Custom Roles and Granular Permissions in empowsec Explained

Most platforms give teams a blunt choice: hand out full administrator access or lock people into a read-only seat. In practice that means the HR coordinator who only needs to assign onboarding courses ends up with the same rights as the person who manages billing and company settings. empowsec takes a different approach with custom roles and granular permissions, so every stakeholder in your security awareness program gets exactly the access their job requires - and nothing more.
This deep dive covers how company administrators create and manage custom roles, how the permission-based dashboard renders only what each user is allowed to see, and how reseller and MSP teams get an equivalent, fully separate permission system on their side of the platform.
Why Least-Privilege Access Matters in Awareness Programs
A security awareness platform holds surprisingly sensitive data. Phishing simulation results reveal which individual employees clicked a lure or submitted credentials. Risk scores summarize personal behavior over time. Invoices and subscription details expose commercial terms. Handing all of that to everyone who merely needs to assign a training course violates the principle of least privilege - the idea that each account should hold the minimum rights needed for its task.
Least privilege is not just good hygiene. Access control requirements appear throughout common frameworks and regulations, from ISO 27001 access management controls to the governance expectations of NIS2. When an auditor asks who can launch phishing campaigns, who can see individual results, and who can change billing details, the answer 'everyone with an admin login' rarely goes over well. Scoped roles give you a defensible, documented answer instead.
Creating Custom Roles as a Company Admin
In empowsec, company administrators can create, update, and delete custom roles directly in the company workspace. Each role is scoped to your company: names must be unique within your organization, and a role you build never leaks into another tenant. The built-in Company Admin role remains available for the small group that genuinely needs full control.
When you create or edit a role, you assign permissions from a structured tree organized into groups such as Users & Access, Training, Phishing, Finance, Settings, and Branding. Each group contains focused permissions - viewing the user list is separate from creating and archiving users, and viewing phishing campaign results is separate from launching simulations or editing templates. Training permissions distinguish between viewing the course catalog, assigning courses to users, and managing training settings and escalations. Finance splits viewing invoices and subscription status from updating payment details and changing plans. Phishing goes further still, with dedicated permissions for remedial training rules and for viewing and triaging the reported emails inbox.
Two guardrails keep this safe. First, the permission tree is capability-filtered: you only see and assign permission groups that your subscription actually includes, and the server re-checks this on every save, so a role can never grant access to a feature your package does not contain. Second, a role that is currently assigned to users cannot be deleted - you first move those users to another role, which prevents accidental lockouts and orphaned access.
A Dashboard That Renders Only Permitted Tabs
Granular permissions would be frustrating if users still saw a full admin interface with most buttons disabled. empowsec instead computes a Permission Dashboard for every user and company combination, rendering only the tabs their permissions allow.
The tab set is assembled dynamically. My Training appears for everyone in a company with the training capability, showing personal assignments, due dates, and progress. My Departments appears only for department managers and summarizes compliance, overdue items, and at-risk members for the teams they lead. The Training tab requires training view or assign permissions, the Phishing tab requires phishing view permission, the Users tab requires user view permission, and the Finance tab requires billing view permission. A user who holds none of these management permissions is routed straight to the learner dashboard.
Scope follows the same logic. A department manager who opens the Training or Phishing tab sees statistics for the departments they manage, not the entire company. That means a team lead can track their own people's overdue training and phishing click rates without gaining company-wide visibility into everyone else's results.
A Separate Permission System for Reseller Teams
Resellers and MSPs manage many client companies at once, so their access model is fully separate from the company-side roles. Every route in the reseller workspace is gated by a dedicated middleware check against a named permission - for example, reseller.seats.view to see seat allocations, reseller.seats.manage to change them, and reseller.courses.manage to create and edit reseller courses. If a team member's role lacks the required permission, the request never reaches the page at all.
Three system roles ship out of the box. Reseller Admin holds every permission. Reseller Manager holds everything except API credential management and role management - a sensible default for day-to-day operators. Reseller Viewer holds only the view permissions across the workspace, ideal for account managers who need reporting visibility without change rights. Beyond these, resellers can create their own custom roles from the same grouped permission tree, which spans company management, seat management, user management, training content, the video library, phishing templates, branding, API access, team and role administration, reports, and billing.
Putting Scoped Access Into Practice
A practical rollout usually starts with three or four roles that mirror how the work is actually divided. An HR role gets training view and assign rights so onboarding and annual refreshers run without IT involvement. A security analyst role gets phishing view and manage rights plus reported email triage, so simulations and the report-button workflow stay with the security team. A finance role gets billing view and manage rights and nothing else. Department managers often need no special role at all - managing a department already unlocks the scoped My Departments view.
Because roles are editable at any time, you can tighten or extend access as your security awareness program matures. The audit story stays clean throughout: every user's reachable tabs and actions follow directly from the permissions attached to their role, which makes access reviews a matter of reading a short list instead of interviewing half the company.
Key Takeaways
- Custom roles let company admins delegate training, phishing, user, and finance tasks without handing out full admin access.
- Granular permissions separate viewing from managing in every area, from course assignment to billing changes.
- Capability filtering ensures a role can only grant permissions for features your subscription actually includes.
- The Permission Dashboard renders only the tabs a user's permissions allow - My Training, My Departments, Training, Phishing, Users, and Finance - and scopes data for department managers.
- Reseller teams get their own system with Reseller Admin, Manager, and Viewer roles plus custom roles, enforced on every single route.
- Auditors get clear answers: scoped access maps each person's rights directly to their actual responsibilities.


