Home / Resources / Access Management
Who is in your organization, and what each of them may do in the console.
A role is a named set of permissions. Built-in roles cover the common shapes; press New Role to create your own, name it, and tick the permissions it should carry.
Permissions are additive: a person holds the union of every role assigned to them. Organization administrators hold all permissions and cannot be locked out by a role change.
A role in use lists the number of people holding it. Deleting a role removes it from them; it does not remove the people.
Fill in a display name and a username, an email address, choose User Account, optionally assign a role, and press Invite user account. They receive an invitation; the role is applied when they accept.
People can also arrive without an invitation if their email domain is listed under Join rules on the Organization page.
Choose Service Account instead of User Account to create an identity for a script or an integration rather than a person. A service account signs in with a key rather than a password and never consumes a client licence.
If Join rules require administrator approval, people who have joined but not yet been approved appear under Approvals. Until approved they hold no access.