Technical · Course T8Lesson 4 of 4
Your team, permissions, and the honest edges
7 min read- Add partner staff with correctly scoped roles and permissions
- Match the reseller role family to real job functions
- State accurately what the console does today — including where billing and white-label actually live
The last piece of partner operations is the least glamorous and the most consequential as you grow: who on your team can do what — and knowing precisely where the product's edges are.
Roles & Permissions
The Roles & Permissions area manages your partner org's own users. Each is created with an email and a role, and the list is searchable and sortable by both.
The reseller role family maps to real jobs:
| Role | Fits |
|---|---|
| Reseller Admin | Your operations lead — full partner-console capability |
| Reseller Customer Admin | Staff who administer assigned customer accounts |
| Reseller Observer | Read-only staff — support, reporting, new hires in training |
Above them sit distributor and distributor admin for multi-tier channels;
below, each customer tenant has its own customer_admin, group_admin, and
observer roles that you help staff.
Permissions are more granular than role names suggest — capabilities break down into View, Create, Update, Delete, plus Account Admin and Observer designations, so you can shape access precisely rather than handing out admin because it's easier.
Three of these actions are themselves gated for your org: adding or updating a reseller user, deleting one, and changing permissions. If your console lacks them, that's your partner configuration.
The practical guidance: default new staff to Observer, promote deliberately, and reserve deletion and permission-change rights for one or two people. A partner org with five admins has five ways to accidentally reconfigure a customer's console.
Your own settings
The reseller Settings page covers your account's security settings — it's about protecting your own login, not configuring customers. Customer configuration lives in the customer's console and in the plans and templates you assign.
The honest edges
Two things partners routinely over-promise. Get them right and you'll never be caught out mid-deployment.
Billing. The reseller console has a Billing area, but its functionality is still under development — the screen itself says invoices, payment methods, and billing information are coming. Today, billing runs through your WeGuard account team. Say that plainly. A customer told "you'll see invoices in our portal next week" who then can't is a trust problem you don't need, especially when the honest version — "billing runs through our account team today; self-serve invoicing is on the roadmap" — costs you nothing.
White-label. Branding is real but narrower than the phrase suggests: the platform supports uploading a dashboard logo and a favicon that apply to the console your customer logs into, configured in the customer console under Settings → Advanced and stored against their account (uploads are audit-logged). It is not a reseller-portal screen, and it is not a full theming system. Setup is coordinated with your WeGuard account team. Pitch it as "your logo on the console your customers use" — which is genuinely valuable to MSPs and telcos — and let the account team scope anything deeper.
Where this leaves you
You can now create a customer tenant, place it correctly in the channel hierarchy, gate its console with a plan, seed it with proven policy templates, staff it with appropriately-scoped users on both sides, and describe the platform's edges honestly. That's the full partner operating loop — and passing this exam completes the Technical track.