What is permissions management?
Permissions management is the ongoing work of deciding who can reach each application and file, and at what level, then keeping that current as staff come and go. For a small business that usually means groups in Microsoft 365 or Google Workspace, plus the permission level each person holds in every business app. Shared passwords belong in a password manager, where they can be handed over and changed safely.
How does onboarding a new employee work with NetSys?
You send us the new hire's role and start date. We create the account from the matching role template, assign the license, add the person to the right groups, send the app invitations and share the Keeper folders the role uses. Before the start date we check that every sign-in works and send first-day instructions.
What is a role template?
A role template lists what one position needs: the groups and shared folders it opens, and each application with its permission level, including the shared passwords the role uses in Keeper. You agree it with us once. Every new hire in that role starts with the same access, and when the template changes we update everyone in the role.
Can you manage permissions in Google Workspace as well as Microsoft 365?
Yes. In Google Workspace we manage users, groups, shared drive roles and admin roles. In Microsoft 365 we manage Entra ID groups, SharePoint and Teams access, admin roles and Conditional Access policies. Some clients run both. The role template stays the same either way; only the place it is built changes.
Which password manager do you use for business password management?
We deploy Keeper. Each team gets shared folders, and admins enforce the master password and two-factor rules from one console. When someone leaves, their vault is transferred to a manager under Keeper's account transfer policy, and we change the shared passwords they knew.
What happens to an employee's access when they leave?
The same day, we block sign-in and end active sessions, then remove the person from their groups and from every app on their template. Their email and files go to the manager you name, and the licenses come back to you. Shared passwords they knew are changed in Keeper.
Do you manage apps that don't support single sign-on?
Yes. Many business apps offer single sign-on or automatic provisioning only on higher-priced plans, and some offer neither. For those apps we add and remove users in the app's own admin console, following the role template, and keep any shared logins in Keeper. We tell you which of your apps fall into which group before anything changes.
Do you work with businesses outside New York?
Yes. Password and permissions management is done remotely, so it works wherever your team is. We manage passwords and permissions for clients across the country from our Brooklyn headquarters.
How is this different from privileged access management?
Privileged access management covers administrator and service accounts, the few logins that can change settings for everyone. Password and permissions management covers the everyday access of every employee. Most businesses need both, and we run them together.