Skip to content

Technicians and Access

WebWorkstation

Managers choose which technicians and organization users can work with which endpoints. Seeing the ZynoRMM tile is not enough—scope and authenticators still apply. Secure actions can also require a hardware-authenticator prompt.

Access types

Access typeWhat it allows
RMM managerManages technician access, organization users, enrollment tokens, tags, saved scripts, upgrades, and discovery policy within the RMM context.
TechnicianWorks with the endpoints that ZynoRMM grants to that technician.
Organization userWorks only within the organization or endpoint scope assigned to that user. It does not grant manager access.
Temporary shared accessGives a narrowly scoped, time-limited support capability where your RMM configuration offers it. It is not a full technician account.

Manage technicians and organization users

  1. Open ZynoRMM > Settings.
  2. Select Technicians to review or manage technician access, or Org Users to manage organization-scoped users.
  3. Confirm the intended organization and endpoint scope before approving, changing, or removing access.
  4. Ask the new technician to complete the requested device registration or hardware-authenticator steps.

Use My Devices to manage your own registered technician devices and authenticators. The ZynoRMM hardware-authenticator flow is separate from the passkey that may be used to sign in to ZynoSuite.

Remove or change access safely

Remove access promptly when a technician changes role, loses a device, or no longer supports an organization. Removing access blocks future secure RMM work; it does not erase historical audit records or endpoint history.

When changing an organization user's scope, verify the assigned organization rather than relying on a broad tenant role. A user who can open ZynoRMM may still be unable to view a particular endpoint, and that is expected when the endpoint lies outside the user's scope.

Common issues

ProblemWhat to check
A technician can open ZynoRMM but cannot see an endpointCheck the technician's organization or explicit endpoint scope and the endpoint's organization assignment.
A manager-only setting is missingConfirm that the active RMM context recognizes the user as a manager, not merely as an authorized technician.
A secure action asks for an authenticatorComplete the prompt with a registered technician device. This is separate from a normal ZynoSuite sign-in prompt.
A technician changed devicesUse My Devices or the manager approval workflow to register and authorize the replacement device before retiring the old one.
Access was removed but an old browser tab is still openRefresh or sign out. New secure actions should require current authorization.

Still need help?

Can’t find what you’re looking for? Our support team is happy to help.