Docs / Admin Console / Add system users (role-based access)
Browse Admin Console
Admin Console

Add system users (role-based access)

Add and manage operator accounts in the ScoutDNS Admin Console. Four built-in roles (Super Admin / Admin / Service Desk / Viewer) and how to transfer Super Admin between users.

Updated Aug 23, 2025 • 3 min read

ScoutDNS supports role-based access control so multiple operators can share an account with the right level of access. This article covers adding operators directly in ScoutDNS.

[!NOTE] To manage role assignments through Microsoft Entra ID instead of (or in addition to) local ScoutDNS users, see SSO with Entra ID. For MSPs granting access to third-party accounts, see Organization Operators.

Access Management page

Built-in roles

RoleManage usersAllow/Block listsOther objectsNotes
Super AdminCreate and remove all users (including other admins)FullCreate, edit, view allOne per account
AdminCreate and remove all users except Super AdminFullCreate, edit, view allMost common admin role
Service DeskNoneEdit allow/block listsView-only on everything elseFor support-tier operators who tune lists but don’t change policy
ViewerNoneView-onlyView-onlyRead-only access

[!NOTE] When SSO is enabled, Super Admin and Organization Operator accounts are exempt, they continue to use local logins. See SSO with Entra ID.

Create an operator account

  1. Open Access Management (profile icon, top right) and click New.
  2. Enter the operator’s email, first name, and last name.
  3. Pick a role.
  4. Save.

What happens next depends on whether the email is already known to ScoutDNS:

  • Existing ScoutDNS user: their account is linked to yours with the selected role.
  • New email: a new operator account is created with the chosen role.

New operator form

[!IMPORTANT] Once an operator account is created or linked, you cannot edit name or email from your side. Only the operator themselves can update those fields. You can still change their role or revoke access at any time.

Revoke access

To remove an operator’s access to your account:

  1. Open the operator on the Access Management page.
  2. Click Revoke Access under their name.

This removes the operator from your account only. If their email is linked to other ScoutDNS accounts, those remain unaffected.

Transfer the Super Admin role

Only the current Super Admin can transfer the role to another operator, and the target must already be an Admin on the account.

  1. On the Access Management page, click Promote New Super Admin at the top.
  2. Select an existing Admin to take over the role.
  3. Confirm.

The previous Super Admin is automatically downgraded to Admin after the transfer. You can keep them as an Admin or revoke their access entirely.

Promote New Super Admin

[!IMPORTANT] Make sure the new Super Admin has 2FA enabled before the transfer, see Two-factor authentication. The Super Admin is your break-glass account if SSO ever needs to be turned off.

Was this article helpful?
Still stuck? Open a ticket and we'll follow up by email.
Open a ticket
Last updated Aug 23, 2025