Appearance
Technicians and Access
WebWorkstationManagers choose which technicians and organization users can work with which endpoints. Seeing the ZynoRMM tile is not enough—scope and authenticators still apply. Secure actions can also require a hardware-authenticator prompt.
Access types
| Access type | What it allows |
|---|---|
| RMM manager | Manages technician access, organization users, enrollment tokens, tags, saved scripts, upgrades, and discovery policy within the RMM context. |
| Technician | Works with the endpoints that ZynoRMM grants to that technician. |
| Organization user | Works only within the organization or endpoint scope assigned to that user. It does not grant manager access. |
| Temporary shared access | Gives a narrowly scoped, time-limited support capability where your RMM configuration offers it. It is not a full technician account. |
Manage technicians and organization users
- Open ZynoRMM > Settings.
- Select Technicians to review or manage technician access, or Org Users to manage organization-scoped users.
- Confirm the intended organization and endpoint scope before approving, changing, or removing access.
- Ask the new technician to complete the requested device registration or hardware-authenticator steps.
Use My Devices to manage your own registered technician devices and authenticators. The ZynoRMM hardware-authenticator flow is separate from the passkey that may be used to sign in to ZynoSuite.
Remove or change access safely
Remove access promptly when a technician changes role, loses a device, or no longer supports an organization. Removing access blocks future secure RMM work; it does not erase historical audit records or endpoint history.
When changing an organization user's scope, verify the assigned organization rather than relying on a broad tenant role. A user who can open ZynoRMM may still be unable to view a particular endpoint, and that is expected when the endpoint lies outside the user's scope.
Common issues
| Problem | What to check |
|---|---|
| A technician can open ZynoRMM but cannot see an endpoint | Check the technician's organization or explicit endpoint scope and the endpoint's organization assignment. |
| A manager-only setting is missing | Confirm that the active RMM context recognizes the user as a manager, not merely as an authorized technician. |
| A secure action asks for an authenticator | Complete the prompt with a registered technician device. This is separate from a normal ZynoSuite sign-in prompt. |
| A technician changed devices | Use My Devices or the manager approval workflow to register and authorize the replacement device before retiring the old one. |
| Access was removed but an old browser tab is still open | Refresh or sign out. New secure actions should require current authorization. |