Team roles and what each role can do
Every person on your StackJack team has a role, and the role decides which parts of the account they can manage. This page is the definitive capability matrix — use it whenever you're deciding what…
Written By Christopher Scaminaci
Last updated 6 days ago
Every person on your StackJack team has a role, and the role decides which parts of the account they can manage. This page is the definitive capability matrix — use it whenever you're deciding what role to give a teammate.
The four roles
The portal presents four customer-facing roles, although the primary owner and co-owners share the stored Owner role. The primary-owner designation identifies the one account anchor; it does not reduce a co-owner's day-to-day owner permissions.
Capability matrix
Three rules worth memorizing:
- An owner is never restricted by their own member record. An owner's portal or browser sign-in resolves to every tool, and the Team page shows no Edit Tools button on an owner's row. A Client ID + Secret connection is a separate question: it serves exactly what that credential is scoped to on MCP Setup, even for an owner.
- Tool restrictions do apply to Administrators, not only to Members. An owner scopes either one the same way. To narrow somebody who holds a custom tool role, change the role with Edit Roles — the tools button only adds extras on top of what their roles grant. An Administrator promoted from an unrestricted member keeps unrestricted tools until someone edits them.
- Ownership, account billing, and region-migration initiation are owner-only. Administrators can manage individual connector subscriptions from Connectors, but cannot view the owner Billing details, change ownership, or start a region move.
Where roles appear in the portal
Team-role badges live on the Team page, under the Access & Team group in the left sidebar — its siblings there are Roles (custom tool roles) and Directory Sync:
- Each member row shows a role badge — Owner, Administrator, or Member.
- An "Understanding team roles" legend card on the same page summarizes what each role can do.

Roles vs. tool assignments
Roles and tool assignments are separate dials:
- A role controls what someone can do in the portal (manage connectors, billing, the team).
- A tool assignment controls what a Member's or Administrator's AI assistant can do through StackJack (which connector tools their agent may call). Owners cannot be tool-restricted through their member record.
For example, a Member with only HaloPSA read tools assigned can ask their AI assistant about Halo tickets but cannot see billing, change connectors, or call any other connector's tools. Changing a Member's tools is covered in Managing members.
A custom role is a third thing again, and the naming overlap is worth pinning down: it is a reusable bundle of tools you build once and reuse for as many people as you like — attached one at a time with Edit Roles on a member's Team row, a pending invitation, or an MCP endpoint — so you stop hand-picking a list per person. It grants no portal permissions at all. See Custom roles. If your organization runs Microsoft Entra, Directory sync can assign those custom roles from the Entra groups you already maintain, instead of assigning them here one person at a time.
Choosing the right role
- Give Administrator to anyone who runs your MSP tooling day to day but shouldn't control payment or ownership.
- Reserve Co-owner for people who genuinely need billing and ownership powers — it is full control, including the ability to remove other owners.
- Keep everyone else a Member with a scoped tool assignment.
Next steps
More in Team & Access
Self-registration and approving new membersManaging members: tools, roles, suspension, and reactivationCo-owners and transferring primary ownershipSetting up members with their own connector credentialsStill need help? Ask the team