Users and access
Use Users for day-to-day team-member administration and Identity for groups, app access, and identity settings. Always start with the least access required, and extend it only when the work requires it.
Invite a user
- Open Users and select Invite user.
- Enter the recipient’s email address and, where relevant, choose their name, language, role, and plan.
- Select the organization domain and local part if the user should receive an organization address.
- Send the invitation. The recipient receives a setup link in the selected language.
A pending invitation can be resent or revoked. Create a new invitation if the original link has expired or should no longer be used.
Roles and lifecycle
| Role | Appropriate for |
|---|---|
| Owner | The person with overall responsibility for the workspace and customer relationship. |
| Administrator | People who need to administer users, domains, services, and billing. |
| Member | Regular users who use their own services without access to Admin. |
On a user page, administrators can see account, email, storage, security, and activity information. Available actions depend on the role and which part of the product is active.
- Change role: Use this only when the person’s actual work changes. Afterwards, check that the user still has the correct access.
- Suspend: Temporarily stops sign-in. Email and data remain.
- Reactivate: Restores access for a suspended user.
- Remove from workspace: Removes access immediately. Email data is normally retained for 30 days before permanent deletion.
You cannot remove the last administrator or perform certain critical actions on your own account. Promote another administrator first if an owner or the last administrator must be replaced.
User profile and account details
Use the detail page to check name, language, mailbox, role, storage, latest activity, and associated devices. Language preferences are used in the interface and for transactional email when the field is available. Telephone numbers must be stored in international E.164 format, for example +4798765432.
A password reset sends a link to the user’s registered recovery address. Never ask a user to send passwords or recovery codes to an administrator.
Identity
Under Identity, you will find more detailed access administration. See the detailed Identity guide for SSO, SCIM, the access matrix, and a safe setup order:
| Page | Used for |
|---|---|
| Overview | View the status of members, groups, and relevant events. |
| Members | View and manage membership, roles, and group membership. |
| Invitations | Create, resend, or revoke identity invitations. |
| Groups | Collect people who should have the same access. |
| Roles and access | Understand what permissions a role has before assigning it. |
| Apps | Manage internal apps, SSO integrations, and SCIM where enabled. |
| Settings | Choose the default role for new invitations. |
Assign the least access necessary
Changes to groups, app access, SSO, or SCIM can give many users new access at once. Confirm the target group and role before saving, then check the audit log afterwards.
Common problems
The user cannot find the invitation: Check the email address, ask the recipient to check junk mail, and resend the invitation when needed.
The user cannot sign in: First check whether the account is suspended or the invitation has expired. Do not create a new account until you have checked that an active account with the same address does not already exist.
Incorrect app access: Review member role, group membership, and app access. Remove unnecessary access before adding new access.