Roles & Permissions
Every user in your ITOC360 organization has a role, and that role decides what they can see and do from acknowledging an incident to changing the subscription. ITOC360 ships with three built-in roles that cover most teams, and if none of them is quite right, you can build your own role by picking exactly the permissions it should include.
You'll find everything under Management → Roles & Permissions.
Creating and managing custom roles is available on the Advanced and Premium plans. The three built-in roles are available on every plan.
Built-in roles
Admin has every permission. Admins are the only ones who can delete things (sources, teams, schedules, escalation policies, channels, domains, maintenance windows, roles), change the plan or payment method, and assign a role to a user. Keep this role for the small group of people who genuinely need to run the organization.
Manager is the day-to-day operator. Managers can create and edit almost everything, acknowledge incidents, silence alerts, and invite new users — but they cannot delete anything, cannot touch billing beyond viewing it, and cannot assign roles to other users. This is the right fit for team leads and senior on-call engineers.
Viewer is read-only. Viewers can see alerts, incidents, sources, schedules, teams, escalation policies, channels, domains, maintenance windows, roles, and the billing overview — but they can't change any of it, and they can't acknowledge incidents or silence alerts. Useful for stakeholders who want visibility without the risk of a stray click.
Built-in roles can't be edited or deleted. If you need something between Manager and Viewer, create a custom role instead.
Permissions reference
The tables below show what each built-in role can do. When you create a custom role, these same permissions are the ones you toggle on and off.
Alerts
View alerts
✅
✅
✅
Silence alerts
✅
✅
—
Incidents
View incidents
✅
✅
✅
Acknowledge incidents
✅
✅
—
Sources
View monitoring sources
✅
✅
✅
Create new sources
✅
✅
—
Edit source settings and configurations
✅
✅
—
Remove sources
✅
—
—
Escalations
View escalation policies
✅
✅
✅
Create new escalation policies
✅
✅
—
Edit escalation policy settings and configurations
✅
✅
—
Remove escalation policies
✅
—
—
Schedules
View schedules
✅
✅
✅
Create new schedules
✅
✅
—
Edit schedule settings and configurations
✅
✅
—
Remove schedules
✅
—
—
Teams
View teams
✅
✅
✅
Create new teams
✅
✅
—
Edit team settings and configurations
✅
✅
—
Remove teams
✅
—
—
Channels
View notification channels
✅
✅
✅
Create new notification channels
✅
✅
—
Edit channel settings and configurations
✅
✅
—
Remove notification channels
✅
—
—
Maintenances
View maintenance windows
✅
✅
✅
Create new maintenance windows
✅
✅
—
Edit maintenance window settings and configurations
✅
✅
—
Remove maintenance windows
✅
—
—
Domains
View domains
✅
✅
✅
Create new domains
✅
✅
—
Edit domain settings and configurations
✅
✅
—
Remove domains
✅
—
—
Roles
View roles, their assigned permissions, and the assignable permissions catalogue
✅
✅
✅
Create new roles within the tenant
✅
✅
—
Edit roles and their permission assignments
✅
✅
—
Remove roles from the tenant
✅
—
—
Users and invitations
Invite users to tenants
✅
✅
—
Assign a role to a user in own tenant
✅
—
—
Billing
View the subscription, plan usage, and invoices
✅
✅
✅
Change the plan, seats, or payment method, and cancel the subscription
✅
—
—



Notice the split in the Roles table: a Manager can create and edit roles, but cannot assign a role to a user or delete a role. Those two actions stay with Admins.
Creating a custom role
Go to Management → Roles & Permissions.
Click Create Role in the top right.
Give the role a name that describes the job, not the person —
Network On-Call,Read-only Auditor,Billing Owner.Toggle on the permissions the role should have. Permissions are grouped by area, so start with the group you care about most.
Save the role.
The new role appears as a column in the permissions table alongside Admin, Manager, and Viewer, and becomes selectable everywhere a role is chosen.
A few things worth keeping in mind while you pick permissions:
Grant the view permission for anything you grant edit on. A role that can edit schedules but can't view them will hit dead ends in the UI.
Delete is always the sharpest edge. Removing a source, schedule, or escalation policy is not recoverable, so hand out the remove permissions deliberately.
Think about who can hand out power. A role with Create new roles, Edit roles, and Assign a role to a user can effectively promote anyone, including itself.
Assigning a role to a user
Go to Management → Users.
Find the user and change their role.
Only a role with Assign a role to a user in own tenant can do this — by default, Admin.
Role changes take effect on the user's next page load; they don't need to sign out and back in.
Choosing a role when you invite someone
The invitation form now includes a role selector, so new users land with the right permissions from their very first login instead of being fixed up afterwards.
Go to Organization → Invites and start a new invitation.
Enter the email address.
Pick the role from the dropdown — built-in and custom roles both appear here.
Send the invitation.
Inviting requires the Invite users to tenants permission, which Admin and Manager both have.

Editing and deleting a role
Open a custom role from Roles & Permissions to change its name or adjust its permissions. Changes apply to everyone already holding that role, so a permission you switch off disappears for those users right away.
Deleting a role needs the Remove roles from the tenant permission. Built-in roles cannot be deleted.
Filtering the table
The permissions table can get long — it covers every permission in the product across every role. Use the search box to filter by permission name, and the View control to show or hide role columns so you can compare just the two roles you're interested in.
Last updated
Was this helpful?

