Skip to main content
Getting Started

Portal navigation and roles

This page maps the portal: what each sidebar item is for, and what each role can actually do there. Keep it handy as a reference — every item links deeper into the relevant docs section.

Written By Christopher Scaminaci

Last updated 6 days ago

This page maps the portal: what each sidebar item is for, and what each role can actually do there. Keep it handy as a reference — every item links deeper into the relevant docs section.

The four roles

RoleWho it isIn short
Primary OwnerThe single account owner (exactly one per workspace)Everything, including billing and ownership changes. Billing contact for the account.
Co-ownerAdditional owners promoted by an ownerSame powers as the primary owner, including billing and ownership management.
AdministratorTrusted managersEverything except account billing, team-role changes, and ownership changes (cannot promote or demote anyone — including Administrator/Member flips — grant or remove co-owners, or transfer ownership). Can create and assign custom tool roles.
MemberEveryone elseUses AI assistants with their assigned tools; manages their own connector sign-ins. No management pages.

The tenant portal groups navigation by journey. What changes by role is what you can do on each page.

GroupNav itemPathWhat it's forWho can act
HomeDashboard/Workspace overview: usage, activity, endpoint. See the dashboard tour.Everyone views.
Get startedConnectors/connectorsConnect and manage supported MSP tools and upgrade or cancel connector plans; also hosts each member's personal per-user sign-ins.Owners, co-owners, and Administrators manage shared connectors. Everyone except the primary owner also gets a Your personal sign-ins section for their own per-user connections.
Get startedMCP Setup/endpointsYour MCP endpoint URLs (standard + compact), setup-guide links, AI client credentials, and a read-only Your AI connections view of your own AI sessions and authorized apps.Everyone views setup instructions and their own AI connections. Owners, co-owners, and Administrators create, rotate, and revoke credentials.
Access & TeamTeam/teamInvites, member roster, team roles, tool assignments, ownership, and per-member AI-connection management. Member and pending-invitation rows show their tool roles as chips and carry an Edit Roles action; the role definitions themselves live on the Roles page.Owners, co-owners, and Administrators manage members, roles, tools, and member AI connections. Team-role and ownership changes remain owner/co-owner only. Most team-management features require an active connector subscription.
Access & TeamRoles/rolesReusable tool bundles ("custom tool roles") that grant tools by rule — for example all read-only Halo tools — and keep pace with the catalog as new tools ship. Assign them to members, pending invitations, and MCP client credentials.Everyone can view the role list; owners, co-owners, and Administrators create, edit, and delete roles.
Access & TeamDirectory Sync/directory-syncConnect a Microsoft Entra directory once; StackJack then keeps the member list and their tool roles in step with the Entra groups you already manage. Read-only access to your directory — StackJack never writes to Entra.Owners, co-owners, and Administrators only — a plain member sees a Directory Sync Access Required notice instead of the page.
Billing & UsageBilling/billingConnector subscriptions, upgrades, Paddle and legacy billing links, usage, and credits.Primary owners and co-owners only. Administrators and Members see a billing-owner notice.
Billing & UsageAudit Logs/auditBrowse, filter, sort, and export connector tool-call metadata across your plan's display window.Everyone views; owners, co-owners, and Administrators get the full windowed browse and export, while Members get a read-only last-100 view.
MoreSettings/settingsPreferences that apply to your whole organization: the tool catalog defaults (whether catalog modes are on, the default catalog mode and the default pinned tools), the per-connector response-shaping rules, and, where your region asks for it, the fast-decisions consent. The old /response-shaping address forwards here.Everyone views the current values; owners, co-owners, and Administrators change them. Shown whether or not Automations is on.
MoreAutomations/automationsManaged AI agents that run on schedules and triggers.Shown for every workspace by default; hidden only if StackJack has suspended Automations for the account.
MoreDocumentationdocs.stackjack.io (opens in a new tab)The published StackJack product documentation — the whole public docs set, searchable, no account needed. See Finding help and documentation.Everyone.

Three former nav items no longer appear in the sidebar:

  • Permissions is now the API Permissions action on each connector card. The /permissions deep link still works and can pre-select a connector.
  • My Connectors is now the Your personal sign-ins section of Connectors. /my-connectors redirects to /connectors.
  • Connected Apps management moved to Team (expand a member row). /connected-apps redirects to /endpoints, where you get a read-only view of your own AI connections.

StackJack staff and partners can receive additional role-specific groups below the tenant groups; ordinary customer accounts do not see operator navigation.

The tenant sidebar as of an earlier release, grouped into Home, Get started, Access and Team, Billing and Usage, and More, with Automations selected — the current sidebar also lists Roles and Directory Sync under Access & Team, and Settings first under More
The customer-facing navigation groups for an Automations-enabled tenant. Operator-only groups and the account footer are intentionally excluded.

Header (every page)

ElementWhen it appearsWhat it does
Sidebar toggleAlwaysCollapses/expands the sidebar.
SupportWhile the support widget is switched on for the PortalOpens the support messenger — search the help center, open a ticket, and read replies. Carries a badge with the number of unread messages.
FeedbackSame condition as Support, beside itOpens the feature-request and voting board, which is a different surface from support. See Support versus Feedback.
Messenger launcher (corner of the page)Same condition as SupportThe same messenger, from the floating launcher rather than the header.
Finish setupWhile first-run setup is incompleteReopens the setup wizard.
Compass tour button ("Take a tour of this page")On pages that have a guided tourReplays that page's tour.
Help button ("Help for this page")On pages that have a matching documentation entryOpens that page's help article in a panel, with an Open full page link into Documentation.
  • Your name (from your sign-in identity).
  • Sign out — ends both the portal and identity session.
  • Reset Tours — replays all guided tours and, if setup is incomplete, lets the setup wizard auto-open again.
  • The portal build version.

Handy behaviors worth knowing

  • Support from anywhere: the Support button in the header opens the messenger on every page, and the corner launcher opens the same thing. Your tickets, their replies, and the help center all live inside it. See Getting Help.
  • Deep links: several pages accept links used throughout the product — for example, Connectors can open a specific connector's configuration dialog, /permissions can pre-select a connector, and the feature-gated Region page is available directly at /settings/region even though it has no sidebar item.
  • Restricted pages never hide silently: if your role can't act on a page, you get an explicit notice explaining who can, rather than an empty screen.