What’s in This Release
- Role-based access granted per client, with multiple roles per user
- Job Title and Department as required fields on every user profile
- Tenant-aware roles, with clearer rules about who can assign what
- Plans and Add-ons replacing feature toggles, plus a package inventory
Role-Based Access Granted Per Client
Multi-tenant teams rarely look the same across every client, and access now reflects that directly. Access is managed explicitly per client, so a single user can hold different roles across different clients, and more than one role within the same account. An analyst can have full visibility on one client and dashboard-only access on another, configured directly per client.
The Users table reflects that. It now shows every role a user holds and every client they can reach, so an access review can be handled from a single screen instead of reviewing each account separately. Terminology changed alongside it: what the platform called sub-accounts are now Clients, and the role and account labels around them have been aligned to match.
Least-privilege access can now be set per engagement, based on the access each engagement requires.
Why this matters
Access reviews are a recurring ask from your own clients and their auditors. A table that shows every role a user holds, per client, makes those access reviews faster and easier to answer consistently.
New Profile Fields and Tenant-Aware Role Assignment
Two changes make it easier to tell who is who once the same names appear across dozens of accounts. User profiles now carry Job Title and Department, and both are required when you create or edit a user, so records stay consistent rather than filling in over time. Roles are also displayed by tenant now, with each tenant showing only the roles that apply to it.
The assignment rules follow the same logic:
- Service Provider Admins can assign and manage client-level roles from the Service Provider account, without automatically gaining access to the client itself
- Service Provider roles can only be assigned from the Service Provider tenant, which keeps ownership clear and reduces misconfiguration at the client level
- Viewer permissions changed by partner request. Viewers can no longer download reports or CSV exports, and keep full read-only access to dashboards and on-screen data
Read-only stakeholders keep their existing on-screen access; only download permissions change.
Plans and Add-Ons Replace Feature Toggles
Feature access is now governed by Packages, structured as Plans, which every account has, and Add-ons, which are optional. The structure mirrors the contracts you actually sell, so what an account includes is legible without cross-referencing a separate agreement. Service Providers also get a package inventory reflecting their own contract with Cynomi, covering available plans, add-ons, and capacity.
Feature-level toggles have been removed entirely, and everything is now managed through Plans and Add-ons. Nothing was taken away in the change: accounts on the ongoing Pro plan have access to the full set of features included in that plan, including BIA and Business Continuity, Assets, Risk Management, and Solutions. The Clients table now shows feature usage and package coverage per account, so you can see consumption and approaching limits from the same place you manage the accounts.
Also in This Release
- Every account now requires an assigned Account Manager, making ownership explicit
- Two roles were renamed: Vendor Assessor is now Vendor Assessment Editor in third-party risk management, and Assessor is now Assessment Editor, the role for running assessments. Permissions are unchanged for both
- A new Content Manager role on the Service Provider tenant can edit task and policy SOPs and a task’s estimated effort
- The Assessor and Company Admin roles were removed from the Service Provider tenant. Users holding them keep their client access
What This Changes for Your Practice
Service providers are adding clients, users, and service lines faster than most internal processes were built for, and their own clients increasingly ask who can see what. Explicit per-client access, a least-privilege model by default, one table showing every role a user holds, and entitlements tied to the package an account sits on give you the governance and auditability to answer that at any size. It’s the kind of operational foundation Cynomi’s Security Growth Platform for MSPs and MSSPs is built on: the access model scales as your team and client base do.