Roles and access
The QuantumOps roles, which role can open which screen, and the checks beyond roles such as modules, linked HaloPSA logins and QBR report ownership.
Written By Chris Scaminaci
Last updated About 1 hour ago
Every person who signs in to QuantumOps has one or more roles. Roles decide which screens a person can open and which actions they can take. This page lists the roles, shows which role opens which screen, and explains the checks that apply on top of roles. Administrators assign roles in Team Management; Inviting people, roles and agent links covers the steps. Quick start by role lists the first screens to learn for each role.
The roles
How roles work:
- A person can have several roles and can open whatever any one of their roles allows.
- The Administrator role opens every screen in the tables on this page, including all configuration.
- Role changes apply at your next sign-in; sign out and in to pick them up now. See When role changes apply.
- Your sign-in provider can also carry a few base roles that Team Management never shows. Changing a person's roles leaves them as they are.
- WhiteLabelPartner is for staff of a white-label partner, who work in the partner dashboard. Do not give it to your own team. It is never admitted to identity verification, so an account that has it cannot use identity verification even if it also has a role that is.
Who can open each screen
A tick means the role can open the screen. The columns use the short names from the roles table above. The tables list the screens where a role decides, grouped by the section of the documentation they belong to, and each screen links to its page. The Partner column has no ticks because the screens that role opens are partner screens, which this documentation does not cover.
Getting started
How tickets are analysed
Qubit and AI
Q-Director and AI settings
Dispatch
Calls and call recordings
Identity verification
Q-Notices and alerts
Customer success
CSAT and NPS surveys
QBR Studio
Reporting and analytics
Timeclock and payroll
Browser extension
Integrations
System and administration
Screens with no role requirement
These screens do not check a role. Three rows are the public pages of features whose settings do need one, and the last column says so. For the other rows, the last column shows which screens are open to anyone who is signed in. Each screen is described on its own page. A module that is off can still switch a screen off: see the Modules reference.
The Web Search, Guides and Call Taking tabs of Q-Director Settings, with the Scripts sub-tab for call scripts, are not in this table. You reach them through Q-Director Settings, which the Administrator and Q-Director Configuration roles use. They are described in Q-Director: web search, Q-Director: guides and the guide simulator, Call Taking settings and Building call scripts.
The Channel Assistant page opens only for Administrators. Anyone else who opens it, for example from a bookmark, gets the Access Denied screen, and the sidebar does not show them the link. Linking your own chat account is a separate page, Link Slack / Teams, which opens for anyone who is signed in. See Channel Assistant settings and Linking your Slack or Teams account.
Sidebar links and the Access Denied screen
A sidebar link is shown only to people whose role can open the screen behind it, and the tables above are the rule for that. A link your role cannot open is hidden, and a section heading in the sidebar is hidden when no link under it is left for you. A few links, such as Home, Browser Extension, MCP Sources and Link Slack / Teams, are open to everyone who signs in. When a link is missing or a page refuses you, work through When a menu item is missing or a page refuses you.
Checks beyond roles
A role is necessary for most screens but is not always enough.
- Modules. A screen can also need its module switched on. A module that is off removes the sidebar links and header buttons it controls, and a few screens show a notice instead of their content. The Modules reference lists what each module controls, and Module Management is where an administrator switches them.
- A login linked to a HaloPSA agent. Actions that write to HaloPSA as you need your QuantumOps login to be linked to your own HaloPSA agent. Examples are posting a note to a ticket, attaching a call recording, creating or linking a ticket from a call and dispatching a ticket from the browser extension. Without the link the extension says, for example, "Your account is not linked to a Halo agent in this tenant, so it cannot post to tickets." The Clock tab needs the login to be linked to a timeclock agent or payroll employee in the same way. An administrator links a login in Team Management.
- The Supervisor tick. Team Management has a Supervisor tick on a team member ("can manage other employees' timeclock entries"). Forcing a clock-in, clock-out or break for another employee, and adding a manual time entry for one, needs that tick on your own team member record, as well as a role that opens the screen. The timeclock and payroll admin hub and Supervising punches, exceptions and time off describe those screens.
- QBR owner and reviewer rules. QBR Studio adds rules about each report on top of the role. Anyone with QBR access can edit a report while it is open for editing. Publishing, unpublishing, archiving, changing the client link, changing the report's details, sending the pre-read and recording decisions are for the report's owner, its listed reviewers and administrators. Approving a report is for its listed reviewers, or for the owner when there are no other reviewers, and for administrators. Your organisation can forbid owners approving their own work. Deleting a report is for its owner and administrators. QBR templates, schedules and settings need the Administrator or Service Desk Manager role. See Review, publish and share with the client.
- What each part of the extension needs. Some parts of the extension, such as call recordings, identity verification and the dispatch board, are also switched on per server and each checks a role. What each part of the extension needs lists them.
Related pages
- Other reference pages: Modules reference, E-mails QuantumOps sends and the Glossary.
- Quick start by role, for the first screens to learn for each role.
- Signing in, for when a role change applies.
- Access denied and sign-in errors, for what to do when a page refuses you.
Was this helpful?
Still need help? Ask the team