Skip to main content
Administrators can assign user roles, share workflows with individual users, restrict dashboard sections, and review activity logs.

User Management

Dashboard Overview

Find RBAC under Roles & Access. It lists users in your organization with their roles, status, and recent activity. Only users with ADMIN role can view/manage other users.

User Roles and Permissions

Neo Agent supports different user roles with varying levels of access:
  • Owner: Everything an Admin can do, plus the workspace-wide chat History and the right to make or remove owners. The first user of a workspace starts as its owner; a workspace always keeps at least one.
  • Admin: Full access to all features and user management capabilities
  • User: Regular Users can create any workflow as well as can edit any workflow shared with them
  • Viewer: Read-only access, can view execution history of any workflow shared with them, but cannot create or edit any workflow
Users with OWNER or ADMIN role have access to all dashboard sections. Users with USER/VIEWER role need to be granted access to restricted dashboard sections.

Workflow access applies everywhere — including Neo Support

A user’s workflow access (their role, the workflows they created, and the workflows shared with them) is enforced consistently across every surface:
  • Dashboard: the workflow list, editor, run-now, version history, and stats only cover workflows the user can access.
  • Audit Log and the public API: the Audit Log lists the actions of the workflows the user can access, on the dashboard page and on GET /public-api/audit-log/tool-calls alike. An owner or admin sees every agent; a user or viewer only the agents they created or that were shared with them.
  • Neo Support chat: when a user asks the Neo Support Agent to list, inspect, edit, or train workflows, the agent operates under that user’s permissions. It only sees the workflows they can see, and edits (including training suggestions) require edit access — a Viewer, or a User the workflow isn’t shared with, will be told to ask an administrator instead.
  • Training suggestions: reviewing or applying a suggested change to a workflow requires access to that workflow.
  • People with no dashboard account: a technician who can chat with the Neo Support Agent (for example in Teams) but has no account in Roles & Access cannot list, view, or edit any workflow through it. Their company data comes from one workspace-wide default, which is empty until an admin sets it — see People without a dashboard account. The agent tells them to ask an administrator for an account. To let someone read workflows without changing them, invite them as a Viewer.
  • Skills: creating, editing, or deleting a Skill applies to every agent in your workspace, so the Neo Support Agent only does it for people whose role can write — a Viewer (or someone with no dashboard account) is told to ask an administrator instead.
  • Company data in AI chat: admins hold every data source implicitly. For everyone else, the Neo Support Agent uses only the sources granted on their page — open Roles & Access and click their row — the PSA (synced tickets, contacts and configurations, plus live reads), each documentation source separately, and devices (all connected RMMs together). Anything not granted is explained by the agent, with the fix, instead of failing. See AI chat data access.
There is no way to use the Neo Support Agent to reach a workflow the user couldn’t reach on the dashboard.

Access Denied Scenarios

When users don’t have the necessary permissions to access the dashboard, they’ll encounter an access denied screen that explains the restriction and provides contact information for administrators:

Inviting New Users

To add new team members to your Neo Agent organization:
  1. Access User Management: Navigate to the Roles & Access section
  2. Click Invite User: Select “Invite New User” to open the invitation form
  3. Enter User Details: Provide the user’s name, email address, and assign their role
  4. Send Invitation: The system automatically sends an email invitation to the new user

Example of Email:

New users receive an email invitation with instructions to access the Neo Agent dashboard and will appear as “Pending” until they complete the activation process.

Changing someone’s name or role

Click their row in Roles & Access. The person’s page opens with Name & role at the top. A new name saves when you click away from the field; a role saves as soon as you pick it. Only an owner can make someone else an owner, and a workspace keeps at least one owner, so the last one cannot be demoted.

Permission Management

Dashboard Tab Access

Control access to dashboard sections through granular permission settings:
Available restricted access tabs include:
  • Integrations: Configure PSA, RMM, and other system integrations
  • Analytics: View workflow performance and system analytics
  • Phone Agent: Manage AI Phone Agents settings and call history
  • Companies: Manage client companies and organizations
  • Profile: View and edit user profile information
  • Billing: Manage billing and subscription information
  • Settings: Configure system settings and preferences
  • Feedback: Provide feedback about workflows
  • Chat: Access chat agents for conversational AI assistance
  • Backfills: Create and manage workflow backfill runs over historical data
  • Scheduled Work: View and manage scheduled workflow runs

Restricted Access Experience

When users attempt to access a dashboard section they don’t have permission for, they’ll see an access restriction message:
The message directs users to their administrator to request access.

Workflow Sharing

Give one person access to agents and workflows they did not create.
  1. Open Roles & Access, then click the person’s row.
  2. In Agents & workflows shared with them, click Add agent. Search by name or by id, then click every agent you want. Each pick gets a check, and the panel stays open.
  3. Click Add to grant them all at once. Closing the panel first cancels your picks.
  4. Use the bin icon on a row to take an agent back, then confirm. When the agent is part of a chain, the confirmation says how many go with it.
Each agent’s id sits beside its name in the list, so two agents that share a name can be told apart. Adding saves when you click Add; removing saves once you confirm. Shared workflows appear in that person’s dashboard alongside the ones they created themselves.
A workflow that runs as part of a chain is shared with the rest of its chain, and taken back with it. Half a chain shows someone a run that starts or ends in a workflow they cannot open.

Chat Agent Access

The Chat Agent Access tab controls who on your team may message each internal chat agent. This is separate from workflow sharing and dashboard tab access. It governs messaging only, not who can see or edit the agent’s configuration.
Controlling a chat agent is two independent questions. Who may message it is this tab. What company data it uses for each person is AI chat data access on that person’s page. Opening the agent to everyone grants nobody your ticket or documentation data, and granting someone that data does not let them message an agent this tab excludes.
For each chat agent, an admin can choose one of three modes: Only admins can change these settings. The mode applies to every internal chat agent, including the Neo Support Agent. Agents that serve end users through a channel are governed by that channel instead, not by this tab. This setting drives what each person sees: the Chat page’s agent list, the Train/Skillify buttons, and the Need help? widget all appear exactly for the people the agent’s mode admits. Restricting the Neo Support Agent therefore also removes those affordances for everyone excluded. You no longer need to restrict the Neo Support Agent to protect your company data: what it may read for each person is a separate, per-person setting — see AI chat data access below. A non-admin who chats with it always gets product help and can train the agents they have access to; company data follows their grants.

AI chat data access

Every person’s page (Users → click their row) has an AI chat data access section. It lists the integrations you have connected that carry company data, and an admin ticks the ones the Neo Support Agent may use when that person is chatting — on the dashboard and in Microsoft Teams alike: The Tickets grant carries two further reads that are assembled from PSA data: raw analytics queries over synced tickets, and resolving a company name to its ids in the systems that person is granted. Admins hold every grant implicitly. Nothing is granted to a new user by default — an invitation on its own grants no company data, whatever role it carries, so a new Viewer starts with every box unticked. When someone asks the agent for data outside their grants, it names the system it cannot read and points them to an administrator.
To let some technicians ask for reports on tickets: invite them under Roles & Access (Viewer is enough to ask questions), then open each person’s page and tick the Tickets grant. If they will never hold a dashboard account and only chat from Microsoft Teams, add Tickets to the no-account default described below instead. Then check Chat Agent Access admits them: Everyone on your team does; under Admins only or Specific people, a person not listed cannot message the agent at all, whatever their grants.
Documentation stays separate from Tickets — a person with Tickets and no documentation source cannot reach your documents through an analytics query either. Saved memories follow the dashboard account rather than a grant. Anyone with an active Neo account can recall them in chat, exactly as they can read them on the Memory page; someone who only chats from Microsoft Teams with no account cannot, whatever their grants say. People without a dashboard account. Anyone in your Microsoft Teams can chat with the Neo Support Agent, including people you never invited to the dashboard. The Users tab has a collapsible card, AI chat data for people without a dashboard account, that sets what the agent may use for such a speaker — empty by default. To give one specific person more or less than that default, invite them (Viewer is enough) and set it on their page. The same page carries that person’s name and role, the Dashboard sections they may open (navigation only — it does not protect data), and the agents shared with them, so one page answers “what can this person reach” and is where every part of the answer is changed. See Who can chat with the agent for how this appears when building an agent.

API Keys

The API Keys tab is where admins create and manage keys for the Neo public API: the credentials your own scripts and integrations use to call Neo programmatically. From Roles & AccessAPI Keys an admin can:
  • Create a key, with an optional expiry. The full key is shown once, right after creation — copy it then, as it can’t be retrieved later.
  • Rotate a key — issues a replacement immediately while the old key keeps working for 24 hours, so you can roll it over without downtime.
  • Revoke a key — disables it immediately and permanently.
Only admins can manage API keys. See Authentication for how to use a key once you’ve created one.

Activity Tracking

Comprehensive Audit Trail

Neo Agent maintains detailed activity logs for all user actions and administrative changes:

Tracked Activities

The system automatically logs:
  • Workflow Sharing: When workflows are shared or access is revoked
  • Role Changes: Updates to user roles and permissions
  • User Management: User creation, activation, enabling, and disabling
  • Permission Updates: Changes to dashboard tab access
  • Announcement Subscriptions: Email notification preferences

Activity Details

Each audit entry includes:
  • Timestamp: When the activity occurred
  • User: Who performed the action
  • Activity Type: What type of change was made
  • Details: Specific information about the change

Managing User Status

User Status Types

Users can have different statuses within your organization:
  • Active: Full access according to their role and permissions
  • Inactive: Temporarily disabled access while preserving user data
  • Pending: Invited but not yet activated their account

Announcement Notifications

Email Subscription Management

Control who receives Neo Agent announcement emails through the RBAC system: Users can be subscribed or unsubscribed from announcement emails while maintaining their access to dashboard notifications.

Access across workspaces

An admin can give a person access to another MSP’s workspace. Add the person from the destination workspace’s Users page. Their role, shared workflows, and chat data access apply only there. For someone from another Microsoft directory, expand Add someone from another Microsoft directory in the invitation form. Enter their Microsoft directory ID and User object ID, together with their name, email, and role. Obtain the IDs from their Microsoft administrator. The person signs in with that work or school Microsoft account to activate the membership. Personal Microsoft accounts cannot access Neo, even if invited. A person with one active workspace opens it directly. If their Microsoft directory has no Neo account yet, the chooser also offers Set up my company. With several workspaces or company setup available, they can use Switch workspace in the account menu. Each browser tab keeps its own selected workspace. A switch opens the new workspace’s home page and clears the previous page’s state. For example, an admin in Tailor Made Technologies can add Alice from Global4. Alice can then access both workspaces with her assigned role in each. Bob’s existing Tailor Made membership gives him access only to Tailor Made. Disable a person’s membership to revoke access to that workspace. A later sign-in does not restore it. Their memberships elsewhere remain active. Acquisitions and shared billing accounts do not automatically grant access or change subscriptions. Public API admins can cancel a pending invitation without a Microsoft object ID using DELETE /public-api/memberships/invitations with an email field in the JSON body. This cancels only a pending invitation in the selected workspace. Active memberships use the user-ID revocation endpoint.