Manage access
Invite and add users to a tenant, give them tenant and workspace roles, organize them in groups, and create custom roles.
Manage access is where a tenant administrator decides who can do what. Switch the sidebar to Tenant and select Manage access. It has four tabs: Users, Groups, Roles and Robot accounts (robot accounts are covered in Machines and robots). What a person can do is the sum of every role they hold, directly or through a group, at tenant level or in a workspace. For the built-in roles and the permission list, see RBAC and permissions. Invite a user# You need users.edit in the tenant (for example Administrator). Go to Manage access ▸ Users. Select Invite user. Enter the person's Email and select Send invitation. The person receives an email, creates their account (see Sign in), and joins the tenant with the Everyone role. Then give them the roles they need (below). Invitations need outbound email to work; see Users and roles. Add an existing account to the tenant# Platform administrators see Add user instead of Invite user. It adds an account that already exists on this Orchestrator. Go to Manage access ▸ Users and select Add user. Under User, search for and pick the account. Under Tenant roles, tick the roles that apply across the tenant. Under Workspace roles, add a workspace and tick roles that apply only there. Select Add user. Change a user's roles# Go to Manage access ▸ Users. Select ⋮ on the user ▸ Edit roles. Tick or clear Tenant roles, and add or change Workspace roles per workspace. Check Effective access to see exactly what the user can do in a workspace, and where each permission comes from. Select Save roles. The user's ⋮ menu also has Reset two-step sign-in (removes their authenticator so they set it up again), Passkeys (review or remove theirs) and Remove from tenant. You can also grant access from the workspace side: see Give people, groups and robot accounts access. Use groups# Groups let you assign roles once for many people. Built-in groups (marked Built-in) match the built-in roles; their roles cannot be changed. Go to Manage access ▸ Groups and select New group. Enter a Name and Description, then select Create group. Open the group. On the Members tab, select Manage members and pick the users. On the Roles tab, tick the group's roles and select Save roles. Optional: on the Single sign-on tab, select Add mapping to tie the group to a group in your identity provider. Members are then added and removed at each sign-in. See Users and roles. To grant a group access to one workspace only, assign it in that workspace (Assign ▸ Type Group). Removing a member, or deleting the group, takes away the roles they had only through it. Create a custom role# You need roles.edit in the tenant. Built-in roles cannot be deleted. Go to Manage access ▸ Roles. Select New role ▸ Tenant role or Workspace role. The scope cannot be changed later. Enter a Name and Description. Under Permissions, tick View, Create, Edit, Delete or Other for each kind of item, or All for a row. Select Create role. Then assign the role to users or groups (above). Start with the smallest set of permissions that does the job. Next steps# RBAC and permissions Users and roles Audit log and webhooks
Invite a user
Add an existing account to the tenant
Change a user's roles
Use groups
Create a custom role
Next steps