HomeServicesPassword and Permissions Management

Password and Permissions Management for Business

Hand NetSys your application stack and a role template for each position. Before a new hire's first day, their accounts and app permissions are in place and their password vault is waiting. The day someone leaves, we take the access back. We work in Microsoft 365 and in Google Workspace.

Review Single Sign-On
By The NetSys Group · Published · Editorial policy

The short answer

Password and permissions management means deciding who can sign in to each business application and what they can do there, and keeping shared passwords in a managed vault instead of a spreadsheet. NetSys runs it for you. You send us your application stack and a role template for each job, such as paralegal or project manager. We build that access in Microsoft 365 or Google Workspace, and shared passwords go into Keeper. New hires start with the right access, and people who leave lose it the same day.

Onboarding, made simple

Most onboarding goes wrong in small places. The new hire has email on day one but can't open the shared drive, and someone ends up texting them the password for the scheduling system. Leaving goes wrong the other way: the email account gets disabled while the project app and the vendor portal keep working for months.

NetSys takes that work off your plate. We document your application stack once and agree a role template with you for each position. After that, onboarding is one email to us with the new hire's role and start date. We handle the accounts, the licenses, the app invitations and the password vault, then confirm before the start date that everything works.

How a role template works

A role template is a short list your managers already know: which groups and shared folders a position needs, and which apps it uses, with the permission level in each. We turn each template into groups in Microsoft Entra ID or Google Workspace, so access follows the group. Apps that support single sign-on or automatic provisioning pick it up from there. For the rest we keep a written checklist and do the steps by hand, including the shared passwords the role gets in Keeper.

Your application stack

The business apps we manage access for

These are the applications we set up and manage permissions in most often. If your team runs something else, send us the list: any app with an admin console can go on a role template.

Identity and passwords

  • Microsoft 365
  • Google Workspace
  • Keeper

CRM

  • Salesforce
  • HubSpot

Chat and meetings

  • Slack
  • Zoom

Business intelligence

  • Microsoft Power BI
  • Tableau
  • Looker

Project management

  • monday.com
  • Asana
  • Trello
  • Jira
  • Smartsheet

Email newsletters

  • Mailchimp
  • Constant Contact

Membership management

  • Wild Apricot
  • Mindbody

Product names and logos are trademarks of their respective owners. They identify applications NetSys administers for clients and do not imply a partnership or endorsement.

What Password and Permissions Management Includes

Onboarding from Role Templates

One email, and the new hire is ready on day one.

  • Account created in Microsoft 365 or Google Workspace, with the license the role needs
  • Group membership that opens the shared drives and mailboxes the team uses
  • Invitations and the right permission level in each app on the template
  • A Keeper vault with the team's shared folders already in it
  • Confirmation from us before the start date that every sign-in works

Microsoft 365 and Google Workspace

Access follows the group, whichever suite you run.

  • Microsoft 365: Entra ID groups for SharePoint and Teams access, with admin roles kept to least privilege
  • Google Workspace: groups and shared drive roles set per team, with organizational units for policy
  • Single sign-on and automatic provisioning for apps whose plan supports them
  • Multi-factor authentication required at every sign-in

Business Password Management

Shared passwords in a vault, not a spreadsheet.

  • Keeper for every user, with shared folders by team or role
  • Master password and two-factor rules enforced from the admin console
  • Shared logins handed to a new hire without anyone reading them out or texting them
  • Security reports on weak and reused passwords, followed up with the people involved

Role Changes, Offboarding and Reviews

Access stays current after day one.

  • Promotions and transfers handled by moving the person to a different template
  • Same-day offboarding, with sign-in blocked and every app seat on the template removed
  • The leaver's vault transferred to a manager and the shared passwords they knew changed
  • Email and files handed to the manager you name
  • Periodic access reviews, so permissions match the job people do now
Industry app stacks

Permissions management for firms in every industry

We already manage passwords and permissions for clients across the country, in many industries. Each field runs its own mix of software. Here are five common apps in each, and what access control looks like there.

Law firms

Document access often has to respect ethical walls between matters. We set permissions in the practice-management and document systems by role and by matter team, and keep those exclusions intact when people join or leave.

  • Clio
  • MyCase
  • NetDocuments
  • iManage
  • DocuSign
Managed IT for law firms 

Healthcare practices

HIPAA expects each person's access to patient information to match their job. We map front-desk and clinical roles to the EHR and patient-messaging apps, and keep a record of who could see what.

  • athenahealth
  • Tebra
  • SimplePractice
  • ModMed
  • Weave
Managed IT for healthcare 

Construction

Subcontractors and owner reps come and go with each project. We give each project team its access in the project-management and drawing apps, and close outside accounts when the job ends.

  • Procore
  • Autodesk Construction Cloud
  • Bluebeam
  • Buildertrend
  • Smartsheet
Managed IT for construction 

Retail

Store teams turn over quickly, and point-of-sale logins get shared. PCI DSS expects every person with access to have their own login, so we set up individual accounts and manager permissions, and remove them after an employee's last shift.

  • Shopify
  • Square
  • Lightspeed
  • Clover
  • QuickBooks
Managed IT for retail 

Consulting firms

Consultants move between client engagements, and client files should stay with the client team. We set CRM and file-sharing permissions by engagement, and give contractors access that ends on a set date.

  • HubSpot
  • Notion
  • Harvest
  • PandaDoc
  • Box
Managed IT for professional services 

Wealth management and RIAs

Client records carry obligations under SEC Regulation S-P, for fiduciaries of every size. We keep each advisor's and assistant's access in the CRM and custodian portals matched to their role, and change it the day that role changes.

  • Redtail CRM
  • Wealthbox
  • Orion
  • Schwab Advisor Services
  • Global Relay
Managed IT for wealth managers 

Marketing agencies

Agencies hold client social accounts and brand files, and freelancers rotate through. We manage seats and shared workspaces in the design and social tools, and keep client logins in Keeper instead of a shared document.

  • Adobe Creative Cloud
  • Canva
  • Figma
  • Hootsuite
  • Semrush
Managed IT for agencies 

Another industry?

Nonprofits, fitness studios, accounting firms and schools each run their own stack. Send us your app list and a role you hire for often, and we will show you how it maps to a template.

Send us your app list 
Why NetSys

Why businesses hand NetSys their access management

Fifteen minutes with a NetSys engineer, not a salesperson, and you will know where your password and permissions management stands and what it would take to fix it. Call 845-203-3914 or request a call to discuss the scope and next steps.

  • We already manage passwords and permissions for clients across the country, in many industries
  • One team runs your Microsoft 365 or Google Workspace tenant and the apps connected to it
  • Role templates are written down, so access never depends on one person's memory
  • Offboarding is same-day and covers the apps outside your email suite
  • Month-to-month terms, like every NetSys agreement
  • Engineers based in Brooklyn, in business since 1998

What a role template looks like

An example template for a paralegal at a small law firm. It is an illustration, not a client's configuration; yours lists the apps and permission levels your team actually uses.

AccessExample: paralegalHow NetSys sets it up
IdentityMicrosoft 365 account and licenseCreated in Entra ID from the template
GroupsLitigation team and all-staffOpens the team's SharePoint site and shared mailbox
Practice managementClio, standard userAccount created with the role the firm set for paralegals
DocumentsNetDocuments, litigation workspacesAccess granted by matter team
E-signatureDocuSign senderSeat assigned now, removed at offboarding
Shared passwordsKeeper, litigation shared folderRecords visible on the first day

Every row comes back out when the person leaves, because the same template drives the offboarding checklist.

Microsoft 365 vs Google Workspace: where permissions live

The role template is the same in either suite. What changes is where each piece of it is built:

Microsoft 365Google Workspace
DirectoryMicrosoft Entra IDGoogle Workspace directory
Grouping peopleSecurity and Microsoft 365 groups; dynamic groups need Entra ID P1Groups, with organizational units for settings
Shared filesSharePoint sites and Teams, with OneDrive sharing rulesShared drives with Manager, Content manager, Contributor, Commenter and Viewer roles
Admin accessEntra ID and Microsoft 365 admin rolesPrebuilt and custom admin roles
Sign-in rulesConditional Access with Entra ID P1, included in Business Premium2-Step Verification, plus context-aware access on the editions that include it
Other appsEnterprise applications with SAML or OpenID Connect sign-inSAML apps, with automatic provisioning for supported apps

NetSys manages both suites. Clients who run both get one template per role.

Common Questions

Password and Permissions Management FAQs

What is permissions management?

Permissions management is the ongoing work of deciding who can reach each application and file, and at what level, then keeping that current as staff come and go. For a small business that usually means groups in Microsoft 365 or Google Workspace, plus the permission level each person holds in every business app. Shared passwords belong in a password manager, where they can be handed over and changed safely.

How does onboarding a new employee work with NetSys?

You send us the new hire's role and start date. We create the account from the matching role template, assign the license, add the person to the right groups, send the app invitations and share the Keeper folders the role uses. Before the start date we check that every sign-in works and send first-day instructions.

What is a role template?

A role template lists what one position needs: the groups and shared folders it opens, and each application with its permission level, including the shared passwords the role uses in Keeper. You agree it with us once. Every new hire in that role starts with the same access, and when the template changes we update everyone in the role.

Can you manage permissions in Google Workspace as well as Microsoft 365?

Yes. In Google Workspace we manage users, groups, shared drive roles and admin roles. In Microsoft 365 we manage Entra ID groups, SharePoint and Teams access, admin roles and Conditional Access policies. Some clients run both. The role template stays the same either way; only the place it is built changes.

Which password manager do you use for business password management?

We deploy Keeper. Each team gets shared folders, and admins enforce the master password and two-factor rules from one console. When someone leaves, their vault is transferred to a manager under Keeper's account transfer policy, and we change the shared passwords they knew.

What happens to an employee's access when they leave?

The same day, we block sign-in and end active sessions, then remove the person from their groups and from every app on their template. Their email and files go to the manager you name, and the licenses come back to you. Shared passwords they knew are changed in Keeper.

Do you manage apps that don't support single sign-on?

Yes. Many business apps offer single sign-on or automatic provisioning only on higher-priced plans, and some offer neither. For those apps we add and remove users in the app's own admin console, following the role template, and keep any shared logins in Keeper. We tell you which of your apps fall into which group before anything changes.

Do you work with businesses outside New York?

Yes. Password and permissions management is done remotely, so it works wherever your team is. We manage passwords and permissions for clients across the country from our Brooklyn headquarters.

How is this different from privileged access management?

Privileged access management covers administrator and service accounts, the few logins that can change settings for everyone. Password and permissions management covers the everyday access of every employee. Most businesses need both, and we run them together.

Onboarding made simple

Send us your app list and one role. We'll draft the template.

Tell us which apps your team uses and a role you hire for often. We will draft that role template with you and walk through how onboarding and offboarding would run.