Users and permissions
Users and permissions are managed separately:
- Users are the people who can sign in.
- Permissions connect a user to a tenant or organization area with a role.
| Role | Typical use |
|---|---|
| Platform Admin | Operates all tenants and global identities. |
| Tenant Admin | Manages one complete tenant, including memberships. |
| Org Admin | Manages one organization area and optionally its children. |
| Viewer | Reads the assigned tenant or organization area. |
Manage users
Section titled “Manage users”Platform administrators can create global users, set a temporary password, edit user details, reset passwords, and disable accounts. A password reset or account deactivation signs the user out everywhere.
Tenant administrators see the current and historical members of the selected tenant but cannot change the person’s global login details.
The user and permission tables provide Previous and Next navigation with 25, 50, or 100 entries per page. Searches and tenant changes reset the table to page 1. Search, status, role where applicable, and page size are kept in the URL so browser Back and Forward restore the filtered view. The result count is the exact filtered number of users or memberships, not an estimate from the current page.
Manage permissions
Section titled “Manage permissions”Open Permissions to create or edit a membership. Select the user, role, and scope. For an organization role, choose the organization unit and decide whether child areas are included.
The user picker searches the server and loads 50 matches at a time. The organization picker searches the complete visible hierarchy and offers only active units that you may manage, with the ancestor path shown for context. Use Load more for another page. If that request fails, current choices stay available and the same action retries it.
Changes apply to the next request. Before removing or narrowing a grant, check whether the user still needs access for current work. Disabled memberships remain in history and can be reactivated.