- What it is
- Roles and statuses
- Invite a user
- Bulk import (CSV)
- Edit, deactivate, resend, unlock
- Approve self-enrollment
- Related
What it is
The Users screen (/users) is where you manage who has access to the tenant. Each person has a role, a status and (optionally) a department, job title and groups.
Roles and statuses
Each user has a role (Collaborator, Manager, or Administrator; see Roles and permissions) and a status:
| Status | Meaning |
|---|---|
| Invited | Invited, awaiting first access |
| Active | In use |
| Pending approval | Self-enrollment awaiting approval (approval mode) |
| Inactive | Deactivated |
Invite a user
In Users → Invite, enter the email, name, role and (optionally) department and job title. What happens next depends on the role:
- A Collaborator receives instructions for the collaborator portal and signs in with an OTP code by email, no password.
- A Manager or Administrator gets a temporary password for the console instead.
The invite is created even if the email fails (it’s recorded; you can resend it).
Bulk import (CSV)
To populate the base all at once, use Import: submit rows with email, name, department, job title (up to 2000). Everyone comes in as passwordless collaborators (OTP login). The import is idempotent: it deduplicates within the file, skips those who already exist and respects the plan’s user limit. Any overflow is returned in the “skipped” list.
Edit, deactivate, resend, unlock
- Edit: name, role, department, job title, status. A role change is recorded as its own event in the audit log.
- Deactivate is a soft delete. It marks the user as inactive and ends all sessions immediately, but never erases the history. You cannot deactivate your own account.
- Resend invite works only for those who are still “Invited”. For managers, it regenerates the temporary password.
- Unlock resets the login attempts of an account locked by brute-force protection.
The phone number (metadata.phone), used for smishing, is not editable from this screen — it arrives via SCIM, self-enrollment or the collaborator's profile.
Approve self-enrollment
If you use self-enrollment in approval mode, pending sign-ups appear here with the Pending approval status — the Approve / Reject buttons are in the user detail view.
Related
</content>