Overview
Trustifi includes several user and administrator roles that determine the level of access and permissions each user has within the platform. These roles allow organizations to delegate responsibilities across security, compliance, and administrative functions while maintaining proper oversight and control.
For transparency and auditing purposes, every action performed by admins or users with elevated permissions is logged in the Trustifi web portal under the Audit Log section of the relevant module.
This guide explains:
The different admin and user roles available in Trustifi
The permissions and access levels associated with each role
How each role can be assigned or configured
Admin Roles
Primary Admin
The Primary Admin is the main administrator of a Trustifi plan. Each Trustifi plan can have only one Primary Admin, and all users within the plan are associated with this account. This role is established during the initial onboarding process when the Trustifi plan is created.
Primary Admins have full read and write permissions across all Trustifi modules.
By default, both Primary Admins and Sub-Admins receive notifications related to:
New users joining the plan
Suspicious user activity
Triggered DLP or inbound security rules
Primary Admins can assign or revoke admin-level and reviewer-level permissions for other users. No other user can revoke permissions from the Primary Admin.
In the User Management page, the Primary Admin always appears at the top of the user list. Other users with admin privileges are listed as Sub-Admins.

To change the Primary Admin for a plan, contact Trustifi support at [email protected]
Sub-Admin
A Sub-Admin is a user who has been granted admin-level permissions by the Primary Admin.
Sub-Admins have the same level of access as the Primary Admin and can perform the same actions, with one exception: they cannot remove admin permissions from the Primary Admin.
To assign a Sub-Admin:
Open User Management under Outbound Management
Locate the user and click Actions
Select Modify Permissions

In the Plan Admin tab, enable Grant administrative permissions to user
.png)
Read-Only Admin
A Read-Only Admin can access all Trustifi management modules but cannot make changes or take actions.
To assign read-only admin access:
Follow the same steps used to grant admin permissions
In the Modify Permissions window, enable both:
Grant administrative permissions to user
Read-only permissions
.png)
Partner Admin
A Partner Admin is a specialized admin role used primarily by MSPs or resellers to manage multiple Trustifi client plans.
Partner Admins have access to the Multi-Tenant View, which allows them to search, view, and manage client accounts from a single interface.

Access to the Multi-Tenant View can be enabled or disabled for Sub-Admins using the Modify Permissions window under the Plan Admin tab.
.png)
Reviewers
Inbound Shield Reviewer
Inbound Shield Reviewers manage and monitor inbound email security. They have partial admin-level access under Inbound Management, including:
Inbound Shield
Allow/Block Lists
Quarantined Emails
URL Hunting
Threat Response
Audit Log
Inbound Shield Reviewers can configure inbound mail flow policies, manage allowlists and blocklists, review quarantined emails for all users and mailboxes, and release emails from quarantine.
They may also receive threat notifications when the Notify reviewer option is enabled under Threat Prevention Rules.
Assigning an Inbound Shield Reviewer
Assigning a user as an Inbound Shield reviewer can be done in 2 ways
Method 1: From the User Management Page
Navigate to Outbound Management → User Management
Locate the user and click Actions
Select Modify Permissions
Open the Plan Reviewer tab
Enable Set as Inbound Shield Reviewer
Method 2: From the Inbound Shield Configuration Page
Navigate to Inbound Management → Inbound Shield Reviewers
Click Add Reviewer
Enter the user’s email address, or select a user from the existing user list
.png)
Inbound Shield Reviewer Permission Settings
From this section, you may also configure these additional permission settings under the “Modify Permissions” action:
“View Content” - When enabled, the reviewer can view the content of quarantined emails.
“Release Malicious” - When enabled, the reviewer can release from quarantined emails that have been tagged as “Malicious“.
“Change Configuration” - When enabled, the reviewer can modify all Inbound Shield settings and access all pages and actions under “Inbound Management” (note: the “Threat Response'“ and “Trends & Insights” page have separate settings for reviewer access).
If this setting is disabled, the reviewer can only access the “Quarantined Emails” page and take actions that are available on that page - review and release emails, allowlist and blocklist senders, trust senders, remove emails from mailboxes, and change quarantined email categories.“Threat Response” - When enabled, the reviewer can Access the "Threat Response" page and use its functionality.
"Defang Malicious URLs” - When enabled, URLs identified as malicious will be disabled and made unclickable in "Threat Analysis” for this reviewer.
“Trends & Insights” - When enabled, the reviewer can Access the "Trends & Insights" page and use its functionality.
Outbound Reviewer
Outbound Reviewers manage outbound email security and compliance. They have admin-level access under Outbound Management, including:
Rules and Policies
Data Classification
Trends and Insights
Quarantined Emails
Reports
Email Trace
Audit Log
Outbound Reviewers receive notifications when emails are placed into outbound quarantine.
Assigning an Outbound Reviewer
Assigning a user as an outbound reviewer can be done in 2 ways:
Method 1: From the User Management page
Open the “User Management“ page under “Outbound Management“
Find the user in the “User Management” list and click on “Actions” next to the user
Click on “Modify Permissions” to open the permission management window
Click on the “Plan Reviewer” tab
Select “Set as Outbound Reviewer”

Method 2: From the outbound reviewers page
Navigate to the Outbound Reviewers Page
Click on the “Add Reviewer” button
Add the user’s email address
You can also click the arrow icon and select the option to add reviewers from your list of users

Outbound Reviewer Permission Settings
Viewing quarantined email content
Releasing emails from quarantine
Changing outbound configurations
Archive Reviewer
Archive Reviewers manage archived email data and cases. They have access to all pages under the Archive section.
They can create, view, share, and manage archive cases and access archive audit logs.
Assigning an Archive Reviewer
Assigning a user as an archive reviewer can be done in 2 ways
Method 1: From the User Management page
Open the “User Management“ page under “Outbound Management“
Find the user in the “User Management” list and click on “Actions” next to the user
Click on “Modify Permissions” to open the permission management window
Click on the “Plan Reviewer” tab
Select “Set as Archive Reviewer”

Method 2: From the archive configurations page
Navigate to the Archive Reviewers Page.
Click on the “Add Reviewer” button
Add the user’s email address
You can also click the arrow icon and select the option to add reviewers from your list of users

From this section, you can also toggle on or off the reviewer’s permissions to view the content of archived emails.
Threat Simulation Reviewer
Threat Simulation Reviewers manage phishing simulation campaigns and templates under the Threat Simulation section.
They can send and manage simulation campaigns, create and edit templates, and view trends and insights.
Assigning a Threat Simulation Reviewer
Assigning a user as a threat simulation reviewer can be done in 2 ways
Method 1: From the User Management page
Open the “User Management“ page under “Outbound Management“
Find the user in the “User Management” list and click on “Actions” next to the user
Click on “Modify Permissions” to open the permission management window
Click on the “Plan Reviewer” tab
Select “Set as Threat Simulation Reviewer”

Method 2: From the Threat Simulation reviewers page
Navigate to the Threat Simulation reviewers page
Click on the “Add Reviewer” button
Add the user’s email address
You can also click the arrow icon and select the option to add reviewers from your list of users

Account Takeover Reviewer
Account Takeover Reviewers monitor and respond to suspicious login activity under Account Takeover Protection.
They can manage policies, review suspicious events, take actions on affected users, and view trends and insights.
Assigning an Account Takeover Reviewer
Assigning a user as an account takeover reviewer can be done in 2 ways
Method 1: From the User Management page
Open the “User Management“ page under “Outbound Management. “
Find the user in the “User Management” list and click on “Actions” next to the user
Click on “Modify Permissions” to open the permission management window
Click on the “Plan Reviewer” tab
Select “Set as Account Takeover Reviewer”

Method 2: From the Account Takeover reviewers page
Navigate to the Account Takeover Reviewers Page
Click on the “Add Reviewer” button
Add the user’s email address
You can also click the arrow icon and select the option to add reviewers from your list of users

From this section, you can also toggle on or off the reviewer’s permissions to view the email content for Incidents
Partner Reviewer
Partner Reviewers have access to all pages under the Partners section of the Trustifi admin portal.
They can view usage statistics, generate reports, register deals, and access partner resources.
Assigning a Partner Reviewer
Assigning a partner reviewer can be done from the User Management page:
Open the “User Management“ page under “Outbound Management“
Find the user in the “User Management” list and click on “Actions” next to the user
Click on “Modify Permissions” to open the permission management window
Click on the “Plan Reviewer” tab
Select “Set as Partner Reviewer”

Global Reviewers
Global Reviewers can be assigned by Partner Admins who manage other Trustifi client plans. A Global Reviewer has admin-level read and write access for the clients they manage and for the module(s) they are assigned to.
When a user is assigned as a Global Reviewer, they receive access to the Multi-Tenant View, which allows them to access and manage Trustifi plans for the partner’s managed clients. For some modules, the Partner Admin can apply limitations to a Global Reviewer’s permissions.
Assigning a Global Reviewer
Assigning a global reviewer can be done from the User Management page:
Open the “User Management“ page under “Outbound Management“
Find the user in the “User Management” list and click on “Actions” next to the user
Click on “Modify Permissions” to open the permission management window
Click on the “Global Reviewer” tab
Select which modules the user should be assigned as a global reviewer for

Global Inbound Reviewer
A Global Inbound Reviewer has access to all pages and tabs under Inbound Management for client plans managed by the partner/MSP. Global inbound reviewers can review and release client quarantined emails, manage allowlists and blocklists, and manage settings related to Inbound Shield.
Assigning a Global Inbound Reviewer
In the “Global Reviewer” tab, select “Set as Inbound Shield Reviewer.”

Permission Restrictions for Global Inbound Reviewers
When assigning a Global Inbound Reviewer, you can set the following limitations:
Allow this reviewer to release malicious emails
If enabled, the reviewer can release all quarantined emails. If disabled, the reviewer can release all quarantined emails except those categorized as malicious.Allow this reviewer to view quarantined email content
If enabled, the reviewer can view the content and attachments of client quarantined emails.Allow this reviewer to change configurations and settings
If enabled, the reviewer can change Inbound Shield configuration settings. If disabled, the reviewer can only review and release emails in quarantine.
Global Outbound Reviewer
A Global Outbound Reviewer has access to all pages and tabs under Outbound Management for client plans managed by the partner/MSP. Global outbound reviewers can add and manage users, create and edit DLP rules and policies, and view outbound email reporting.
Assigning a Global Outbound Reviewer
In the “Global Reviewer” tab, select “Set as Outbound Reviewer“.

Permission Restrictions for Global Outbound Reviewers
When assigning a Global Outbound Reviewer, you can set the following limitations:
Allow this reviewer to view the content of quarantined emails
If enabled, the reviewer can view the content and attachments of users’ quarantined emails.Allow this reviewer to change configurations and settings
If enabled, the reviewer can change outbound configuration settings. If disabled, the reviewer can only review and release emails in quarantine.
Global Archive Reviewer
A Global Archive Reviewer has access to all pages and tabs under Archive for client plans managed by the partner/MSP. Global archive reviewers can create, view, share, and manage archive cases and access the audit log for that section.
Assigning a Global Archive Reviewer
In the “Global Reviewer” tab, select “Set as Archive Reviewer“.

Permission Restrictions for Global Archive Reviewers
When assigning a Global Archive Reviewer, you can set the following limitation:
Allow this reviewer to view archived email content
If enabled, the reviewer can view the content and attachments of client archived emails.
Global Threat Simulation Reviewer
A Global Threat Simulation Reviewer has access to all pages and tabs under Threat Simulation for client plans managed by the partner/MSP. Global threat simulation reviewers can send and view simulation campaigns, create and edit templates, and view trends and insights.
Assigning a Global Threat Simulation Reviewer
In the “Global Reviewer” tab, select “Set as Threat Simulation Reviewer“.

Global Account Takeover Reviewer
A Global Account Takeover Reviewer has access to all pages and tabs under Account Takeover Protection for client plans managed by the partner/MSP. Global account takeover reviewers can manage policies, review suspicious events, take actions on users, and view Trends and Insights.
Assigning a Global Account Takeover Reviewer
In the “Global Reviewer” tab, select “Set as Account Takeover Reviewer“.

User Roles
End-Users
End-users have no control over rules or policies that affect other users. In the Trustifi web portal, users can perform the following actions:
Send secure emails
Manage their own contacts and templates
Manage their own secure attachments
Note: Access to the items above can be blocked by the admin. If you wish to block users from performing these actions, please contact Trustifi support.
View their own quarantined emails. Under default settings, users cannot release their own quarantined emails. This can be allowed by admins or reviewers by selecting “Allow recipient control” for a specific type of emails under “Threat Prevention Rules”, or by assigning a user to be a personal reviewer (detailed further in this guide).
View and manage their personal allowlists and blocklists
Personal Reviewer
A Personal Reviewer is a standard user who can review and release their own quarantined emails only. They cannot review emails for other users or modify inbound or outbound policies.
Assigning a Personal Reviewer
Navigate to Inbound Management → Mailbox Management
Locate the user’s mailbox and click Actions
Select Edit Personal Reviewer
Choose whether the user may release malicious emails
Click OK to confirm
.png)
Blocking users
Admins may block users if compromise, misuse, or policy violations are suspected.
Blocking a User
Navigate to Outbound Management → User Management
Locate the user and click Actions
Select Block User

When a user is blocked:
They cannot log in to Trustifi
They cannot send emails through Trustifi
Previously sent encrypted emails, attachments, and links become inaccessible
Users can be unblocked at any time by selecting Unblock User, which restores access.
Outbound and inbound user licenses
Trustifi supports inbound-only, outbound-only, or full-suite deployments.
Outbound users are managed under User Management
Inbound users (mailboxes) are managed under Mailbox Management
When inbound or outbound Email Relay is enabled, Trustifi users are created automatically as emails are sent or received.
.png)