Release 3.28.0

Per-Client User Roles and a New Package Structure

As your security practice grows, managing who can access what across clients gets harder with one-size-fits-all permissions. This release moves Cynomi to explicit, per-client access control, along with a new Plans and Add-ons structure for managing feature entitlements. The result is clearer visibility into who can do what, and how each account's package aligns with what they're entitled to.

Packages

What’s in This Release

  • Role-based access granted per client, with multiple roles per user
  • Job Title and Department as required fields on every user profile
  • Tenant-aware roles, with clearer rules about who can assign what
  • Plans and Add-ons replacing feature toggles, plus a package inventory

Role-Based Access Granted Per Client

Multi-tenant teams rarely look the same across every client, and access now reflects that directly. Access is managed explicitly per client, so a single user can hold different roles across different clients, and more than one role within the same account. An analyst can have full visibility on one client and dashboard-only access on another, configured directly per client.

The Users table reflects that. It now shows every role a user holds and every client they can reach, so an access review can be handled from a single screen instead of reviewing each account separately. Terminology changed alongside it: what the platform called sub-accounts are now Clients, and the role and account labels around them have been aligned to match.

Least-privilege access can now be set per engagement, based on the access each engagement requires.

Why this matters

Access reviews are a recurring ask from your own clients and their auditors. A table that shows every role a user holds, per client, makes those access reviews faster and easier to answer consistently.

New Profile Fields and Tenant-Aware Role Assignment

Two changes make it easier to tell who is who once the same names appear across dozens of accounts. User profiles now carry Job Title and Department, and both are required when you create or edit a user, so records stay consistent rather than filling in over time. Roles are also displayed by tenant now, with each tenant showing only the roles that apply to it.

The assignment rules follow the same logic:

  • Service Provider Admins can assign and manage client-level roles from the Service Provider account, without automatically gaining access to the client itself
  • Service Provider roles can only be assigned from the Service Provider tenant, which keeps ownership clear and reduces misconfiguration at the client level
  • Viewer permissions changed by partner request. Viewers can no longer download reports or CSV exports, and keep full read-only access to dashboards and on-screen data

Read-only stakeholders keep their existing on-screen access; only download permissions change.

Plans and Add-Ons Replace Feature Toggles

Feature access is now governed by Packages, structured as Plans, which every account has, and Add-ons, which are optional. The structure mirrors the contracts you actually sell, so what an account includes is legible without cross-referencing a separate agreement. Service Providers also get a package inventory reflecting their own contract with Cynomi, covering available plans, add-ons, and capacity.

Feature-level toggles have been removed entirely, and everything is now managed through Plans and Add-ons. Nothing was taken away in the change: accounts on the ongoing Pro plan have access to the full set of features included in that plan, including BIA and Business Continuity, Assets, Risk Management, and Solutions. The Clients table now shows feature usage and package coverage per account, so you can see consumption and approaching limits from the same place you manage the accounts.

Also in This Release

  • Every account now requires an assigned Account Manager, making ownership explicit
  • Two roles were renamed: Vendor Assessor is now Vendor Assessment Editor in third-party risk management, and Assessor is now Assessment Editor, the role for running assessments. Permissions are unchanged for both
  • A new Content Manager role on the Service Provider tenant can edit task and policy SOPs and a task’s estimated effort
  • The Assessor and Company Admin roles were removed from the Service Provider tenant. Users holding them keep their client access

What This Changes for Your Practice

Service providers are adding clients, users, and service lines faster than most internal processes were built for, and their own clients increasingly ask who can see what. Explicit per-client access, a least-privilege model by default, one table showing every role a user holds, and entitlements tied to the package an account sits on give you the governance and auditability to answer that at any size. It’s the kind of operational foundation Cynomi’s Security Growth Platform for MSPs and MSSPs is built on: the access model scales as your team and client base do.

Frequently Asked Questions

What happened to sub-accounts?

Sub-accounts are now called Clients. The related role and account labels were aligned to match, so the terminology is consistent across the platform.

Can one user hold more than one role?

Yes. A user can hold different roles across different clients, and more than one role within the same account. The Users table shows every role a user holds and the clients they can access.

What changed for the Viewer role?

Viewers can no longer download reports or CSV exports. They keep full read-only access to dashboards and on-screen data. The change was made based on partner feedback.

Can a Service Provider Admin manage client roles without accessing the client?

Yes. Service Provider Admins can assign and manage client-level roles from the Service Provider account without automatically gaining access to the client itself. Service Provider roles can only be assigned from the Service Provider tenant.

Does moving to Plans and Add-ons remove any capability?

No. There is no reduction in capability as part of the change. Accounts on the ongoing Pro plan have access to the full set of features included in that plan, including Business Continuity, Assets, Risk Management, and Solutions.

Which Cynomi release do these changes ship in?

Release 3.28.0, March 2026. It covers user management and role-based access control, account management, and packaging.

The Security Growth Platform
for Service Providers

Discover how Cynomi can help you standardize delivery, accelerate onboarding, and scale your CISO advisory services.