Moorfox

Documentation

Users, permissions and guest accounts

Quick answer

Settings, Users is where you invite people and decide what each of them may do. There are three roles, Admin, Technician and Guest, and a role is only a starting point: open a user and you can tick or untick individual permissions, so a field technician can enrol machines without also being handed billing.

Anyone who is not an admin can also be limited to only assigned devices. That is what makes a guest account useful: a customer's office manager who can remote into their own three PCs and cannot see that the rest of your estate exists.

The Moorfox Users page listing five accounts with their role, how many devices each can see, two-factor status and buttons for Permissions, Send reset and Remove
The Users page. The Devices column says all, or how many grants a limited user holds.

The three roles

RoleStarts withMeant for
AdminEverything, always. An admin's boxes cannot be unticked; to take something away, change the role.The people who own the account: users, billing and organisation settings included.
TechnicianViewing and managing devices, remote desktop, the terminal and file tools, running saved commands, groups, alerts, a read-only view of patching, the activity log and QuickSupport.The people who do the work on machines every day.
GuestViewing devices and remote desktop, limited to assigned devices.Somebody outside your team who needs to reach their own machines and nothing else.

A user whose ticks no longer match their role's preset shows as Technician (custom) in the list, so you can see at a glance who has been given something extra or had something taken away.

Invite a user

  1. Open Settings, then Users, and press Invite user.
  2. Enter their email address and pick a role.
  3. Press Send invitation. They get a link at that address and choose their own password. Nothing is created until they use it, and the link stops working after a week.
The Invite user dialog with an email address filled in and the Guest role selected
Inviting a guest. You never choose or see their password.

Invitations that have not been used yet are listed under Invited, not yet joined, each with a Withdraw button that stops the link working. If your deployment cannot send email, the link is shown once for you to pass on yourself; only its hash is stored, so if it is lost, invite them again.

Permissions and device assignments are set once the person has joined, not on the invitation. A guest with nothing assigned sees nothing, so open them in the list as soon as they appear and pick their machines.

Change what one person can do

Press Permissions on a user's row. Choosing a role resets the boxes to that role's preset, and you can change them freely afterwards.

The permissions editor for a technician, with checkboxes grouped under Devices, Remote access, Operations and Organisation, and Add devices ticked in addition to the technician preset
A technician who can also add devices. Every permission says in plain words what it allows.

The permissions are grouped the way the dashboard is:

GroupWhat is in it
DevicesView devices; manage them (rename, group, tag, archive, restart and update the agent, scan for patches, run disk usage scans); add devices; roll out agent releases to a whole group; forget devices.
Remote accessRemote desktop; the terminal, file explorer, processes and services; running saved commands; editing the command library; flows; network isolation.
OperationsSeeing and resolving alerts; changing alert thresholds and routing; seeing patching; managing patching; the activity log; QuickSupport; managing groups; managing tags.
OrganisationManaging users; organisation settings; billing and EDR.

Two of them work as a pair. Run saved commands needs the terminal permission as well, because a saved command is a script running as SYSTEM or root, and a person who may not open a shell should not get one by another door.

The dashboard only offers what a person holds. Somebody without Add devices has no Add device button; somebody without Flows has no Flows page. This is a convenience, not the lock: the server checks the permission on every request, so knowing the address of a page gets nobody anywhere.

Limit someone to particular devices

At the bottom of the editor, tick Only assigned devices and pick what the person may see. It is on by default for guests and available for technicians, which is how you give a customer's own IT person a real technician account for their company and nobody else's.

The Only assigned devices section of the permissions editor, with the Northbay Dental group and two individual workstations ticked
One group and two loose machines. Everything else in the organisation is invisible to this person.
You can assignWhat it covers
A groupEvery device in it, now and later. Move a new machine into the group and the person can see it without you touching their account.
UngroupedEvery device that is not in a group, including newly enrolled ones.
Individual devicesExactly those machines. The filter box is there for when the list is long.

The editor will not let you save a limited user with nothing picked, because an account that sees nothing only generates a support call.

What a guest sees

A guest gets a much smaller dashboard: their devices and their own settings. No Manage section in the sidebar, no Add device button, no alerts, no activity log. On a device they can read its details and press Connect for remote desktop, with clipboard and chat. The terminal, file explorer, processes and services are not there.

The Moorfox dashboard as a guest sees it: a sidebar with only Devices and Settings, and a device list of three machines
The whole product, as a guest sees it. Three machines, one group, nothing else.

Rules that protect you from yourself

  • Only an admin can make an admin. Somebody holding Manage users can invite technicians and guests, and cannot edit or remove an admin.
  • Nobody can hand out a permission they do not hold. The boxes you cannot grant are greyed out.
  • A limited manager can only create limited users. If you can see one customer's machines, so can the people you invite, and no more.
  • The last admin cannot be demoted or removed, so the organisation always has a way back in.

Send reset on a user's row emails them a password reset code. They choose the new password themselves and nothing changes until they do. Remove ends their session immediately. All of it lands in the activity log under Administration.

Moorfox is remote monitoring and management without the enterprise tax.

One agent, one dashboard, remote desktop and a real terminal on every machine you look after.

Start free