Portal navigation and roles
This page maps the portal: what each sidebar item is for, and what each role can actually do there. Keep it handy as a reference — every item links deeper into the relevant docs section.
The four roles
| Role | Who it is | In short |
|---|---|---|
| Primary Owner | The single account owner (exactly one per workspace) | Everything, including billing and ownership changes. Billing contact for the account. |
| Co-owner | Additional owners promoted by an owner | Same powers as the primary owner, including billing and ownership management. |
| Administrator | Trusted managers | Everything except account billing, role changes, and ownership changes (cannot promote or demote anyone — including Administrator/Member flips — grant or remove co-owners, or transfer ownership). |
| Member | Everyone else | Uses AI assistants with their assigned tools; manages their own connector sign-ins. No management pages. |
Note: a few places in the portal still say "only the account owner can manage team access." That copy is out of date — co-owners and Administrators can manage team members too (invite, edit tool assignments, revoke and reactivate access), exactly as the table above describes. Only billing, member role changes (Administrator ↔ Member), and ownership actions are owner/co-owner exclusive.
Sidebar: the Platform group
All of these items are visible to every signed-in user — what changes by role is what you can do on each page.
| Nav item | Path | What it's for | Who can act |
|---|---|---|---|
| Dashboard | / |
Workspace overview: usage, activity, endpoint. See the dashboard tour. | Everyone views. |
| Connectors | /connectors |
Connect and manage the 34 MSP tools and upgrade or cancel connector plans; also hosts each member's personal per-user sign-ins. | Owners, co-owners, and Administrators manage the shared connectors. Everyone (except the primary owner) also gets a Your personal sign-ins section for their own per-user connections. |
| MCP Setup | /endpoints |
Your MCP endpoint URLs (standard + compact), a link to the per-tool setup guides, AI client credentials (MCP clients and API keys), and a read-only Your AI connections view of your own AI sessions and authorized apps. | Everyone views and copies setup instructions and sees their own AI connections. Creating/rotating/revoking credentials: owners, co-owners, Administrators. Managing other members' connections lives on the Team page. |
| Permissions | /permissions |
Interactive map of which vendor-side API permissions each tool needs — for scoping least-privilege API keys. | Everyone. |
| Billing | /billing |
Subscriptions, upgrades, invoices/portal links, usage. | Primary owner and co-owners only. Administrators and Members see a "billing is managed by the account owner" notice. |
| Audit Logs | /audit |
Browse, filter, sort, and export every connector tool call (metadata only) across your plan's display window. | Everyone views; the full windowed browse, filters, sort, and CSV export are for owners, co-owners, and Administrators. Members get a read-only last-100 view. |
| Team | /team |
Invites, member roster, roles, tool assignments, ownership, and per-member AI-connection management (member credentials, connected apps, AI sessions — expand a member's row). | Owners, co-owners, and Administrators manage members, tools, and each member's AI connections (invite, edit tools, revoke/reactivate, rotate/revoke member credentials, revoke/reinstate connected apps). Role changes (Administrator ↔ Member) and ownership actions (co-owner grant/removal, primary-ownership transfer) are owner/co-owner only. Requires at least one active connector subscription — configure a connector first. |
| Automations | /automations |
Managed AI agents that run on schedules and triggers. | Appears only when Automations is enabled for your workspace. Enablement is per-tenant by StackJack — contact StackJack support to request it. |
| Documentation | /docs |
The full StackJack product documentation, browsable and searchable inside the portal. See Finding help and documentation. | Everyone. StackJack staff additionally see internal operator pages. |
Two former nav items have been folded in and no longer appear in the sidebar: My Connectors is now the Your personal sign-ins section of the Connectors page, and Connected Apps management moved to the Team page (expand a member's row to manage their connected apps). Their old addresses (/my-connectors, /connected-apps) still work — they redirect to /connectors and /endpoints respectively; on /endpoints you get a read-only view of your own AI connections.
An Admin sidebar group exists below the Platform group, but it is visible only to StackJack staff — customers never see it.
The full sidebar with the Platform group expanded, for an owner on a tenant with Automations enabled
Header (every page)
| Element | When it appears | What it does |
|---|---|---|
| Sidebar toggle | Always | Collapses/expands the sidebar. |
| Support button (center) | Always | Opens the in-app support drawer; a pulsing dot shows unread replies from StackJack. |
| Finish setup | While first-run setup is incomplete | Reopens the setup wizard. |
| Tour button ("Take a tour of this page") | On pages that have a guided tour | Replays that page's tour. |
| Help button ("Help for this page") | On pages that have a matching documentation entry | Opens that page's help article in a panel, with an Open full page link into Documentation. |
Sidebar footer
- Your name (from your sign-in identity).
- Sign out — ends both the portal and identity session.
- Reset Tours — replays all guided tours and, if setup is incomplete, lets the setup wizard auto-open again.
- The portal build version.
Handy behaviors worth knowing
- Support from anywhere: the support drawer is reachable on every page, and opening a link with
?ticket=<id>in the URL (as StackJack's reply notifications do) opens the drawer straight to that ticket. - Deep links: several pages accept query links used throughout the product — e.g. the Connectors page can open a specific connector's configuration dialog directly, and the Permissions page can pre-select a connector.
- Restricted pages never hide silently: if your role can't act on a page, you get an explicit notice explaining who can, rather than an empty screen.