and control exactly which domains they see.

New Read-Only Roles

Two new read-only roles sit at the start of the role ladder:

  • Dashboard Viewer - read report data on the Dashboard.
  • Viewer - everything in Dashboard Viewer, plus Domains and Insights.

Read-only users cannot add, change or delete domains, and the Settings pages (Users, Organisation, Alerts and API) are hidden. They suit managers, auditors and anyone who needs to see email security posture without changing it.

Scoped Users

Each read-only role has a scoped variant: Scoped Dashboard Viewer and Scoped Viewer. A scoped user sees the same pages, limited to the domains an Organisation Admin assigns to them.

  • Up to 20 domains can be assigned to each scoped user from the Users page.
  • Subdomains are included. Access to a domain includes reported traffic from its subdomains. A subdomain added to VerifyDMARC as its own domain is assigned separately.
  • Nothing is visible by default. A scoped user with no assigned domains sees no reporting data.
  • Removals flow through. Removing a domain from your organisation also removes it from every scoped user’s access.

Scoped Users or Sub-Accounts?

VerifyDMARC now gives you two ways to handle customer access:

  • Scoped users suit a customer or partner who only needs to see their own domains. They sign in to your organisation, while billing, alerts and settings stay with your team.
  • Separate organisations are the closest thing to sub-accounts. They suit a customer who needs their own billing, admin users or settings. One login can switch between organisations, and each organisation is invoiced independently.

For most clients who want visibility rather than control, a scoped user is the simpler option.

Getting Started

Choose a role when inviting a user, or change an existing user’s role from the Users page. For a scoped role, assign the user’s domains in the Domain access column.

Scoped users sign in the same way as everyone else, with a passwordless email code or Google or Microsoft Single Sign-On. Each scoped user counts as an admin user, so is included on plans from Starter and above.

See the Users documentation for the full list of roles and how domain access works.

Not a VerifyDMARC customer yet? Sign up for our 30-day free trial, no credit card required, and put your domains on watch.