Documentation Index

Fetch the complete documentation index at: https://docs.trustifi.com/llms.txt

Use this file to discover all available pages before exploring further.

Admin and User Roles in Trustifi

Prev Next

Overview

Trustifi includes several user and administrator roles that determine the level of access and permissions each user has within the platform. These roles allow organizations to delegate responsibilities across security, compliance, and administrative functions while maintaining proper oversight and control.

For transparency and auditing purposes, every action performed by admins or users with elevated permissions is logged in the Trustifi web portal under the Audit Log section of the relevant module.

This guide explains:

  • The different admin and user roles available in Trustifi

  • The permissions and access levels associated with each role

  • How each role can be assigned or configured


Admin Roles

Primary Admin

The Primary Admin is the main administrator of a Trustifi plan. Each Trustifi plan can have only one Primary Admin, and all users within the plan are associated with this account. This role is established during the initial onboarding process when the Trustifi plan is created.

Primary Admins have full read and write permissions across all Trustifi modules.

By default, both Primary Admins and Sub-Admins receive notifications related to:

  • New users joining the plan

  • Suspicious user activity

  • Triggered DLP or inbound security rules

Primary Admins can assign or revoke admin-level and reviewer-level permissions for other users. No other user can revoke permissions from the Primary Admin.

In the User Management page, the Primary Admin always appears at the top of the user list. Other users with admin privileges are listed as Sub-Admins.


To change the Primary Admin for a plan, contact Trustifi support at [email protected]

Sub-Admin

A Sub-Admin is a user who has been granted admin-level permissions by the Primary Admin.

Sub-Admins have the same level of access as the Primary Admin and can perform the same actions, with one exception: they cannot remove admin permissions from the Primary Admin.

To assign a Sub-Admin:

  1. Open User Management under Outbound Management

  2. Locate the user and click Actions

  3. Select Modify Permissions


  1. In the Plan Admin tab, enable Grant administrative permissions to user

Read-Only Admin

A Read-Only Admin can access all Trustifi management modules but cannot make changes or take actions.

To assign read-only admin access:

  • Follow the same steps used to grant admin permissions

  • In the Modify Permissions window, enable both:

    • Grant administrative permissions to user

    • Read-only permissions

Partner Admin

A Partner Admin is a specialized admin role used primarily by MSPs or resellers to manage multiple Trustifi client plans.

Partner Admins have access to the Multi-Tenant View, which allows them to search, view, and manage client accounts from a single interface.

Access to the Multi-Tenant View can be enabled or disabled for Sub-Admins using the Modify Permissions window under the Plan Admin tab.


Reviewers

Inbound Shield Reviewer

Inbound Shield Reviewers manage and monitor inbound email security. They have partial admin-level access under Inbound Management, including:

  • Inbound Shield

  • Allow/Block Lists

  • Quarantined Emails

  • URL Hunting

  • Threat Response

  • Audit Log

Inbound Shield Reviewers can configure inbound mail flow policies, manage allowlists and blocklists, review quarantined emails for all users and mailboxes, and release emails from quarantine.

They may also receive threat notifications when the Notify reviewer option is enabled under Threat Prevention Rules.

Assigning an Inbound Shield Reviewer

Assigning a user as an Inbound Shield reviewer can be done in 2 ways

Method 1: From the User Management Page

  1. Navigate to Outbound ManagementUser Management

  2. Locate the user and click Actions

  3. Select Modify Permissions

  4. Open the Plan Reviewer tab

  5. Enable Set as Inbound Shield Reviewer

Method 2: From the Inbound Shield Configuration Page

  1. Navigate to Inbound Management → Inbound Shield Reviewers

  2. Click Add Reviewer

  3. Enter the user’s email address, or select a user from the existing user list

Inbound Shield Reviewer Permission Settings

From this section, you may also configure these additional permission settings under the “Modify Permissions” action:

  • “View Content” - When enabled, the reviewer can view the content of quarantined emails.

  • “Release Malicious” - When enabled, the reviewer can release from quarantined emails that have been tagged as “Malicious“.

  • “Change Configuration” - When enabled, the reviewer can modify all Inbound Shield settings and access all pages and actions under “Inbound Management” (note: the “Threat Response'“ and “Trends & Insights” page have separate settings for reviewer access).
    If this setting is disabled, the reviewer can only access the “Quarantined Emails” page and take actions that are available on that page - review and release emails, allowlist and blocklist senders, trust senders, remove emails from mailboxes, and change quarantined email categories.

  • Threat Response” - When enabled, the reviewer can Access the "Threat Response" page and use its functionality.

  • "Defang Malicious URLs” - When enabled, URLs identified as malicious will be disabled and made unclickable in "Threat Analysis” for this reviewer.

  • Trends & Insights” - When enabled, the reviewer can Access the "Trends & Insights" page and use its functionality.

Outbound Reviewer

Outbound Reviewers manage outbound email security and compliance. They have admin-level access under Outbound Management, including:

  • Rules and Policies

  • Data Classification

  • Trends and Insights

  • Quarantined Emails

  • Reports

  • Email Trace

  • Audit Log

Outbound Reviewers receive notifications when emails are placed into outbound quarantine.

Assigning an Outbound Reviewer

Assigning a user as an outbound reviewer can be done in 2 ways:

Method 1: From the User Management page

  1. Open the User Management page under “Outbound Management

  2. Find the user in the “User Management” list and click on “Actions” next to the user

  3. Click on “Modify Permissions” to open the permission management window

  4. Click on the “Plan Reviewer” tab

  5. Select “Set as Outbound Reviewer”

Method 2: From the outbound reviewers page

  1. Navigate to the Outbound Reviewers Page

  2. Click on the “Add Reviewer” button

  3. Add the user’s email address

  4. You can also click the arrow icon and select the option to add reviewers from your list of users


Outbound Reviewer Permission Settings

  • Viewing quarantined email content

  • Releasing emails from quarantine

  • Changing outbound configurations

Archive Reviewer

Archive Reviewers manage archived email data and cases. They have access to all pages under the Archive section.

They can create, view, share, and manage archive cases and access archive audit logs.

Assigning an Archive Reviewer

Assigning a user as an archive reviewer can be done in 2 ways

Method 1: From the User Management page

  1. Open the User Management page under “Outbound Management

  2. Find the user in the “User Management” list and click on “Actions” next to the user

  3. Click on “Modify Permissions” to open the permission management window

  4. Click on the “Plan Reviewer” tab

  5. Select “Set as Archive Reviewer”


Method 2: From the archive configurations page

  1. Navigate to the Archive Reviewers Page.

  2. Click on the “Add Reviewer” button

  3. Add the user’s email address

  4. You can also click the arrow icon and select the option to add reviewers from your list of users

From this section, you can also toggle on or off the reviewer’s permissions to view the content of archived emails.


Threat Simulation Reviewer

Threat Simulation Reviewers manage phishing simulation campaigns and templates under the Threat Simulation section.

They can send and manage simulation campaigns, create and edit templates, and view trends and insights.

Assigning a Threat Simulation Reviewer

Assigning a user as a threat simulation reviewer can be done in 2 ways

Method 1: From the User Management page

  1. Open the User Management page under “Outbound Management

  2. Find the user in the “User Management” list and click on “Actions” next to the user

  3. Click on “Modify Permissions” to open the permission management window

  4. Click on the “Plan Reviewer” tab

  5. Select “Set as Threat Simulation Reviewer”


Method 2: From the Threat Simulation reviewers page

  1. Navigate to the Threat Simulation reviewers page

  2. Click on the “Add Reviewer” button

  3. Add the user’s email address

  4. You can also click the arrow icon and select the option to add reviewers from your list of users

Account Takeover Reviewer

Account Takeover Reviewers monitor and respond to suspicious login activity under Account Takeover Protection.

They can manage policies, review suspicious events, take actions on affected users, and view trends and insights.

Assigning an Account Takeover Reviewer

Assigning a user as an account takeover reviewer can be done in 2 ways

Method 1: From the User Management page

  1. Open the User Management page under “Outbound Management. “    

  2. Find the user in the “User Management” list and click on “Actions” next to the user

  3. Click on “Modify Permissions” to open the permission management window

  4. Click on the “Plan Reviewer” tab

  5. Select “Set as Account Takeover Reviewer”


Method 2: From the Account Takeover reviewers page

  1. Navigate to the Account Takeover Reviewers Page

  2. Click on the “Add Reviewer” button

  3. Add the user’s email address

  4. You can also click the arrow icon and select the option to add reviewers from your list of users

From this section, you can also toggle on or off the reviewer’s permissions to view the email content for Incidents

Partner Reviewer

Partner Reviewers have access to all pages under the Partners section of the Trustifi admin portal.

They can view usage statistics, generate reports, register deals, and access partner resources.

Assigning a Partner Reviewer

Assigning a partner reviewer can be done from the User Management page:

  1. Open the User Management page under “Outbound Management

  2. Find the user in the “User Management” list and click on “Actions” next to the user

  3. Click on “Modify Permissions” to open the permission management window

  4. Click on the “Plan Reviewer” tab

  5. Select “Set as Partner Reviewer”

Global Reviewers

Global Reviewers can be assigned by Partner Admins who manage other Trustifi client plans. A Global Reviewer has admin-level read and write access for the clients they manage and for the module(s) they are assigned to.

When a user is assigned as a Global Reviewer, they receive access to the Multi-Tenant View, which allows them to access and manage Trustifi plans for the partner’s managed clients. For some modules, the Partner Admin can apply limitations to a Global Reviewer’s permissions.

Assigning a Global Reviewer

Assigning a global reviewer can be done from the User Management page:

  1. Open the User Management page under “Outbound Management

  2. Find the user in the “User Management” list and click on “Actions” next to the user

  3. Click on “Modify Permissions” to open the permission management window

  4. Click on the “Global Reviewer” tab

  5. Select which modules the user should be assigned as a global reviewer for

  

Global Inbound Reviewer

A Global Inbound Reviewer has access to all pages and tabs under Inbound Management for client plans managed by the partner/MSP. Global inbound reviewers can review and release client quarantined emails, manage allowlists and blocklists, and manage settings related to Inbound Shield.

Assigning a Global Inbound Reviewer

In the “Global Reviewer” tab, select “Set as Inbound Shield Reviewer.

Permission Restrictions for Global Inbound Reviewers

When assigning a Global Inbound Reviewer, you can set the following limitations:

  • Allow this reviewer to release malicious emails
    If enabled, the reviewer can release all quarantined emails. If disabled, the reviewer can release all quarantined emails except those categorized as malicious.

  • Allow this reviewer to view quarantined email content
    If enabled, the reviewer can view the content and attachments of client quarantined emails.

  • Allow this reviewer to change configurations and settings
    If enabled, the reviewer can change Inbound Shield configuration settings. If disabled, the reviewer can only review and release emails in quarantine.

Global Outbound Reviewer

A Global Outbound Reviewer has access to all pages and tabs under Outbound Management for client plans managed by the partner/MSP. Global outbound reviewers can add and manage users, create and edit DLP rules and policies, and view outbound email reporting.

Assigning a Global Outbound Reviewer

In the “Global Reviewer” tab, select “Set as Outbound Reviewer“.

Permission Restrictions for Global Outbound Reviewers

When assigning a Global Outbound Reviewer, you can set the following limitations:

  • Allow this reviewer to view the content of quarantined emails
    If enabled, the reviewer can view the content and attachments of users’ quarantined emails.

  • Allow this reviewer to change configurations and settings
    If enabled, the reviewer can change outbound configuration settings. If disabled, the reviewer can only review and release emails in quarantine.

Global Archive Reviewer

A Global Archive Reviewer has access to all pages and tabs under Archive for client plans managed by the partner/MSP. Global archive reviewers can create, view, share, and manage archive cases and access the audit log for that section.

Assigning a Global Archive Reviewer

In the “Global Reviewer” tab, select “Set as Archive Reviewer“.

Permission Restrictions for Global Archive Reviewers

When assigning a Global Archive Reviewer, you can set the following limitation:

  • Allow this reviewer to view archived email content
    If enabled, the reviewer can view the content and attachments of client archived emails.

Global Threat Simulation Reviewer

A Global Threat Simulation Reviewer has access to all pages and tabs under Threat Simulation for client plans managed by the partner/MSP. Global threat simulation reviewers can send and view simulation campaigns, create and edit templates, and view trends and insights.

Assigning a Global Threat Simulation Reviewer

In the “Global Reviewer” tab, select “Set as Threat Simulation Reviewer“.

Global Account Takeover Reviewer

A Global Account Takeover Reviewer has access to all pages and tabs under Account Takeover Protection for client plans managed by the partner/MSP. Global account takeover reviewers can manage policies, review suspicious events, take actions on users, and view Trends and Insights.

Assigning a Global Account Takeover Reviewer

In the “Global Reviewer” tab, select “Set as Account Takeover Reviewer“.


User Roles

End-Users

End-users have no control over rules or policies that affect other users. In the Trustifi web portal, users can perform the following actions:

  • Send secure emails

  • Manage their own contacts and templates

  • Manage their own secure attachments

Note: Access to the items above can be blocked by the admin. If you wish to block users from performing these actions, please contact Trustifi support.

  • View their own quarantined emails. Under default settings, users cannot release their own quarantined emails. This can be allowed by admins or reviewers by selecting “Allow recipient control” for a specific type of emails under “Threat Prevention Rules”, or by assigning a user to be a personal reviewer (detailed further in this guide).

  • View and manage their personal allowlists and blocklists

Personal Reviewer

A Personal Reviewer is a standard user who can review and release their own quarantined emails only. They cannot review emails for other users or modify inbound or outbound policies.

Assigning a Personal Reviewer

  1. Navigate to Inbound Management → Mailbox Management

  2. Locate the user’s mailbox and click Actions

  3. Select Edit Personal Reviewer

  4. Choose whether the user may release malicious emails

  5. Click OK to confirm

Blocking users

Admins may block users if compromise, misuse, or policy violations are suspected.

Blocking a User

  1. Navigate to Outbound ManagementUser Management

  2. Locate the user and click Actions

  3. Select Block User

When a user is blocked:

  • They cannot log in to Trustifi

  • They cannot send emails through Trustifi

  • Previously sent encrypted emails, attachments, and links become inaccessible

Users can be unblocked at any time by selecting Unblock User, which restores access.

Outbound and inbound user licenses

Trustifi supports inbound-only, outbound-only, or full-suite deployments.

  • Outbound users are managed under User Management

  • Inbound users (mailboxes) are managed under Mailbox Management

When inbound or outbound Email Relay is enabled, Trustifi users are created automatically as emails are sent or received.